496
| Reference
ClearPass Guest 3.9 | Deployment Guide
ldap.password_attribute
= “nspmPassword”
To support Novell eDirectory Universal Password, this option must
be set to “nspmPassword”. Retrieves the user’s plain-text
password from the directory and uses in the RADIUS server for
user authentication. Universal Password requires a secure
connection to the LDAP server.
Required for Novell eDirectory support. When defining this
attribute for an individual Novell eDirectory LDAP server, remove
the “ldap.” prefix from the attribute name.
ldap.password_header
= “{clear}”
To extract the user’s plain-text password via Novell Universal
Password, this value must be set to “{clear}”. The value for this
attribute must be lowercase. Universal Password requires a secure
connection to the LDAP server.
Required for Novell eDirectory support. When defining this
attribute for an individual Novell eDirectory LDAP server, remove
the “ldap.” prefix from the attribute name.
ldap.net_timeout
= 1
Number of seconds to wait for a response from the LDAP server
(network failures).
l
dap.timeout
= 4
Number of seconds to wait for the LDAP query to finish.
ldap.timelimit
= 3
Number of seconds the LDAP server has to process the query
(server-side time limit).
ldap.ldap_debug
= 0
Debug flags for LDAP SDK (see OpenLDAP documentation)
Example: (LDAP_DEBUG_ LDAP_DEBUG_CONNS)
ldap.ldap_debug = 0x0028
ldap.identity =
not set
The DN under which LDAP searches are done.
ldap.password
=
not set
Password which authenticates the identity DN. If not set, the
default is to perform an anonymous bind, with no password
required. NOTE: this implies that searches will be done over an
unencrypted connection!
ldap.basedn
ldap.filter
= "o=My Org,c=UA"
Base of LDAP searches.
ldap.filter
ldap.filter
= "uid=%{Stripped-User-Name:-%{User-Name}}"
The LDAP search filter, to locate user object using the name
supplied by client during the RADIUS authentication process.
ldap.base_filter
=
not set
The LDAP search filter used for base scope searches, like when
searching for the default or regular profiles.
ldap.start_tls
= no
When set to “yes”, the StartTLS extended operation is used to
enable TLS transport encryption.
ldap.tls_mode
= no
When set to “yes”, or if the server port is 636, we try to connect
with TLS. Start TLS should be preferred; ‘tls_mode’ is provided
only for LDAP servers like Active Directory which do not support it.
ldap.tls_cacertfile =
not set
A PEM-encoded file that contains the CA Certificates that you
trust.
ldap.tls_cacertdir
=
not set
Path to a directory of CA Certificates that you trust, the directory
must be in “hash format” (see: openssl verify).
Table 63
LDAP Module Settings (Continued)
Setting
Description
Содержание ClearPass Guest 3.9
Страница 1: ...ClearPass Guest 3 9 Deployment Guide ...
Страница 32: ...32 Management Overview ClearPass Guest 3 9 Deployment Guide ...
Страница 178: ...178 RADIUS Services ClearPass Guest 3 9 Deployment Guide ...
Страница 316: ...316 Guest Management ClearPass Guest 3 9 Deployment Guide ...
Страница 328: ...328 Report Management ClearPass Guest 3 9 Deployment Guide Figure 46 Components of the Report Editor Report Type ...
Страница 410: ...410 Administrator Tasks ClearPass Guest 3 9 Deployment Guide ...
Страница 414: ...414 Administrator Tasks ClearPass Guest 3 9 Deployment Guide ...
Страница 423: ...ClearPass Guest 3 9 Deployment Guide Hotspot Manager 423 ...
Страница 440: ...440 High Availability Services ClearPass Guest 3 9 Deployment Guide ...
Страница 518: ...518 Index ClearPass Guest 3 9 Deployment Guide ...