Copyright 2010-2015 Obihai Technology, Inc.
134
Search Parameters
authentication. By default SASL is disabled.
IP Phone – LDAP –
Search Parameters
SASLsecurityPro
perties
This is an optional parameter that specifies the desired SASL security properties. It is
a comma separated list of one or more of the following properties:
-
NOPLAIN
-
NOACTIVE
-
NODICT
-
FORWARD
-
NOANON
-
CRED
-
MUTUAL
IP Phone – LDAP –
Search Parameters
SASLauthcid
The authentication ID for SASL authentication. The format of this ID depends on the
actual SASL mechanism used.
IP Phone – LDAP –
Search Parameters
SASLmech
The supported mechanisms are:
-
PLAIN
-
LOGIN
-
DIGEST-MD5
-
GSSAPI (Kerberos V5)
-
KERBEROS_V4
-
EXTERNAL
For more informations on each of these mechanisms, please check for example
http://www.openldap.org
Client Authentication
LDAP v2 supports
ldap://
and
ldaps://
with Simple Authentication only. LDAP v3 adds support for TLS and
SASL Authentication. Simple authentication involves sending the LDAP server the fully qualified DN of the client and the
corresponding password in clear-text, which has obivious security issue unless
ldaps://
or TLS is used.
SASL (stands for Simple Authentication and Security Layer) [RFC2222] is a framework for authentication. To use SASL
the parameter
LDAP
–
SASLenable
must be enabled. At the start of each query, the phone will first negotiate
with the server a SASL mechanism to use. The phone supports the following mechanisms
*
:
-
PLAIN
-
LOGIN
-
DIGEST-MD5
-
GSSAPI (Kerberos V5)
-
KERBEROS_V4
-
EXTERNAL
*For more informations on each of these SASL mechanisms, please check for example http://www.openldap.org
LDAP Directory Search Application
The LDAP application on the phone may be invoked either from the Main Menu or with a soft key.