When the Authentication Mechanism
service attribute is set to Enterprise
, Presence Services offers a combination of Basic, IWA/Kerberos, or OAuth2/JWT to the clients. The setting of other configuration attributes decide this. If the requirements of an authentication protocol are met, it is offered by the server to the clients.
|
Basic Basic authentication is offered only when at least one Enterprise Directory Group is configured correctly.
|
IWAIWA takes only the default Enterprise Directly Group into account and is offered only when this group’s settings are correct.,IWA also requires the Keytab file to be uploaded to the server. If not, IWA is not offered.
|
OAuth2
|
|
Applicable Domains
|
Required
|
N/A
|
N/A
|
|
Directory URL
|
Required
|
Required
|
N/A
|
|
Directory User DN
|
RequiredIf Directory User DN is provided, Directory User Password must be provided. If anonymous access is desired, both attributes must be blank. Also, note that in such cases, the directory should be configured to allow anonymous access.
|
Required4
|
N/A
|
|
Directory User Password
|
Required4
|
Required4
|
N/A
|
|
User Search Base
|
Optional
|
Optional
|
N/A
|
|
User Mapping Directory Attribute
|
Required
|
Required
|
N/A
|
|
User Identity Directory Attribute
|
Required
|
Required
|
N/A
|
|
Kerberos Service Principal
|
N/A
|
Required
|
N/A
|
|
OAuth2 - Authentication Server Public Key
|
N/A
|
N/A
|
Required
|
|
OAuth2 - User Id Token Key
|
N/A
|
N/A
|
Required
|
|
OAuth2 - JWT Algorithm
|
N/A
|
N/A
|
Required
|