Dell B3465dnf Mono Embedded Web Server -- Security Administrators Guide - Page 14

Use Active Directory Device Credentials, Add an LDAP Setup

Page 14 highlights

Using security features in the Embedded Web Server 14 3 Click Add an LDAP Setup. The LDAP Server Setup dialog is divided into four parts: General Information • Setup Name-This name is used to identify each particular LDAP Server Setup when creating security templates. • Server Address-Type the IP address or the host name of the LDAP server where the authentication will be performed. • Server Port-The Embedded Web Server communicates with the LDAP server using this port. The default LDAP port is 389. • Use SSL/TLS-From the drop‑down menu, select None, SSL/TLS (Secure Sockets Layer/Transport Layer Security), or TLS. • Userid Attribute-Type either cn (common name), uid, userid, or user‑defined. • Mail Attribute-Type a maximum of 48 characters to uniquely identify e‑mail addresses. The default value is "mail." • Full Name Attribute-Type a maximum of 48 characters. The default value is "cn." • Search Base-This is the node in the LDAP server where user accounts reside. Multiple search bases may be entered, separated by commas. Note: A search base consists of multiple attributes separated by commas, such as cn (common name), ou (organizational unit), o (organization), c (country), and dc (domain). • Search Timeout-Enter a value from 5 to 30 seconds or 5 to 300 seconds depending on your printer model. • Required User Input-Select either User ID and password or User ID to specify which credentials a user must provide when attempting to access a function protected by the LDAP building block. User ID and password is the default setting. Device Credentials • Use Active Directory Device Credentials-If selected, then user credentials and group designations can be pulled from the existing network comparable to other network services. • Anonymous LDAP Bind-If selected, then the Embedded Web Server binds with the LDAP server anonymously, and the Distinguished Name and MFP Password fields are unavailable. • Distinguished Name-Type the distinguished name of the print server or servers. • MFP's Password-Type the password for the print servers. Search specific object classes • Person-If selected, then the "person" object class will also be searched. • Custom Object Class-If selected, then this custom search object class will also be searched. The administrator can define up to three custom search object classes (optional). LDAP Group Names • Administrators can associate as many as 32 named groups stored on the LDAP server by entering identifiers for those groups under the Group Search Base list. Both the Short name for group and Group Identifier must be provided. • When creating security templates, the administrator can pick groups from this setup for controlling access to device functions. 4 Click Submit to save the changes, or Cancel to return to previous values.

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52

3
Click
Add an LDAP Setup
.
The LDAP Server Setup dialog is divided into four parts:
General Information
Setup Name
—This name is used to identify each particular LDAP Server Setup when creating security templates.
Server Address
—Type the IP address or the host name of the LDAP server where the authentication will be
performed.
Server Port
—The Embedded Web Server communicates with the LDAP server using this port. The default LDAP
port is 389.
Use SSL/TLS
—From the drop
down menu, select
None
,
SSL/TLS
(Secure Sockets Layer/Transport Layer
Security), or
TLS
.
Userid Attribute
—Type either
cn
(common name),
uid
,
userid
, or
user
defined
.
Mail Attribute
—Type a maximum of 48 characters to uniquely identify e
mail addresses. The default value is
“mail.”
Full Name Attribute
—Type a maximum of 48 characters. The default value is “cn.”
Search Base
—This is the node in the LDAP server where user accounts reside. Multiple search bases may be
entered, separated by commas.
Note:
A search base consists of multiple attributes separated by commas, such as cn (common name), ou
(organizational unit), o (organization), c (country), and dc (domain).
Search Timeout
—Enter a value from 5 to 30 seconds or 5 to 300 seconds depending on your printer model.
Required User Input
—Select either
User ID and password
or
User ID
to specify which credentials a user must
provide when attempting to access a function protected by the LDAP building block.
User ID and password
is
the default setting.
Device Credentials
Use Active Directory Device Credentials
—If selected, then user credentials and group designations can be pulled
from the existing network comparable to other network services.
Anonymous LDAP Bind
—If selected, then the Embedded Web Server binds with the LDAP server anonymously,
and the Distinguished Name and MFP Password fields are unavailable.
Distinguished Name
—Type the distinguished name of the print server or servers.
MFP’s Password
—Type the password for the print servers.
Search specific object classes
Person
—If selected, then the “person” object class will also be searched.
Custom Object Class
—If selected, then this custom search object class will also be searched. The administrator
can define up to three custom search object classes (optional).
LDAP Group Names
Administrators can associate as many as 32 named groups stored on the LDAP server by entering identifiers for
those groups under the Group Search Base list. Both the
Short name for group
and
Group Identifier
must be
provided.
When creating security templates, the administrator can pick groups from this setup for controlling access to
device functions.
4
Click
Submit
to save the changes, or
Cancel
to return to previous values.
Using security features in the Embedded Web Server
14