In this scenario, user credentials are kept in an LDAP server external to Web Central.
The security service:
For information on configuring this scenario, see Configuring the LDAP Authentication Use Case.
The following diagram illustrates LDAP authentication dependencies:
When you use an LDAP server for authentication, you need to map the user’s LDAP account to an ARCHIBUS account in the afm_users table.
There are three methods.
Active Directory (AD) users are mapped to their own unique ARCHIBUS identity. For instance, BIGUNIV\smith is mapped to the smith ARCHIBUS user, and BIGUNIV\davies is mapped to the davies ARCHIBUS user.
All LDAP accounts are mapped to a single ARCHIBUS account (by default "AFM").
Each LDAP account has an authority (LDAP Group) with the specified prefix (by default, "Afm"). The LDAP Group with the specified prefix (Afm) will be used as the ARCHIBUS account name. For example:
For example:
Copyright © 1984-2014, ARCHIBUS, Inc. All rights reserved. |