Dell PowerConnect W Clearpass 100 Software 3.7 Deployment Guide - Page 420

Setting, Description, LDAP Module Settings Continued

Page 420 highlights

Table 54 LDAP Module Settings (Continued) Setting Description ldap.password_attribute = "nspmPassword" To support Novell eDirectory Universal Password, this option must be set to "nspmPassword". Retrieves the user's plain-text password from the directory and uses in the RADIUS server for user authentication. Universal Password requires a secure connection to the LDAP server. Required for Novell eDirectory support. When defining this attribute for an individual Novell eDirectory LDAP server, remove the "ldap." prefix from the attribute name. ldap.password_header = "{clear}" To extract the user's plain-text password via Novell Universal Password, this value must be set to "{clear}". The value for this attribute must be lowercase. Universal Password requires a secure connection to the LDAP server. Required for Novell eDirectory support. When defining this attribute for an individual Novell eDirectory LDAP server, remove the "ldap." prefix from the attribute name. ldap.net_timeout = 1 Number of seconds to wait for a response from the LDAP server (network failures). ldap.timeout = 4 Number of seconds to wait for the LDAP query to finish. ldap.timelimit = 3 Number of seconds the LDAP server has to process the query (server-side time limit). ldap.ldap_debug = 0 Debug flags for LDAP SDK (see OpenLDAP documentation) Example: (LDAP_DEBUG_FILTER + LDAP_DEBUG_CONNS) ldap.ldap_debug = 0x0028 ldap.identity = not set The DN under which LDAP searches are done. ldap.password = not set Password which authenticates the identity DN. If not set, the default is to perform an anonymous bind, with no password required. NOTE: this implies that searches will be done over an unencrypted connection! ldap.basedn ldap.filter= "o=My Org,c=UA" Base of LDAP searches. ldap.filter ldap.filter = "uid=%{Stripped-User-Name:-%{User-Name}}" The LDAP search filter, to locate user object using the name supplied by client during the RADIUS authentication process. ldap.base_filter = not set The LDAP search filter used for base scope searches, like when searching for the default or regular profiles. ldap.start_tls = no When set to "yes", the StartTLS extended operation is used to enable TLS transport encryption. ldap.tls_mode = no When set to "yes", or if the server port is 636, we try to connect with TLS. Start TLS should be preferred; 'tls_mode' is provided only for LDAP servers like Active Directory which do not support it. ldap.tls_cacertfile = not set A PEM-encoded file that contains the CA Certificates that you trust. ldap.tls_cacertdir = not set Path to a directory of CA Certificates that you trust, the directory must be in "hash format" (see: openssl verify). 420 | Reference Amigopod 3.7 | Deployment Guide

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401
  • 402
  • 403
  • 404
  • 405
  • 406
  • 407
  • 408
  • 409
  • 410
  • 411
  • 412
  • 413
  • 414
  • 415
  • 416
  • 417
  • 418
  • 419
  • 420
  • 421
  • 422
  • 423
  • 424
  • 425
  • 426
  • 427
  • 428
  • 429
  • 430
  • 431
  • 432
  • 433
  • 434
  • 435
  • 436
  • 437
  • 438

420
| Reference
Amigopod 3.7
|
Deployment Guide
ldap.password_attribute
= “nspmPassword”
To support Novell eDirectory Universal Password, this option must
be set to “nspmPassword”. Retrieves the user’s plain-text
password from the directory and uses in the RADIUS server for
user authentication. Universal Password requires a secure
connection to the LDAP server.
Required for Novell eDirectory support. When defining this
attribute for an individual Novell eDirectory LDAP server, remove
the “ldap.” prefix from the attribute name.
ldap.password_header
= “{clear}”
To extract the user’s plain-text password via Novell Universal
Password, this value must be set to “{clear}”. The value for this
attribute must be lowercase. Universal Password requires a secure
connection to the LDAP server.
Required for Novell eDirectory support. When defining this
attribute for an individual Novell eDirectory LDAP server, remove
the “ldap.” prefix from the attribute name.
ldap.net_timeout
= 1
Number of seconds to wait for a response from the LDAP server
(network failures).
l
dap.timeout
= 4
Number of seconds to wait for the LDAP query to finish.
ldap.timelimit
= 3
Number of seconds the LDAP server has to process the query
(server-side time limit).
ldap.ldap_debug
= 0
Debug flags for LDAP SDK (see OpenLDAP documentation)
Example: (LDAP_DEBUG_FILTER + LDAP_DEBUG_CONNS)
ldap.ldap_debug = 0x0028
ldap.identity =
not set
The DN under which LDAP searches are done.
ldap.password
=
not set
Password which authenticates the identity DN. If not set, the
default is to perform an anonymous bind, with no password
required. NOTE: this implies that searches will be done over an
unencrypted connection!
ldap.basedn
ldap.filter
= "o=My Org,c=UA"
Base of LDAP searches.
ldap.filter
ldap.filter
= "uid=%{Stripped-User-Name:-%{User-Name}}"
The LDAP search filter, to locate user object using the name
supplied by client during the RADIUS authentication process.
ldap.base_filter
=
not set
The LDAP search filter used for base scope searches, like when
searching for the default or regular profiles.
ldap.start_tls
= no
When set to “yes”, the StartTLS extended operation is used to
enable TLS transport encryption.
ldap.tls_mode
= no
When set to “yes”, or if the server port is 636, we try to connect
with TLS. Start TLS should be preferred; ‘tls_mode’ is provided
only for LDAP servers like Active Directory which do not support it.
ldap.tls_cacertfile =
not set
A PEM-encoded file that contains the CA Certificates that you
trust.
ldap.tls_cacertdir
=
not set
Path to a directory of CA Certificates that you trust, the directory
must be in “hash format” (see: openssl verify).
Table 54
LDAP Module Settings (Continued)
Setting
Description