11-25
User Guide for Cisco Secure ACS for Windows Server
78-14696-01, Version 3.1
Chapter 11 Working with User Databases
Generic LDAP
If the tree containing users is the base DN, type:
o=corporation.com
or
dc=corporation,dc=com
as applicable to your LDAP configuration. For more information, refer to
your LDAP database documentation.
–
Group Directory Subtree—The DN for the subtree that contains all
groups. For example:
ou=
organizational unit
[,ou=
next organizational unit
]o=corporation.com
If the tree containing groups is the base DN, type:
o=corporation.com
or
dc=corporation,dc=com
as applicable to your LDAP configuration. For more information, refer to
your LDAP database documentation.
–
UserObjectType—The name of the attribute in the user record that
contains the username. You can obtain this attribute name from your
Directory Server. For more information, refer to your LDAP database
documentation. Cisco Secure ACS provides default values that reflect
the default configuration of a Netscape Directory Server. Confirm all
values for these fields with your LDAP server configuration and
documentation.
–
UserObjectClass—The value of the LDAP “objectType” attribute that
identifies the record as a user. Often, user records have several values for
the objectType attribute, some of which are unique to the user, some of
which are shared with other object types. This box should contain a value
that is not shared.
–
GroupObjectType—The name of the attribute in the group record that
contains the group name.
–
GroupObjectClass—A value of the LDAP “objectType” attribute in the
group record that identifies the record as a group.