Blue Coat OPT-1000-2499-3YR User Manual Page 49

  • Download
  • Add to my manuals
  • Print
  • Page
    / 121
  • Table of contents
  • BOOKMARKS
  • Rated. / 5. Based on customer reviews
Page view 48
49
Administrator: DN and access code of the LDAP server. If the LDAP server allows
anonymous listening, they may be left empty.
Base: base for user and group searches.
Type: type of LDAP server.
The type of LDAP server is used to indicate to the filter the way in which the users and
groups are to be obtained and the relation between each. To obtain that information the
filter needs the following data:
User objects: LDAP filter to search for objects with the user information, e.g.
(objectClass=inetOrgPerson), (objectClass=rvUser) etc.
Names of LDAP user attributes that will be used as a user name, e.g. shortname etc.
Filtering criterion: When working with ICAP and a user identifier other than
"Distinguished name" has been configured on LDAP, the option
consult user alias
(LDAP)” must be activated and a
maximum time set for the cache, as described
later on in this manual. In this case, OPTENET will carry out a consultation in order to
obtain the user identifier/s other than "Distinguished name". For OPTENET to know
which of the identifiers described in the consultation it must use, this box exists so that
a search pattern (for example "U*") can be used. In this respect, OPTENET shall only
consider those fields that begin with U. Finally, in order to resolve possible cases with
more than one match, a scroll-down exists which enables us to select "first value" or
"last value".
User members: condition that is applied to user objects to obtain the groups to which
it belongs, e.g. (memberOf=cn=%cn%), (ou=%ou%) etc. Note that it can be indicated
between % the object attributes that must meet the condition for the user to be
considered a member of that group.
Group objects: LDAP filter to obtain the objects with the group information, e.g.
(objectClass=groupOfUniqueNames), (objectClass=rvGroup) etc.
Group names: LDAP attribute that is used as a name for the groups, e.g. cn, ou etc.
Group members: condition that is applied to group objects to obtain the users
belonging to them, e.g. (uniqueMember=%dn%), (memberUid=%uid%) etc. Note that
it may be indicated between % the attribute of the user objects that must meet the
condition for the group to include that user as a member of it.
Nested groups: maximum level of group nesting. A value of -1 is possible, in which
case all the groups corresponding to a user will be searched for until there are no
more nests. If the value is 0, nested groups will not be searched for. This must be
used carefully, as more LDAP queries are performed per level, which can have a
negative effect on performance.
Page view 48
1 2 ... 44 45 46 47 48 49 50 51 52 53 54 ... 120 121

Comments to this Manuals

No comments