493
In This Chapter
Returning User Group Information ........................................................493
Setting the Registry to Permit Write Operations to the Schema ...........494
Creating a New Attribute .......................................................................494
Adding Attributes to the Class ...............................................................495
Updating the Schema Cache.................................................................497
Editing rciusergroup Attributes for User Members ................................497
Returning User Group Information
Use the information in this section to return User Group information (and
assist with authorization) once authentication is successful.
From LDAP/LDAPS
When an LDAP/LDAPS authentication is successful, the EMX
determines the permissions for a given user based on the permissions of
the user's role. Your remote LDAP server can provide these user role
names by returning an attribute named as follows:
rciusergroup
attribute type: string
This may require a schema extension on your LDAP/LDAPS server.
Consult your authentication server administrator to enable this attribute.
In addition, for Microsoft
®
Active Directory
®
, the standard LDAP
memberOf is used.
From Microsoft Active Directory
Note: This should be attempted only by an experienced Active Directory
®
administrator.
Returning user role information from Microsoft's
®
Active Directory for
Windows 2000
®
operating system server requires updating the
LDAP/LDAPS schema. See your Microsoft documentation for details.
1. Install the schema plug-in for Active Directory. See Microsoft Active
Directory documentation for instructions.
2. Run Active Directory Console and select Active Directory Schema.
Appendix G Updating the LDAP Schema
Содержание EMX2-888
Страница 19: ...Chapter 1 Introduction 5 Retrieval of the link local IPv4 address See IPv4 Address on page 72...
Страница 71: ...Chapter 4 Connecting External Equipment Optional 57...
Страница 148: ...Chapter 6 Using the Web Interface 134 LHX 20 SHX 30 LHX 40 PowerLogic PM710...
Страница 506: ...Appendix F LDAP Configuration Illustration 492 5 Click OK The EMX_Admin role is created 6 Click Close to quit the dialog...
Страница 526: ...Appendix H RADIUS Configuration Illustration 512 Note If your EMX uses PAP then select PAP...
Страница 527: ...Appendix H RADIUS Configuration Illustration 513 10 Select Standard to the left of the dialog and then click Add...
Страница 528: ...Appendix H RADIUS Configuration Illustration 514 11 Select Filter Id from the list of attributes and click Add...
Страница 531: ...Appendix H RADIUS Configuration Illustration 517 14 The new attribute is added Click OK...
Страница 532: ...Appendix H RADIUS Configuration Illustration 518 15 Click Next to continue...