www.eaton.com
Network
Management Card
(Network-MS)
User Manual
Network Management Card
– User Manual
34003991XT_EN/JC
Page
58/143
4.4.3.2 Authorization management
When an authorization mode is set, the “
UPSAdministrators
” string is searched in the LDAP Directory.
Consequently, the LDAP Directory must be updated in the following way to allow users to open Web session in
the NCM card:
•
If the mode is “
By User Attribute
”: the administrator must set the LDAP attribute defined by the "
Group
Name Attribute
" with the “
UPSAdministrators
” value. This update must be done for all allowed users.
•
If the mode is “
By Group
”: the LDAP administrator must create a group with the following properties :
o
The location of this group in the LDAP directory must set under the DN path set in the
UPS
Group Base DN
value
.
o
The attribute defined in the
Group Name Attribute
must be set with the
“
UPSAdministrators
”
value.
o
All allowed users must be declared as member of this group: the multi valued attribute defined
in the
User Name Attribute
must be set with all allowed users DN .
4.4.3.3 MD5 Authentication Mechanism
When MD5 is set as Authentication Mechanism, the following rule must be applied:
•
A DNS server must be registered in the Network Configuration of the card.
•
A DNS reverse lookup must be possible for the LDAP IP server.
•
If an Accredited User is used for the LDAP search, its name is no longer a DN but a SASL name.
•
The user login must be compliant with the SASL name rules of the LDAP server used.
4.4.3.4 Typical Setting Values for Active Directory
If the LDAP server is Active Directory, the following values are usually employed:
For user settings :
•
User Object
: user
•
User Attribute:
sAMAccountName
For Authorization settings when the group mode is set:
•
Group Name Attribute:
sAMAccountName
•
User Name Attribute:
member