Lexmark MS517 Embedded Web Server--Security: Administrator s Guide - Page 16

Editing an LDAP setup, Use Active Directory Device Credentials

Page 16 highlights

Managing authentication and authorization methods 16 • Mail Attribute-Type a maximum of 48 characters to identify e‑mail addresses. The default value is "mail." • Full Name Attribute-Type a maximum of 48 characters. The default value is "cn." • Search Base-The node in the LDAP server where user accounts reside. You can enter multiple search bases, separated by commas. Note: A search base consists of multiple attributes separated by commas, such as cn (common name), ou (organizational unit), o (organization), c (country), and dc (domain). • Search Timeout-Enter a value from 5 to 30 seconds or 5 to 300 seconds, depending on your printer model. • Required User Input-Select either User ID and password or User ID to specify which credentials a user must provide when attempting to access a function protected by the LDAP building block. User ID and password is the default setting. Device Credentials • Use Active Directory Device Credentials-Allow user credentials and group designations to be pulled from the existing network comparable to other network services. • Anonymous LDAP Bind-Bind the Embedded Web Server with the LDAP server anonymously, and make the Distinguished Name and MFP Password fields unavailable. • Distinguished Name-Type the distinguished name of the print server. • MFP's Password-Type the password for the print server. Search specific object classes • Person-Allow the "person" object class to be searched. • Custom Object Class-Allow the custom search object class to be searched. You can define up to three custom search object classes. LDAP Group Names • Administrators can associate as many as 32 named groups stored on the LDAP server by entering identifiers for those groups under the Group Search Base list. Both the Short name for group and Group Identifier must be provided. • When creating security templates, you can pick groups from this setup for controlling access to device functions. 4 Click Submit to save the changes, or Cancel to return to previous values. Editing an LDAP setup 1 From the Embedded Web Server, click Settings > Security > Security Setup. 2 Under Advanced Security Setup, click LDAP. 3 Click a setup from the list. 4 Make any needed changes in the LDAP Configuration dialog. 5 Click Modify to save the changes, or click Cancel to return to previous values. Deleting an LDAP setup 1 From the Embedded Web Server, click Settings > Security > Security Setup. 2 Under Advanced Security Setup, click LDAP.

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93

Mail Attribute
—Type a maximum of 48 characters to identify e
mail addresses. The default value is
“mail.”
Full Name Attribute
—Type a maximum of 48 characters. The default value is “cn.”
Search Base
—The node in the LDAP server where user accounts reside. You can enter multiple search
bases, separated by commas.
Note:
A search base consists of multiple attributes separated by commas, such as cn (common name),
ou (organizational unit), o (organization), c (country), and dc (domain).
Search Timeout
—Enter a value from 5 to 30 seconds or 5 to 300 seconds, depending on your printer
model.
Required User Input
—Select either
User ID and password
or
User ID
to specify which credentials a
user must provide when attempting to access a function protected by the LDAP building block.
User ID
and password
is the default setting.
Device Credentials
Use Active Directory Device Credentials
—Allow user credentials and group designations to be pulled
from the existing network comparable to other network services.
Anonymous LDAP Bind
—Bind the Embedded Web Server with the LDAP server anonymously, and make
the Distinguished Name and MFP Password fields unavailable.
Distinguished Name
—Type the distinguished name of the print server.
MFP’s Password
—Type the password for the print server.
Search specific object classes
Person
—Allow the “person” object class to be searched.
Custom Object Class
—Allow the custom search object class to be searched. You can define up to three
custom search object classes.
LDAP Group Names
Administrators can associate as many as 32 named groups stored on the LDAP server by entering
identifiers for those groups under the Group Search Base list. Both the
Short name for group
and
Group
Identifier
must be provided.
When creating security templates, you can pick groups from this setup for controlling access to device
functions.
4
Click
Submit
to save the changes, or
Cancel
to return to previous values.
Editing an LDAP setup
1
From the Embedded Web Server, click
Settings
>
Security
>
Security Setup
.
2
Under Advanced Security Setup, click
LDAP
.
3
Click a setup from the list.
4
Make any needed changes in the LDAP Configuration dialog.
5
Click
Modify
to save the changes, or click
Cancel
to return to previous values.
Deleting an LDAP setup
1
From the Embedded Web Server, click
Settings
>
Security
>
Security Setup
.
2
Under Advanced Security Setup, click
LDAP
.
Managing authentication and authorization methods
16