Service attribute requirements for enterprise authentication

Last Updated : Oct 05, 2020 |
Prolog information
When the Authentication Mechanism service attribute is set to Enterprise, Presence Services offers a combination of Basic, IWA/Kerberos, or OAuth2/JWT to the clients. The setting of other configuration attributes decide this. If the requirements of an authentication protocol are met, it is offered by the server to the clients.
Basic Basic authentication is offered only when at least one Enterprise Directory Group is configured correctly.
IWAIWA takes only the default Enterprise Directly Group into account and is offered only when this group’s settings are correct.,IWA also requires the Keytab file to be uploaded to the server. If not, IWA is not offered.
OAuth2
Applicable Domains
Required
N/A
N/A
Directory URL
Required
Required
N/A
Directory User DN
RequiredIf Directory User DN is provided, Directory User Password must be provided. If anonymous access is desired, both attributes must be blank. Also, note that in such cases, the directory should be configured to allow anonymous access.
Required4
N/A
Directory User Password
Required4
Required4
N/A
User Search Base
Optional
Optional
N/A
User Mapping Directory Attribute
Required
Required
N/A
User Identity Directory Attribute
Required
Required
N/A
Kerberos Service Principal
N/A
Required
N/A
OAuth2 - Authentication Server Public Key
N/A
N/A
Required
OAuth2 - User Id Token Key
N/A
N/A
Required
OAuth2 - JWT Algorithm
N/A
N/A
Required
  • N/A = Not applicable in the context of this authentication mechanism