Configuring a Domino user directory as a user store is a three-step process:
A Domino user directory is an LDAP directory. Be sure that the Domino user directory meets the following prerequisites before you configure it as a user store:
Example: When adding the group marketing/myorg.org to the address book (names.nsf) in Lotus Notes, type o=myorg.org in the Root field on the User Directory screen.
Note: We recommend that you register users when you add them to a Domino user directory. This additional step prevents multiple user name entries in the Domino user directory. When there are multiple entries in the directory, the Policy Server uses the first one. Attempts to log in with other user names fail.
Pinging the user store system verifies that a network connection exists between the Policy Server and the user directory or database.
Note: Some user store systems may require the Policy Server to present credentials.
You can configure a user directory connection that lets the Policy Server communicate with a Domino user store.
Follow these steps:
Objects related to user directories appear on the left.
The User Directories screen appears.
The Create User Directory screen appears and displays the required settings to configure an LDAP connection.
Note: Click Help for descriptions of settings and controls, including their respective requirements and limits.
Note: If the Policy Server is operating in FIPS mode and the directory connection is to use a secure SSL connection when communicating with the Policy Server, the certificates used by the Policy Server and the directory store must be FIPS compliant.
Note: The value that you specify in Root must match the organization name that you assigned in Lotus Notes. The Root must also include a country, if you specified a country in Lotus Notes.
Example: You have an organization called "myorg", which is located in the United States. The Search Root is specified as o=myorg,c=us.
Note: The search strings that you specify in the User DN Lookup Start and End fields must adhere to proper LDAP notation, not the Lotus Notes shorthand notation. More information about search strings exists in LDAP Search Filters.
Note: More information about load balancing and failover, see LDAP Load Balancing and Failover.
The user directory connection is created.
Copyright © 2013 CA.
All rights reserved.
|
|