Standalone VGA Grid User Guide
User administration
10. By default the search attribute is
uid
, which is suitable for a unix environment. Specify a different value
in the
Search attribute
field, if needed. For Active Directory environments, specify
userPrincipalName
. The value of this attribute must be unique in the Base DN.
11. In the
Administrators (group DN)
field, specify the distinguished name of the group users must be
part of to be logged in as the administrator. Users must have the
member
or
unqueMember
attribute
for the specified group to be granted Administrator access.
If left blank, LDAP is not supported for Administrators (but can still be used for Operators and Viewers).
12. In the
Operators (group DN)
field, specify the distinguished name of the group users must be part of
to be logged in as the operator. Users must have the
member
or
unqueMember
attribute for the
specified group to be granted Operator access.
If left blank, LDAP is not supported for Operators (but can still be used for Administrators and Viewers).
13. In the
Viewers (group DN)
field, specify the distinguished name of the group users must be part of to
be logged in as a viewer. Users must have the
member
or
unqueMember
attribute for the specified
group to be granted Viewer access.
If left blank, LDAP is not supported for Viewers (but can still be used for Administrators and Operators).
14. Click
Apply
.
When a user of the LDAP server next visits the admin or viewer page for the system, the system prompts for
use the username and password. For ActiveDirectory servers, the user needs to enter his fully qualified
username (i.e. username@domainname) in addition to his LDAP password.
Users are required to authenticate once to the system and one time per channel they view.
Therefore users see a prompt to log in to the system (the system name is shown) and a second
time to log in to the channel (the channel name is shown).
In one case, LDAP replaces the local
viewer
account instead of working side-by-side with it.
When LDAP is enabled and the viewer account has no password (either there is no global viewer
password or the channel overrides the global password with a blank password), the viewer must
authentication with LDAP, he may
not
alternatively use the
viewer
account with a blank
password.
Change the logged-in user
When you log in to the web interface as admin or operator, your browser remembers this configuration and
automatically logs you in as the same user when you go back to the site.
Sometimes you need to change from operator to admin, or vice versa.
40