S W G U s e r G u i d e
Chapter 4: Defining and Managing Users
30
8. In the
Password
field, enter the password for logging into your organization's directory.
9. To enable the import of LDAP groups over SSL, select the
Use
secure
connection
checkbox. If you
selected this checkbox:
• If the Policy Server should not perform certificate validation before starting the SSL session,
select the
Ignore
Certificate
Validation
checkbox.
• If the Policy Server should validate the certificate on each connection, leave the
Ignore
Certif
icate
Validation
checkbox cleared. In this case, if the certificate is invalid, user import fails
and an event such as a log, trap, or email is created.
10. To use Kerberos Authentication:
a. Click the
Do
not
check
configuration
settings
on
next
save
checkbox.
b. Click
Save
and exit this window.
c. Create the needed Kerberos keytab file if it is not already created.
d. Import the Keytab file as follows:
i. Right‐click this LDAP directory node in the LDAP directory configuration tree, and
selecting I
mport
Keytab
. This displays the Kerberos Keytab Upload screen.
ii. Upload the keytab file.
e. Reopen this LDAP directory definition.
f. Select the
Use
Kerberos
Authentication
checkbox.
g. Clear the
Do
not
check
configuration
settings
on
next
save
checkbox.
h. Skip to
Step 12
.
11. If you do not want the connection to the server to be checked after you save the definition, make
sure that the
Do
not
check
configuration
settings
on
next
save
checkbox at the bottom of the
window is NOT selected.
12. Click
Save
.
13. If you are ready to distribute and implement the changes in your system devices, click
.
The directory will appear in the LDAP Servers tree. You can also check in the logs for verification.
NOTE:
LDAP
passwords
cannot
include
the
<
,
>
or
space
characters.
Do
not
use
non
English
characters
if
you
will
be
using
the
Kerberos
authentication
method.
NOTE:
You
cannot
use
Kerberos
authentication
if
you
use
SSL
authentication.
To
use
Kerberos
authentication:
• A DNS server must be present, and all directory servers must be resolved via the M86
SWG Appliance.
• The times on the Policy Server and the directory machine must be synchronized.
• You must have or create a Kerberos keytab file.
NOTE:
To
check
the
address
that
is,
that
the
connection
to
the
server
was
successful,
right
click
on
the
Active
Directory
LDAP
server
in
tree,
and
select
Check
Connection
from
the
drop
down
menu.
If
there
was
a
problem
connecting
to
the
servers,
an
error
message
is
displayed.