on CMC for authorization similar to the working of the Standard Schema setup with Active Directory
support.
To enable the LDAP user to access a specific CMC card, the role group name and its domain name must
be configured on the specific CMC card. You can configure a maximum of five role groups in each CMC.
A user has the option to be added to multiple groups within the directory service. If a user is a member of
multiple groups, then the user obtains the privileges of all their groups.
For information about the privileges level of the role groups and the default role group settings, see Types
of Users.
Configuring the Generic LDAP Directory to Access CMC
The CMC's Generic LDAP implementation uses two phases in granting access to a user—user
authentication, and then the user authorization.

Authentication of LDAP Users

Some directory servers require a bind before a specific LDAP server can be searched for.
To authenticate a user:
1. Optionally bind to the Directory Service. The default is an anonymous bind.
2. Search for the user on the basis of the user login. The default attribute is uid. If more than one
object is found, then the process returns an error.
3. Unbind and perform a bind with the user's DN and password. If the system is unable to bind, then the
login will not be successful.
4. If these steps succeed, the user is authenticated.

Authorization Of LDAP Users

To authorize a user:
1. Search each configured group for the user's domain name within the member or uniqueMember
attributes. An administrator can configure a user domain.
2. For every user group that the user belongs to, give the user appropriate user access rights and
privileges.
Configuring Generic LDAP Directory Service Using CMC Web Interface
To configure the generic LDAP directory service:
NOTE: You must have the Chassis Configuration Administrator privilege.
1. In the left pane, click Chassis OverviewUser AuthenticationDirectory Services.
2. Select Generic LDAP.
The settings to be configured for standard schema is displayed on the same page.
3. Specify the following:
NOTE: For information about the various fields, see the Online Help.
Common Settings
Server to use with LDAP:
141