User guide
Remote Authentication
70
From LDAP
WhenanLDAP/LDAPSauthenticationissuccessful,KXII‐101
determinesthepermissionsforagivenuserbasedonthepermissionsof
theuserʹsgroup.YourremoteLDAPservercanprovidetheseusergroup
namesbyreturninganattributenamedasfollows:
rciusergroup attributetype:string
ThismayrequireaschemaextensiononyourLDAP/L
DAPSserver.
Consultyourauthenticationserveradministratortoenablethisattribute.
From Microsoft Active Directory
Note:ThisshouldbeattemptedonlybyanexperiencedActiveDirectory
administrator.
ReturningusergroupinformationfromMicrosoftʹsActiveDirectoryfor
Windows2000ServerrequiresupdatingtheLDAP/LDAPSschema.
RefertoyourMicrosoftdocumentationformoredetail.
1. Installtheschemaplug‐inforActiveDirectory‐refertoMicrosoft
ActiveDirectorydocumentationforinstructions.
2. RunActiveDirectoryConsoleandselectActiveDi
rectorySchema.