You can authenticate the users of an organization (mapped to LDAP repository) by using their LDAP attributes. You must use the performQnAVerification operation to perform this authentication. This section walks you through the following steps related to this operation:
The following table lists the elements of the QnAVerificationRequest message.
|
Element |
Mandatory |
Description |
|---|---|---|
|
username |
Yes |
The unique identifier of the user whose attributes you want to verify. |
|
orgname |
Yes |
The name of the LDAP organization to which the user belongs. |
|
attributes/attribute |
Yes |
The name (attrName) and value (attrValue) of the attribute that has to be verified. |
|
ignorecase |
Yes |
Specifies whether the case of the attribute values passed in the input must match the case of the values stored in the directory service:
|
|
clientTxId |
No |
The unique transaction identifier that your calling application can include. This identifier helps in tracking the related transactions. |
To authenticate users with their LDAP attributes:
This operation returns the QnAVerificationResponse message that includes the transaction identifier, authentication token, and verification result. See the following section for more information on the response message.
The response message, QnAAVerificationResponse, returns the transaction identifier and the authentication token in the SOAP envelope header. The SOAP body includes the verification result for each attribute and the Fault response for an error condition.
See the following table for more information on the elements returned for a successful transaction. Refer to appendix, "Exceptions and Error Codes" if there are any errors.
|
Element |
Description |
|
|---|---|---|
|
Header Elements |
||
|
udsTransactionID |
The unique identifier of the transaction performed by using UDS. |
|
|
authToken |
The authentication token that is returned if the credential verification to access the Web service was successful. This token eliminates the need for you to present the authentication credential for successive access to the Web service. By default, the authentication token is valid for one day, after which you need to authenticate again. |
|
|
Body Elements |
||
|
QnAResponseAttribute/name |
The name of the attribute that was verified. |
|
|
QnAResponseAttribute/result |
The result of the verification:
|
|
|
Copyright © 2013 CA.
All rights reserved.
|
|