HP 6125XLG R2306-HP 6125XLG Blade Switch Security Configuration Guide - Page 48

Creating an LDAP scheme, Specifying the LDAP authentication server, Displaying and maintaining LDAP

Page 48 highlights

• User object class If the LDAP server contains many directory levels, a user DN search starting from the root directory can take a long time. You can change the start point by specifying the search base DN to improve search efficiency. To configure LDAP user attributes: Step 1. Enter system view. 2. Enter LDAP server view. 3. Specify the user search base DN. 4. (Optional.) Specify the user search scope. 5. (Optional.) Specify the username attribute. 6. (Optional.) Specify the username format. 7. (Optional.) Specify the user object class. Command Remarks system-view N/A ldap server server-name N/A search-base-dn base-dn By default, no user search base DN is specified. search-scope { all-level | single-level } By default, the user search scope is all-level. user-parameters user-name-attribute { name-attribute | cn | uid } By default, the username attribute is cn. user-parameters user-name-format { with-domain | without-domain } By default, the username format is without-domain. user-parameters user-object-class object-class-name By default, no user object is specified, and the default user object class on the LDAP server is used. Creating an LDAP scheme You can configure up to 16 LDAP schemes. An LDAP scheme can be referenced by multiple ISP domains. To create an LDAP scheme: Step 1. Enter system view. 2. Create an LDAP scheme and enter its view. Command system-view Remarks N/A ldap scheme ldap-scheme-name By default, no LDAP scheme is defined. Specifying the LDAP authentication server Step 1. Enter system view. 2. Enter LDAP scheme view. 3. Specify the LDAP authentication server. Command system-view ldap scheme ldap-scheme-name authentication-server server-name Remarks N/A N/A By default, no LDAP authentication server is specified. Displaying and maintaining LDAP Execute the display command in any view. 39

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276

39
User object class
If the LDAP server contains many directory levels, a user DN search starting from the root directory can
take a long time. You can change the start point by specifying the search base DN to improve search
efficiency.
To configure LDAP user attributes:
Step
Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enter LDAP server view.
ldap server
server-name
N/A
3.
Specify the user search base
DN.
search-base-dn
base-dn
By default, no user search base DN
is specified.
4.
(Optional.) Specify the user
search scope.
search-scope
{
all-level
|
single-level
}
By default, the user search scope is
all-level
.
5.
(Optional.) Specify the
username attribute.
user-parameters
user-name-attribute
{
name-attribute
|
cn
|
uid
}
By default, the username attribute
is
cn
.
6.
(Optional.) Specify the
username format.
user-parameters
user-name-format
{
with-domain
|
without-domain
}
By default, the username format is
without-domain
.
7.
(Optional.) Specify the user
object class.
user-parameters user-object-class
object-class-name
By default, no user object is
specified, and the default user
object class on the LDAP server is
used.
Creating an LDAP scheme
You can configure up to 16 LDAP schemes. An LDAP scheme can be referenced by multiple ISP domains.
To create an LDAP scheme:
Step
Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Create an LDAP scheme
and enter its view.
ldap scheme
ldap-scheme-name
By default, no LDAP scheme is defined.
Specifying the LDAP authentication server
Step
Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enter LDAP scheme view.
ldap scheme
ldap-scheme-name
N/A
3.
Specify the LDAP
authentication server.
authentication-server
server-name
By default, no LDAP authentication
server is specified.
Displaying and maintaining LDAP
Execute the
display
command in any view.