Previous Topic: Auto Enrollment LDAP UsersNext Topic: Security System Checking Order for Mainframe and LDAP Authentications


LDAP User Generation

When a user enrolls in a role automatically, and if the user does not exist, CA OM Web Viewer creates a user object. The new User object has several of its fields auto-populated from your LDAP directory. For this auto population to occur, your LDAP system must support this kind of lookup, and use the appropriate naming conventions.

Note: Only newly created users have their attributes populated, existing users are not modified even if they are automatically enrolled in a role.

The following LDAP attributes automatically map to the equivalent values in the CA OM Web Viewer User object.

LDAP Attributes Automatically Imported

Web Viewer Mapping

Administrator supplied Login Attribute, defined at creation of a Directory object or from the Role profile section of the edit/create Role panel.

User ID

givenName

First Name

sn

Last Name

title

Title

For more information about the User object fields, see Editing User Objects in the User section.

External Security EXIT

The External Security EXIT uses Java programming interface as exit calls to external authentication functions (customer supplied) to authenticate domain/network users for mainframe report access. This is an integration solution to the customer existing Single-Sign-On system.