Previous Topic: Setting Up LDAP AuthenticationNext Topic: Enable LDAP Authentication with No Authentication Mechanism


LDAP Support

Single Sign-On provides LDAP integration, allowing operators to authenticate to a Lightweight Directory Access Protocol (LDAP) server running in your environment. Once authenticated, they are mapped to a user account that the administrator can specify: either to a predefined user account, or to a custom account.

The Single Sign-On Configuration Tool lets you precisely specify how the Single Sign-On server connects to the LDAP server. You can also map individual CA Performance Center users to the user accounts that support their workflow while protecting sensitive data.

Note: Changes made in the Single Sign-On Configuration Tool only affect newly created LDAP users. They do not apply to existing LDAP users registered within CA Performance Center.

The LDAP parameters available in the Single Sign-On Configuration Tool let you integrate CA Infrastructure Management and all registered data sources into an existing authentication scheme. For example, the LDAP server can authorize groups of users who are mapped to a single custom user account in CA Performance Center. The actual account names and LDAP groups can be extensively customized. Search scope parameters let you determine how the directory search is conducted. And you can select the user account properties that are considered when validating users.