Manual ResistTel IP2 / IP152
Page 185
ExResistTel IP2 / IP154
If you use the latter, please specify the RID of the groups that shall have
administrator or viewer rights, respectively.
4.3.2.1.3.4
Determining the RID of a Windows Domain Group
The RID (relative ID) of a Windows domain group is the last numeric part of the
domain group SID (secure ID).
The easiest way to determine it for a group you are a member of is using the
following command:
whoami /groups /sid
[Group 1] = "DOMAIN\Domain-Users" S-1-5-21-854245398-616249376-725345543-
513
[Group 2] = "DOMAIN\Admins" S-1-5-21-854245398-616249376-725345543-
1180
In this example the RID for
DOMAIN\Domain-Users
is
513
and the RID for
DOMAIN\Admins
is
1180
.
4.3.2.1.3.5
Prerequisites for Windows Groups
You can use a Windows group for authorization if
it is in the domain of the users
it is a global security group
it does not contain nested groups
4.3.2.1.4
Using it
If your Kerberos Server is once configured you can use Kerberos user accounts for
logging into the administration interface of boxes using your web browser.
4.3.2.1.4.1
Use HTTPS for Kerberos Users
Delegated authentication works only with HTTPS connections. Using HTTP the boxes
accept only local user accounts.
4.3.2.1.4.2
User Names
To distinguish between local users and users of a Kerberos realm, the name of the
realm has to be pretended to the user name, separated by a backslash (\).
Alternatively you can append the realm to the user name separated by an at (
@
).
Summary of Contents for ExResistTel IP2/IP154
Page 43: ...Manual ResistTel IP2 IP152 Page 43 ExResistTel IP2 IP154 Figure 9 Set View ...
Page 386: ...Page 386 Manual ResistTel IP2 IP152 ExResistTel IP2 IP154 ...
Page 387: ...Manual ResistTel IP2 IP152 Page 387 ExResistTel IP2 IP154 ...
Page 390: ...Page 390 Manual ResistTel IP2 IP152 ExResistTel IP2 IP154 ...