Difference between revisions of "LDAP Configuration"
IVSWikiBlue (talk | contribs) (→Connecting to the LDAP Server) |
IVSWikiBlue (talk | contribs) (→Importing an Individual User) |
||
(35 intermediate revisions by the same user not shown) | |||
Line 2: | Line 2: | ||
#Navigate to the VALT software either through the IP Address or the FQDN using Chrome, Firefox, or other standard web browser | #Navigate to the VALT software either through the IP Address or the FQDN using Chrome, Firefox, or other standard web browser | ||
#Log in using your login credentials | #Log in using your login credentials | ||
− | #: | + | #: '''Note:''' (Default credentials: Username = ''admin'' | Password = ''admin'') |
#Click on '''Admin''' -> '''Users & Groups''' -> '''LDAP''' -> '''Show Advanced Settings''' | #Click on '''Admin''' -> '''Users & Groups''' -> '''LDAP''' -> '''Show Advanced Settings''' | ||
#:[[File:LDAP1.png|1000px]] | #:[[File:LDAP1.png|1000px]] | ||
#Scroll down to '''Servers''' | #Scroll down to '''Servers''' | ||
#:[[File:LDAP_Server_Box.png|1000px]] | #:[[File:LDAP_Server_Box.png|1000px]] | ||
− | #Enter in your LDAP Server information | + | #Enter in your LDAP Server information: |
#:<table> | #:<table> | ||
<tr> | <tr> | ||
Line 13: | Line 13: | ||
</tr> | </tr> | ||
<tr> | <tr> | ||
− | <td style="padding: 0 10px">'''A:'''</td> | + | <td style="padding: 0 10px;vertical-align: top">'''A:'''</td> |
− | <td style="padding: 0 10px">Enter the IP Address or FQDN of your Active Directory or other LDAP compatible server in the Server field <br><span class="indent"> '''Note: | + | <td style="padding: 0 10px;vertical-align: top">Enter the IP Address or FQDN of your Active Directory or other LDAP compatible server in the Server field <br><span class="indent"> <font color="red">'''Note: <br> I: ''If you are using LDAPS, enter the IP or FQDN as ldaps://myldapsserver.com'''''<br> ''' II: ''If you are using a Global Catalog Server then it needs to be written as myldapserver.com:3268''''' <br> ''' III: ''If you are using a Global Catalog Server with LDAPS, then it needs to be formatted as ldaps://myldapserver.com:3269'''''</font></span></td> |
</tr> | </tr> | ||
<tr> | <tr> | ||
− | <td style="padding: 0 10px">'''B:'''</td> | + | <td style="padding: 0 10px;vertical-align: top">'''B:'''</td> |
− | <td style="padding: 0 10px">Enter a Service Account user with read access in the LDAP Bind User field <br>< | + | <td style="padding: 0 10px;vertical-align: top">Enter a Service Account user with read access in the LDAP Bind User field <br><span class="indent"><font color="red">'''Note: The user must be entered as user@domain.com'''</font></span></td> |
</tr> | </tr> | ||
<tr> | <tr> | ||
− | <td style="padding: 0 10px">'''C:'''</td> | + | <td style="padding: 0 10px;vertical-align: top">'''C:'''</td> |
− | <td style="padding: 0 10px">Enter the Service Account password</td> | + | <td style="padding: 0 10px;vertical-align: top">Enter the Service Account password<br><span class="indent"> <font color="red">'''Note: Our password requirements do not allow for the use of these reserved characters: ! * ' ( ) ; : @ & = + $ , / ? % # [ ]'''</font></span></td> |
</tr> | </tr> | ||
<tr> | <tr> | ||
− | <td style="padding: 0 10px">'''D:'''</td> | + | <td style="padding: 0 10px;vertical-align: top">'''D:'''</td> |
− | <td style="padding: 0 10px">Enter in the Base DN of the Service Account | + | <td style="padding: 0 10px;vertical-align: top">Enter in the Base DN of the Service Account <br><span class="indent"><font color="red">'''Note: Base DN must be entered in the form of DC=ad,DC=ipivs,DC=com'''</font></span></td> |
</tr> | </tr> | ||
<tr> | <tr> | ||
− | <td style="padding: 0 10px">'''E:'''</td> | + | <td style="padding: 0 10px;vertical-align: top">'''E:'''</td> |
− | <td style="padding: 0 10px">Select either '''Active Directory''' or '''Open LDAP'''</td> | + | <td style="padding: 0 10px;vertical-align: top">Select either '''Active Directory''' or '''Open LDAP'''</td> |
</tr> | </tr> | ||
<tr> | <tr> | ||
− | <td style="padding: 0 10px">'''F:'''</td> | + | <td style="padding: 0 10px;vertical-align: top">'''F:'''</td> |
− | <td style="padding: 0 10px">Click '''Save'''</td> | + | <td style="padding: 0 10px;vertical-align: top">Click '''Save'''</td> |
</tr> | </tr> | ||
</table> | </table> | ||
− | *If the credentials were accepted and a connection was established, you will receive a message stating connected and you will see your LDAP Server in '''Green''' | + | *If the credentials were accepted and a connection was established, you will receive a message stating connected and you will see your LDAP Server in '''Green:'''<br>[[File:LDAP2.png]] |
<br> | <br> | ||
− | *If the connection fails, you will receive an error message stating '''Wrong Credentials''' | + | *If the connection fails, you will receive an error message stating '''Wrong Credentials:'''<br>[[File:LDAP3.png]] |
==Syncing Security Groups== | ==Syncing Security Groups== | ||
− | :[[File: | + | #To sync users accounts, navigate to '''Sync Schedules''' |
− | # | + | #:[[File:Finding_Sync_Schedules_Box.png|1050px]] |
− | + | #Once here, start entering in the following information: | |
