Chapter 4. Configuration

LDAP Settings

To allow authentication and authorization via LDAP or LDAPS, the Active Directory’s LDAP Schema must be extended so that an extended attribute name for the CN8600 CN8600-userProfileis added as an optional attribute to the person class.

In order to configure the LDAP server, you will have to complete the following procedures: 1) Install the Windows Server Support Tools; 2) Install the Active Directory Schema Snap-in; and 3) Extend and Update the Active Directory Schema. Refer to the LDAP Server Configuration Example for further information, please see the ATEN website at www.aten.com and navigate to the Download page.

To allow authentication and authorization for the CN8600 via LDAP / LDAPS, refer to the information in the following table.

Item

Action

 

 

Enable

Put a check in the Enable checkbox to allow LDAP / LDAPS

 

authentication and authorization.

 

 

LDAP / LDAPS

Click a radio button to specify whether to use LDAP or LDAPS.

 

 

LDAP Server

Fill in the IP address and port number for the LDAP or LDAPS

 

server. For LDAP, the default port number is 389; for LDAPS,

Port

the default port number is 636.

 

 

 

Timeout (seconds)

Set the time in seconds that the CN8600 waits for an LDAP or

 

LDAPS server reply before it times out.

 

 

Admin DN

Consult the LDAP / LDAPS administrator to ascertain the

 

appropriate entry for this field. For example, the entry might

 

look like this:

 

cn=LDAPAdmin,ou=cn8600,dc=aten,dc=com

 

 

Admin Name

Key in the Group Name for CN8600 administrator users.

 

 

Password

Key in the LDAP administrator’s password.

 

 

Search DN

Set the distinguished name of the search base. This is the

 

domain name where the search starts for user names.

 

If Enable Authorization is not checked, this field must include

 

the entry where the CN8600 Admin Group is created. Consult

 

the LDAP / LDAPS administrator to ascertain the appropriate

 

value.

 

 

39