Dell Powerconnect W-ClearPass Hardware Appliances W-ClearPass Policy Manager 6 - Page 134

Table 61, AD/LDAP Default Filters Explained

Page 134 highlights

Table 61: AD/LDAP Default Filters Explained Directory Default Filters Active Directory l Authentication: This is the filter used for authentication. The query searches in objectClass of type user. This query finds both user and machine accounts in Active Directory: (&(objectClass=user)(sAMAccountName=%{Authentication:Username})) When a request arrives, Policy Manager populates %{Authentication:Username} with the authenticating user or machine. This filter is also set up to fetch the following attributes based on this filter query: n dn (aliased to UserDN): This is an internal attribute that is populated with the user or machine record's Distinguished Name (DN) n department n title n company n memberOf: In Active Directory, this attribute is populated with the groups that the user or machine belongs to. This is a multi-valued attribute. n telephoneNumber n mail n displayName l Group: This is filter used for retrieving the name of the groups a user or machine belongs to. (distinguishedName=%{memberOf}) This query fetches all group records, where the distinguished name is the value returned by the memberOf variable. The values for the memberOf attribute are fetched by the first filter (Authentication) described above. The attribute fetched with this filter query is cn, which is the name of the group l Machine: This query fetches the machine record in Active Directory. (&(objectClass=computer)(sAMAccountName=%{Host:Name}$)) %{Host:Name} is populated by Policy Manager with name of the connecting host (if available). dNSHostName, operatingSystem and operatingSystemServicePack attributes are fetched with this filter query. l Onboard Device Owner: This is the filter for retrieving the name of the owner the onboard device belongs to. This query finds the user in the ACtive Directory. (&(sAMAccountName=%{Onboard:Owner})(objectClass=user)) %{Onboard:Owner} is populated by Policy Manager with the name of the onboarded user. l Onboard Device Owner Group: This filter is used for retrieving the name of the group the onboarded device owner belongs to. (distinguishedName=%{Onboard memberOf}) This query fetches all group records where the distinguished name is the value returned by the Onboard memberOf variable. The attribute fetched with this filter query is cn, which is the name of the Onboard group Generic LDAP Directory Authentication: This is the filter used for authentication. (&(objectClass=*)(uid=%{Authentication:Username})) When a request arrives, Policy Manager populates %{Authentication:Username} with the authenticating user or machine. This filter is also set up to fetch the following attributes based on this filter query: n dn (aliased to UserDN): This is an internal attribute that is populated with the user record's Distinguished Name (DN) Group: This is filter used for retrieving the name of the groups a user belongs to. (&(objectClass=groupOfNames)(member=%{UserDn})) n This query fetches all group records (of objectClass groupOfNames), where member field contains the DN of the user record (UserDN, which is populated after the Authentication filter query is executed. The attribute fetched with this filter query is cn, which is the name of the group (this is aliased to a more readable name: groupName) 134 Dell Networking W-ClearPass Policy Manager 6.0 | User Guide

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372

134
Dell Networking W-ClearPass Policy Manager 6.0 | User Guide
Table 61:
AD/LDAP Default Filters Explained
Directory
Default Filters
Active
Directory
l
Authentication
: This is the filter used for authentication. The query searches in objectClass of type
user
. This query finds both user and machine accounts in Active Directory:
(&(objectClass=user)(sAMAccountName=%{Authentication:Username}))
When a request arrives, Policy Manager populates
%{Authentication:Username}
with the
authenticating user or machine. This filter is also set up to fetch the following attributes based on
this filter query:
n
dn
(aliased to UserDN): This is an internal attribute that is populated with the user or machine
record’s Distinguished Name (DN)
n
department
n
title
n
company
n
memberOf
: In Active Directory, this attribute is populated with the groups that the user or
machine belongs to. This is a multi-valued attribute.
n
telephoneNumber
n
mail
n
displayName
l
Group
: This is filter used for retrieving the name of the groups a user or machine belongs to.
(distinguishedName=%{memberOf})
This query fetches all group records, where the distinguished name is the value returned by the
memberOf
variable. The values for the
memberOf
attribute are fetched by the first filter
(Authentication) described above. The attribute fetched with this filter query is
cn
, which is the
name of the group
l
Machine
: This query fetches the machine record in Active Directory.
(&(objectClass=computer)(sAMAccountName=%{Host:Name}$))
%{Host:Name} is populated by Policy Manager with name of the connecting host (if available).
dNSHostName, operatingSystem and operatingSystemServicePack attributes are fetched with this
filter query.
l
Onboard Device Owner:
This is the filter for retrieving the name of the owner the onboard device
belongs to. This query finds the user in the ACtive Directory.
(&(sAMAccountName=%{Onboard:Owner})(objectClass=user))
%{Onboard:Owner} is populated by Policy Manager with the name of the onboarded user.
l
Onboard Device Owner Group:
This filter is used for retrieving the name of the group the
onboarded device owner belongs to.
(distinguishedName=%{Onboard memberOf})
This query fetches all group records where the distinguished name is the value returned by the
Onboard memberOf variable. The attribute fetched with this filter query is cn, which is the name of
the Onboard group
Generic
LDAP
Directory
Authentication
: This is the filter used for authentication.
(&(objectClass=*)(uid=%{Authentication:Username}))
When a request arrives, Policy Manager populates %{Authentication:Username} with the
authenticating user or machine. This filter is also set up to fetch the following attributes based on
this filter query:
n
dn
(aliased to UserDN): This is an internal attribute that is populated with the user record’s
Distinguished Name (DN)
Group
: This is filter used for retrieving the name of the groups a user belongs to.
(&(objectClass=groupOfNames)(member=%{UserDn}))
n
This query fetches all group records (of objectClass groupOfNames), where member field
contains the DN of the user record (UserDN, which is populated after the Authentication filter
query is executed. The attribute fetched with this filter query is cn, which is the name of the
group (this is aliased to a more readable name: groupName)