DescriptionName
Thespecific distinguished name in the LDAP hierarchywhere the
servershould begin a search when a remote user logs in and the
systemattempts to get the user's DN based on their username. The
maximumsupported string length is 127 characters.
Thisproperty is required. If you do not specify a base DN on this
tabthen you must specify one on the General tab for every LDAP
providerdefined in this Cisco UCS domain.
BaseDN field
TheLDAP search is restricted to those usernames that match the
definedfilter.
Thisproperty is required. If you do not specify a filter on this tab
thenyou must specify one on the General tab for every LDAP
providerdefined in this Cisco UCS domain.
Filterfield
Step 4 ClickSave Changes.
What to Do Next
Createan LDAP provider.
Creating an LDAP Provider
CiscoUCS Manager supports a maximum of 16 LDAP providers.
Before You Begin
Ifyou are using Active Directory as your LDAP server,create a user account in the Active Directory server
tobind with Cisco UCS. This account should be given a non-expiring password.
• In the LDAP server,perform one of the following configurations:
◦ Configure LDAP groups. LDAP groups contain user role and locale information.
◦ Configure users with the attribute that holds the user role and locale information for Cisco UCS
Manager.You can choose whether to extend the LDAP schema for this attribute. If you do not
wantto extend the schema, use an existing LDAP attribute to hold the Cisco UCS user roles and
locales.If you prefer to extend the schema, create a custom attribute, such as the CiscoAVPair
attribute.
TheCisco LDAP implementation requires a unicode type attribute.
Ifyou choose to create the CiscoAVPaircustom attribute, use the following attribute ID:
1.3.6.1.4.1.9.287247.1
◦ For a cluster configuration, add the management port IP addresses for both fabricinterconnects.
Thisconfiguration ensures that remote users can continue to log in if the first fabric interconnect
failsand the system fails over to the second fabric interconnect. All login requests are sourced
fromthese IP addresses, not the virtual IP address used by Cisco UCS Manager.
Cisco UCS Manager GUI Configuration Guide, Release 2.0
OL-25712-04 135
Configuring LDAP Providers