3.0

Table Of Contents
Lab Manager User’s Guide
194 VMware, Inc.
Toconnecttoanodeinthetree,specifythedistinguishednameforthatnode,for
example:OU=LabManager,DC=vmware,DC=com.Connectingatanodelimitsthe
scopeofthedirectoryavailabletoLab Manager.
UseLDAPSIfyouhaveanOpenLDAPserversetuptosupportLDAPS,select
LDAPStomakeOpenLDAPtrafficconfidentialandsecurebyusingLDAPover
SSL(SecureSocketsLayer).ThisoptionisonlyavailableforOpenLDAP,because
ActiveDirectorysupportssecurebindingbydefault,andLab Manageronly
connectsto
ActiveDirectoryusingsecurebinding.
IfyoudonothaveanOpenLDAPserversetuptosupportLDAPS,refertoyour
OpenLDAPdocumentation.
AcceptallcertificatesAllowsLDAPScommunicationbetweentheLDAPserver
andLab ManagerserverwithoutrequiringtheLDAPSservercertificateintheLab
Managerservercertificatestore.
Ifyoudonotselectthisoption,youmustimportaserverauthenticationcertificate
fromtheLDAPSserverintotheLab Managerserverscertificatestore.
Seethe
WindowsServer2003ProductHelpforinformationaboutimportingcertificates.
CAUTIONIfyouspecifyanOU,theonlyLDAPusersthatcanloginto
Lab ManagerareusersinthatOU.Insomecases,thiscanblockaccesstousersthat
youdonotwanttoblock.
Forexample,considerthefollowingscenario:
DomainName:mydomain.com
TopLevelOUs:DublinOfficeandHeadOffice
Groups:LabMangroupthatincludesusersfromboththeDublinOfficeand
HeadOfficeOUs.
Ifyourbindingstringis:OU=HeadOffice,DC=mydomain,DC=com,andyouadd
theLabMangrouptoaLab Managerorganization,onlymembersoftheLabMan
groupwhoarealsomembersoftheHeadOfficeOUwillbeabletologinto
Lab Manager
andaccesstheorganization.MembersoftheLabMangroupfrom
theDublinOfficeOUwillbeexcluded.
CAUTIONDonotselectthisoptionunlessyouaresureyournetworkissecure.