Previous Topic: Create a Common View of the Same User Information Across DirectoriesNext Topic: Alias Attribute Use Case


Establish Connections to User Directories

Before you can establish user attribute mappings, establish connections to the user directories that store user records.

LDAP or ODBC are the two types of directories to which the product can connect.

Follow these steps:

  1. Click the User Directory tab.
  2. Click Connect to LDAP or ODBC.
  3. Configure the settings in each section. Required parameters are marked by red dots.

    Note: Click Help for a description of fields, controls, and their respective requirements.

  4. Click Failover or Load Balancing if you want to set up either of these features.
  5. Click Test Connection to verify that the connection is valid.

    You can click View Contents to list the contents of the user directory.

    Note:

  6. Click Save.

    If your settings are valid, you are redirected to the View User Directories dialog.

    The connection to the directory is configured.

Configure User Attribute Mappings

Use one or more of the following mapping types to define attribute mappings:

The following table lists the type of data you can enter in the mapping definition. Define individual mappings for each user directory in your deployment.

Mapping Type

Map Common Name to...

Data Types

Access

Alias

A user attribute name in the directory.

String, Number, Boolean

Read/Write

Group name

An attribute that identifies whether a user belongs to a specific group.

Boolean

Read/Write

Mask

A user attribute that stores a bit pattern.

Boolean

Read/Write

Constant

A value that is the same or constant for every user in a directory.

String, Number, Boolean

Read

Expression

To an expression.

For complete syntax information, see the Attributes and Expression Reference appendix in the SiteMinder Policy Server Configuration Guide. This guide is part of the SiteMinder bookshelf.

String, Number, Boolean

Read

The configuration procedures for each mapping type are basically the same. Refer to the use cases for each mapping type for implementation examples.

Follow these steps:

  1. In the Administrative UI, navigate to the User Directory tab.
  2. Select one of the Connect to options in the User Directory List.
  3. Verify that a user directory connection is configured or configure one.
  4. Scroll to the Directory Mapping Attribute section and select Create Mapping.
  5. Complete the General fields:
    Name

    Specify the common name for this mapping. Common names must conform to the same rules as user attribute names.

    Description

    Enter a description of the attribute mapping.

  6. Complete the Properties fields:
    Mapping type

    Select the mapping type that you want to configure.

    Definition

    Enter the mapping definition using the appropriate syntax. Refer to the previous table.

  7. (Optional) Select Disabled to disable an attribute mapping.
  8. Click Save.

The new attribute mapping is submitted and then added to the list on the Attribute Mapping List table.