Lexmark X925 Lexmark Document Distributor - Page 47

Assigning privileges to groups, Example

Page 47 highlights

Monitoring and maintaining the system 47 Example • User Search Filter: uid • User Search Base: ou=Employees • Group Search Filter: uniquemember • Group Search Base: ou=Groups • Group Identifier: groupOfNames • Member of Group(s): Dept A,Dept C If the user name testuser is used to log in to LMC, then the user can be authenticated if each of the following is true: - The distinguished name uid=testuser,ou=Employees,o=MyOrganization is found in the directory. - The distinguished name cn=Dept A,ou=Groups,o=MyOrganization or cn=Dept C,ou=Groups,o=MyOrganization is found in the directory and contains the attribute uniquemember: uid=testuser,ou=Employees,o=MyOrganization. - The object class is groupOfNames . - The correct password is supplied for the user. 8 Select an authentication method: • If the LDAP server accepts anonymous connections, then select Anonymous. • If the LDAP server requires authentication, then do the following: a Select the Username option. b In the Username field, type a distinguished name used to log on to the LDAP server, such as uid=ldapuser,ou=Employees,o=MyOrganization. c Type the password associated with the selected user name. 9 If you want to test the connection settings, then click Test Settings. Note: If the LDAP server accepts anonymous connections but you want to authenticate with a user name and password, then the test cannot determine whether the user name and password are correct. If the test reports an anonymous connection when you have chosen to use a user name and password, then you should check the user name and password. 10 In the Search Base field, type the distinguished name where the directory search should begin, such as o=MyOrganization. 11 Click Save Settings. Assigning privileges to groups You can add access control to users accessing LMC. This feature allows you to restrict system access to authorized groups. The Privileges settings depend on the role assigned to the user. Notes: • You need to add a group first before defining privileges. By default, the LDD Default Group is already added to the group list. This group has access to all tabs and tasks of LMC. The administrator can modify the privileges of the default group.

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146

Example
User Search Filter:
uid
User Search Base:
ou=Employees
Group Search Filter:
uniquemember
Group Search Base:
ou=Groups
Group Identifier:
groupOfNames
Member of Group(s):
Dept A,Dept C
If the user name
testuser
is used to log in to LMC, then the user can be authenticated if each of the
following is true:
The distinguished name
uid=testuser,ou=Employees,o=MyOrganization
is found in the
directory.
The distinguished name
cn=Dept A,ou=Groups,o=MyOrganization
or
cn=Dept C,ou=Groups,o=MyOrganization
is found in the directory and contains the attribute
uniquemember: uid=testuser,ou=Employees,o=MyOrganization
.
The object class is
groupOfNames
.
The correct password is supplied for the user.
8
Select an authentication method:
If the LDAP server accepts anonymous connections, then select
Anonymous
.
If the LDAP server requires authentication, then do the following:
a
Select the
Username
option.
b
In the Username field, type a distinguished name used to log on to the LDAP server, such as
uid=ldapuser,ou=Employees,o=MyOrganization
.
c
Type the password associated with the selected user name.
9
If you want to test the connection settings, then click
Test Settings
.
Note:
If the LDAP server accepts anonymous connections but you want to authenticate with a user name and
password, then the test cannot determine whether the user name and password are correct. If the test reports
an anonymous connection when you have chosen to use a user name and password, then you should check the
user name and password.
10
In the Search Base field, type the distinguished name where the directory search should begin, such as
o=MyOrganization
.
11
Click
Save Settings
.
Assigning privileges to groups
You can add access control to users accessing LMC. This feature allows you to restrict system access to authorized
groups. The Privileges settings depend on the role assigned to the user.
Notes:
You need to add a group first before defining privileges. By default, the LDD Default Group is already added to
the group list. This group has access to all tabs and tasks of LMC. The administrator can modify the privileges of
the default group.
Monitoring and maintaining the system
47