Chapter 6 Configuring authentication 251

if user entries are located in several places in the LDAP Dictionary Information Tree (DIT), the position in the DIT from where all user records can be found with a subtree search (requires isdBindDN and isdBindPassword)

group attribute name — the LDAP attribute that contains the names of the groups. You can specify more than one group attribute name.

user attribute name — refers to one of the following:

the LDAP attribute that contains the user name (does not require isdBindDN and isdBindPassword)

the LDAP attribute that is used in combination with the user’s login name to search the DIT (requires isdBindDN and isdBindPassword)

isdBindDN — used to authenticate the Nortel SNAS 4050 to the LDAP server, so that the LDAP DIT can be searched. The isdBindDN corresponds to an entry created in the Schema Admins account (for example, cn=ldap ldap, cn=Users, dc=example, dc=com). An account must be created on the LDAP server to enable the Nortel SNAS 4050 to do the bind search in the directory structure.

isdBindPassword — used to authenticate the Nortel SNAS 4050 to the LDAP server. The isdBindPassword is the password, configured in the Schema Admins account, for the entry referenced in isdBindDN.

enable LDAPS — if true, makes LDAP requests between the Nortel SNAS 4050 and the LDAP server occur over a secure SSL connection. The default is false. Retain the default value or reset to false.

The Authentication menu displays.

Nortel Secure Network Access Switch 4050 User Guide

Page 251
Image 251
Nortel Networks 4050 manual Configuring authentication