Authentication Servers field descriptions

Last Updated : May 14, 2020 |

Provision First and Second LDAP Server

Name

Description

IP (or DNS)

The IP address or the DNS name of the LDAP server.

TCP Port

The TCP port of the LDAP server.

Base Distinguished Name

The base distinguished name of the LDAP server.

SSL/TLS Mode

The connection type supported by the LDAP server.

Is Active Directory

The field to select if active directory does not support anonymous binding.

Supports Anonymous Binding

The field to select if active directory supports anonymous binding.

Supports Anonymous Binding field is inactive if Is Active Directory field is enabled.

Distinguished Name for Root Binding

The distinguished name for the root binding. For example, type cn for Users.

Password for Root Binding

The password for the root binding in this field.

From Release 8.1.3, you can enter up to 256 characters for the LDAP server authentication.

Provision Radius Server

Name

Description

IP (or DNS)

The IP address or the DNS name of the primary RADIUS server.

UDP Port

The UDP port number of the primary RADIUS server.

Shared Secret

The shared secret of the RADIUS server.

Provision Kerberos Server

Name

Description

DC Host Name (FQDN)

The FQDN in the following format: machineName.domainName.com/net/.

DC Computer Domain

The domain name of the Kerberos server.

Keytab File

The field to select the encrypted Kerberos server key.

Provision SAML Remote Identity Provider

Name

Description

Entity ID

The entity ID of the provisioned SAML remote identity provider.

The text -- not configured -- is displayed if a Remote Identity Provider is not configured.

Metadata Type

The method to query the metadata for Remote Identity Provider. The options are:

  • URL. A valid HTTP URL.

  • File. A valid XML file.

Metadata Url

The valid HTTP URL for the metadata of Remote Identity Provider.

This field is disabled if the File option is selected in the Metadata Type field.

Metadata File

The valid XML file for the metadata of Remote Identity Provider.

This field is disabled if the URL option is selected in the Metadata Type field.

Choose File

The field to select an XML file that contains the metadata for Remote Identity Provider.

Provision User Certificate Authentication

Name

Description

Certificate Purpose

The purpose of the certification, such as Client Authentication.

Certificate Field Name to get User Name

The fields that can be used to retrieve the username from the certificate.

The left section contains the fields that can be read from the certificate. The right section contains the fields that the system will read from the certificate.

Button

Description

Remove

Removes the selected client purpose.

Add

Adds the typed client purpose.

>>

Moves the selected certificate field to the right pane.

<<

Moves the selected certificate field to the left pane.

Up

Increments the priority of the selected certificate field.

Down

Decrements the priority of the selected certificate field.

Button

Description

Save

Saves your settings on the Authentication Servers page.

Cancel

Cancels your action and takes you to the earlier page.