User Manual DEV 5072
38
Copyright DEV Systemtechnik GmbH 2016-2017
A stored certificate can be deleted by operating the button
plus the
confirmation via the appearing pop up window.
For the "Account" and "Password" entries a service LDAP user is to be entered who
has access to the directory structure of the LDAP server.
"Base DN" defines the distinguished name (DN) for accessing the naming structure
of the LDAP server, e.g.
uid=user,ou=people,dc=example,dc=com
and "Login Attribute" may be
used to add the LDAP login attribute, e.g.
sAMAccountName
.
Finally, a click on the
button applies the changes made.
Note:
If the active authorization method is "RADIUS" (or "LDAP"), all approved users
of the RADIUS (or of the LDAP) server may access the device using their RADIUS
(or their LDAP) authentication.
Passwords (except the password of the ADMIN user) cannot be changed locally
if the active authorization method is "RADIUS" (or "LDAP").
The first login of a RADIUS (or LDAP) user generates a local account providing
"read" permission. A user with "admin" permission may alter the permission
for each 'registered' user (chapter 5.4.6.1.3).
If using LDAP as authorization method, LDAP specific error messages (here e.g.
"Can't contact LDAP server" during login) are passed via pop up window:
If the configured RADIUS (or LDAP) server is not available during login, the local
account is used for authentication.
The local ADMIN user has always access to the device, independent from the
active authorization method.