− | + | #:<table><tr><th rowspan="7">[[File:Adding_LDAP_Sync_Schedules.png]]</th></tr><tr><td style="padding: 0 10px;vertical-align: top">'''A:'''</td><td style="padding: 0 10px;vertical-align: top">Enter in a name for the Security Group <br><span class="indent"> <font color="red">'''Note: ''Try to keep these similar to the VALT groups you have created'''''</font></span></td></tr><tr><td style="padding: 0 10px;vertical-align: top">'''B:'''</td><td style="padding: 0 10px;vertical-align: top">Enter in the DN for the Security Group, omitting the DC components <br><span class="indent">'''Example:''' ''CN=Service Accounts,OU=Users,OU=Install''</span></td></tr><tr><td style="padding: 0 10px;vertical-align: top">'''C:'''</td><td style="padding: 0 10px;vertical-align: top">Select the '''VALT Group''' to have the users added to <br> | |
− | + | <span class="indent"> <font color="red">'''Note: The VALT groups need to be created before you can link the Security Groups to them''' </font></span></td></tr><tr><td style="padding: 0 10px;vertical-align: top">'''D:'''</td><td style="padding: 0 10px;vertical-align: top">Choose either '''Manual''' or '''Automatic''' Sync Type <br><span class="indent"><font color="red">'''Note: Automatic syncs users every day at 7AM server time whereas Manual requires an Admin account to manually sync the users'''</font></span></td></tr><tr><td style="padding: 0 10px;vertical-align: top">'''E:'''</td><td style="padding: 0 10px;vertical-align: top">Select any '''Additional Groups''' you would like the users added to</td></tr><tr><td style="padding: 0 10px;vertical-align: top">'''F:'''</td><td style="padding: 0 10px">Click '''Save'''</td></tr></table> | |
− | + | #Test that the user import worked: | |
+ | :<span class="indent">A. Click on the '''Group'''</span> | ||
+ | :<span class="indent">B. Click '''Import'''</span> | ||
+ | :::[[File:Testing_Sync_Schedule_Import.png]] | ||
+ | <br> | ||
+ | ::*If the import was successful, ''and there are users assigned to Security Groups'', you will see this message:<br> | ||
+ | :::[[File:Import_Results.png]] | ||
+ | <br> | ||
+ | ::*If the import failed, ''and there are users assigned to Security Groups'', you will see this message:<br> | ||
+ | :::[[File:Failed_Import_Results.png]] | ||
+ | <br> | ||
+ | <font color="red">Note: If the import failed, ''and you have users assigned to a group'', most likely either your '''Bind Script''' in the '''''Sync Schedule''''' block or the '''Base DN'''/'''LDAP Bind User''' in the '''''Server''''' block are entered incorrectly | ||
==Importing an Individual User== | ==Importing an Individual User== | ||
− | :[[File:LDAP5.png]] | + | <font color="black"> |
− | # | + | #Navigate to the '''User Import''' section:[[File:LDAP5.png|1000px]] |
− | + | #Enter in the information: | |
− | + | #:<table><tr><th rowspan="7">[[File:Full_User_Import_.png]]</th></tr><tr><td style="padding: 0 10px;vertical-align: top">'''A:'''</td><td style="padding: 0 10px;vertical-align: top">Enter in the name of a user and click '''Search'''</td></tr><tr><td style="padding: 0 10px;vertical-align: top">'''B:'''</td><td style="padding: 0 10px;vertical-align: top">A list of all users that populate with your search entry will appear</td></tr><tr><td style="padding: 0 10px;vertical-align: top">'''C:'''</td><td style="padding: 0 10px;vertical-align: top">The full DN of the user you select will appear here</td></tr><tr><td style="padding: 0 10px;vertical-align: top">'''D:'''</td><td style="padding: 0 10px;vertical-align: top">Select the '''Group''' you want to add the user to</td></tr><tr><td style="padding: 0 10px;vertical-align: top">'''E:'''</td><td style="padding: 0 10px;vertical-align: top">Select any '''Additional Groups''' you would like the user added to</td></tr><tr><td style="padding: 0 10px;vertical-align: top">'''F:'''</td><td style="padding: 0 10px;vertical-align: top">Click '''Import'''</td></tr></table> | |
− | + | #You will see a confirmation message displayed that the user has been imported and you can verify the user got assigned to the group:[[File:User_Import_Finalization.png|1000px]] | |
+ | </font> |
Latest revision as of 13:03, 16 June 2022
Connecting to the LDAP Server
- Navigate to the VALT software either through the IP Address or the FQDN using Chrome, Firefox, or other standard web browser
- Log in using your login credentials
- Note: (Default credentials: Username = admin | Password = admin)
- Click on Admin -> Users & Groups -> LDAP -> Show Advanced Settings
- Scroll down to Servers
- Enter in your LDAP Server information:
- If the credentials were accepted and a connection was established, you will receive a message stating connected and you will see your LDAP Server in Green:
Syncing Security Groups
- To sync users accounts, navigate to Sync Schedules
- Once here, start entering in the following information:
- Test that the user import worked:
Note: If the import failed, and you have users assigned to a group, most likely either your Bind Script in the Sync Schedule block or the Base DN/LDAP Bind User in the Server block are entered incorrectlyImporting an Individual User
- Navigate to the User Import section:
- Enter in the information:
- You will see a confirmation message displayed that the user has been imported and you can verify the user got assigned to the group:
- If the credentials were accepted and a connection was established, you will receive a message stating connected and you will see your LDAP Server in Green: