Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

  1. Create Authentication Policy

  2. Name the authentication policy and select Authentication Method LDAP + Database with Roles

  3. Select Linked authentication Database created previously for Yarngate

  4. Configure LDAP authentication

    1. The LDAP server address should be in the format LDAPS://<FQDN>:<port> - Note that LDAP:// can be used but passwords will not be encrytped encrypted in transit

    2. Verify TLS/SSL certificates can be enabled - Note that the LDAPS server certificate or trusted root CA certificate must be uploaded via the administration app

    3. LDAP username match regex can be used to match username formats - This is a generic username match regex that can be adjusted as needed(^[A-Za-z0-9]+(?:[ _-][A-Za-z0-9]+)*$)

    4. LDAP replace regex allows to adding prefixes/suffices to suite the authentication requirements such as adding a domain suffix

  5. Save the authentication policy - Note that new tabs will now become visablevisible

  6. Configure LDAP authorisation and roles

    1. The LDAP interface field is optional - this can be used if an out of band check using another LDAP user is required for LDAP user group search on LDAP, . If this option is not selected, the LDAP groups are retreived using the authenticated LDAP user

    2. Base DN - provide the base DN for LDAP searches

    3. Username Match Field - this is the LDAP username field used typically sAMAccountName

    4. LDAP group to role mapping - this provide a mapping from LDAP groups to the Autentication Database roles defined previously. The LDAP groups can be entered in as global group name of LDAP distingushed name

...