398
Authorized users
The attribute "memberOf" in LDAP user objects can be used to restrict access
to certain users. In Microsoft Active Directory, "memberOf" refers to a user's
group membership. Simply enter the complete DN of the group (e.g. "CN=internet-
users,CN=users,DC=ad,DC=example,DC=com"). If you leave this field empty, all users
found in the LDAP searchbase will be able to authenticate themselves.
Login for LDAP search
A hierarchical search or searching for a user object with a specific "SAMAccountName"
attribute requires permission to perform an anonymous LDAP search within the search
path (in ActiveDirectory this involves read permission for "everyone"). If this is not
possible or desired, SX-GATE must log on to the LDAP server. To do this, please enter
the login for the LDAP account here.
You
must
state
the
complete
distinguished
name
(DN)
of
the
LDAP
account
(e.g.
"CN=proxyuser,CN=users,DC=ad,DC=example,DC=com").
14.7.1-F
Authentication options
This tab is not available if proxy authentication is off.
No authentication required for access to
Specify domain names or IP addresses, if you want to grant unauthenticated access
to these destinations. The specification of a domain includes all subdomains. So if e.g.
the domain "example.com" is found in the list, unauthenticated access is also possible
to "www.example.com" and "ftp.example.com".
Unauthenticated proxy access to the hostname of SX-GATE and
SX-GATE's eth0-IP is always granted.
Many web pages include elements from other internet domains. To completely disable
authentication for a certain web page all domains used by this page have to be included
in this list.
No authentication required for client
Connections from IPs from this list may use the proxy without authentication.