aXsGUARD Identifier 3.0.2.0 Product Guide v1.5
LDAP User Synchronization
LDAP Synchronization Profiles define:
where the source LDAP Server is located
which User Accounts from the source need to be synchronized (filtering)
whether existing User Accounts on the aXsGUARD Identifier can be updated with data from the source LDAP
Server
the destination for the new or updated User Accounts on the aXsGUARD Identifier
the frequency of synchronizations
how to map LDAP Server User Account Attributes to aXsGUARD Identifier Properties. (Please note that User
Account settings are called source
Attributes
in the LDAP Server and destination
Properties
in the aXsGUARD
Identifier.)
For a full listing and explanations of the fields for LDAP Synchronization Profiles, please refer to the
aXsGUARD
Identifier Administration Reference Guide,
'Configuration Tool: Field Listings' section.
Example mappings of LDAP Server User Account Attributes to aXsGUARD Identifier User Account Properties are
listed
in the
aXsGUARD Identifier Installation Guide
.
Note:
For most LDAP Servers, the LDAP User password attribute cannot be mapped to an aXsGUARD
Identifier User Account password due to security settings on the LDAP Server.
Once the appropriate settings and mappings have been configured, synchronization is automatic. LDAP
Synchronization of User Accounts is from the LDAP Server (source) towards the aXsGUARD Identifier (destination)
and is not bidirectional.
14.3
Synchronization Profile IDs
The Synchronization Profile ID is used to track the source status of a User Account, i.e. whether the User Account
was created through a synchronization or by another method. Each Synchronization Profile has a unique ID. User
Accounts created or updated by a Synchronization Profile have the corresponding Synchronization Profile ID added.
The specific aXsGUARD Identifier User Account Properties which are updated or created by the synchronization
depend on the
Attribute Mapping
entries in the Synchronization Profile.
The 'User Attributes' screen in the aXsGUARD Identifier (see image below) identifies User Accounts which have
been synchronized from an LDAP Server.
Example
In the example shown in the image below, the User Account 'annelies' has been synchronized by a Synchronization Profile with the
ID, 'AD2003'.
©
2009 VASCO Data Security
82