立即与支持人员聊天
与支持团队交流

Identity Manager 8.2 - Administration Guide for Connecting to LDAP

About this guide Managing LDAP environments Synchronizing LDAP directories
Setting up initial LDAP directory synchronization Adjusting the synchronization configuration for LDAP environments Running synchronization Tasks following synchronization Troubleshooting Ignoring data error in synchronization
Managing LDAP user accounts and employees Managing memberships in LDAP groups Login information for LDAP user accounts Mapping LDAP objects in One Identity Manager Handling of LDAP objects in the Web Portal Basic data for managing a LDAP environment Troubleshooting Configuration parameters for managing an LDAP environment Default project template for LDAP Generic LDAP connector settings LDAP connector V2 settings

LDAP specific main data for LDAP domains

On the LDAP tab, enter the following main data.

Table 24: LDAP data
Property Description

Full domain name

Name of the domain confirming to DNS syntax.

<name of this domain>.<name of parent domain>.<name of root domain>.

Distinguished name

Distinguished name of the domain. The distinguished name is determined using a template from the full domain name and cannot be edited.

Structural object class Structural object class representing the object type.
Object class List of classes defining the attributes for this object. The default object class is DOMAIN. However, in the input field, you can add object classes and auxiliary classes that are used by other LDAP and X.500 directory services.
Search mask Search mask for another LDAP object.

Defining categories for inheritance by LDAP groups

In One Identity Manager, user accounts can selectively inherit groups. To do this, groups and user accounts are divided into categories. The categories can be freely selected and are specified using a mapping rule. Each category is given a specific position within the template. The template contains two tables; the user account table and the group table. Use the user account table to specify categories for target system dependent user accounts. In the group table, enter your categories for the target system-dependent groups. Each table contains the category positions position 1 to position 63.

To define a category

  1. In the Manager, select the domain in the LDAP > Domains category.

  2. Select the Change main data task.

  3. Switch to the Mapping rule category tab.

  4. Extend the relevant roots of the user account table or group table.

  5. To enable the category, double-click .

  6. Enter a category name of your choice for user accounts and groups in the login language that you use.

  7. Save the changes.
Detailed information about this topic

Editing the synchronization project for an LDAP domain

Synchronization projects in which a domain is already used as a base object can also be opened in the Manager. You can, for example, check the configuration or view the synchronization log in this mode. The Synchronization Editor is not started with its full functionality. You cannot run certain functions, such as, running synchronization or simulation, starting the target system browser and others.

NOTE: The Manager is locked for editing throughout. To edit objects in the Manager, close the Synchronization Editor.

To open an existing synchronization project in the Synchronization Editor

  1. In the Manager, select the LDAP > Domains category.

  2. Select the domain in the result list.

  3. Select the Change main data task.

  4. Select the Edit synchronization project task.

Related topics

Displaying the LDAP domain overview

Use this task to obtain an overview of the most important information about a domain.

To obtain an overview of a domain

  1. In the Manager, select the LDAP > Domains category.

  2. Select the domain in the result list.

  3. Select the LDAP domain overview task.

相关文档

The document was helpful.

选择评级

I easily found the information I needed.

选择评级