User guide

Remote Authentication
70
From LDAP
WhenanLDAP/LDAPSauthenticationissuccessful,KXII101
determinesthepermissionsforagivenuserbasedonthepermissionsof
theuserʹsgroup.YourremoteLDAPservercanprovidetheseusergroup
namesbyreturninganattributenamedasfollows:
rciusergroup attributetype:string
ThismayrequireaschemaextensiononyourLDAP/L
DAPSserver.
Consultyourauthenticationserveradministratortoenablethisattribute.
From Microsoft Active Directory
Note:ThisshouldbeattemptedonlybyanexperiencedActiveDirectory
administrator.
ReturningusergroupinformationfromMicrosoftʹsActiveDirectoryfor
Windows2000ServerrequiresupdatingtheLDAP/LDAPSschema.
RefertoyourMicrosoftdocumentationformoredetail.
1. InstalltheschemapluginforActiveDirectory‐refertoMicrosoft
ActiveDirectorydocumentationforinstructions.
2. RunActiveDirectoryConsoleandselectActiveDi
rectorySchema.