LDAP client behavior overview 292
LDAP client behavior overview
UID masks (simple and complex)
The client application login dialog enables you to enter two fields, labeled User name and Password.
Before the HP IP Console Viewer was enhanced with support for directory services integration (LDAP), the
product supported only one form of authentication, which used an internal database. Therefore, there was
no ambiguity about the use of these two fields because the internal database supports only one form of
user name. However, Active Directory supports many types of attributes that could sensibly be used as
credentials for the purposes of authenticating the user of the client application. After an administrator
chooses which Active Directory attributes to use as credentials, the choice is implemented using a feature
of the HP IP Console Switch called the UID Mask. This flexibility engenders several questions:
•
What are the Active Directory attributes that could sensibly be used as credentials?
•
How does the value of each of those attributes get set in Active Directory?
•
How is the UID mask in the Manage Console Switch window used to implement a customer's choice
of credentials?
These questions are addressed in the following subsections.
Active Directory attributes that can be used as credentials
Several attributes that are candidates for use as credentials are defined when a new user account is
initialized in Active Directory. Other candidates are found in the Properties dialog for user objects in
Active Directory. In addition, other candidates are available but not readily accessible in the default
Properties dialog for user objects. For these attributes, it is necessary to use an Active Directory tool, such
as ADSI Editor, to access the attribute and set its value.
Attributes initialized during creation of a new user object
When a new object is created in Active Directory to represent a user, the dialog presented by Active
Directory enables values to be set for the following attribute types:
•
First Name
•
Initials
•
Last Name
•
Full Name
•
User Logon Name
•
User Principal Name
NOTE:
This attribute is not explicitly labeled in the dialog used to create a new user object.
Содержание 1x1x16 - IP Console Switch KVM
Страница 1: ...HP IP Console Viewer User Guide Part Number 409053 003 July 2008 Third Edition ...
Страница 41: ...Managing KVM console switches 41 For more information on connection sharing see Video session types on page 79 ...
Страница 50: ...Managing KVM console switches 50 Unlocking an account 1 Select Users ...
Страница 122: ...Managing serial console switches 122 Unlocking an account for serial console switches 1 Select Users ...
Страница 176: ...Organizing the system 176 Serial console switch General tab Server General tab ...
Страница 181: ...Organizing the system 181 KVM console switch Network tab Serial console switch Network tab ...
Страница 216: ...Using directory services integration 216 The following are examples of groups defined in Active Directory ...
Страница 259: ...Using the on board Web interface OBWI 259 5 Click Save ...
Страница 264: ...Troubleshooting 264 2 Select Install Certificate ...
Страница 267: ...Troubleshooting 267 1 Select the error field in the browser to view the certificate error 2 Select View Certificates ...
Страница 268: ...Troubleshooting 268 3 Select Install Certificate ...
Страница 295: ...LDAP client behavior overview 295 As an example consider the following instance of the New Object User dialog ...
Страница 296: ...LDAP client behavior overview 296 ...
Страница 303: ...LDAP client behavior overview 303 The corresponding UID mask is shown in the following example ...