...
Configure LDAP Directory Manager
Image Added
Figure 1: Configure LDAP Directory Manager
Name | Value | Screen (Click to view) |
---|
URL | - ldap://IP_ADDRESS:389
- ldaps://IP_ADDRESS:636
| Image Removed Figure 1: Configure LDAP Directory Manager |
Admin Username (Principal) | LDAP username with read permission to LDAP/AD. Example: cn=admin,dc=joget,dc=org |
Admin Password (Credential) | admin |
| DC=joget,DC=org |
Users
Image Added
Figure 2: Users Properties
Name | Value | Screen (Click to view) |
---|
User Base DN | User Base DN Info |
---|
| If you set the "User Base DN" to your LDAP Root DN, it means that the search will start from the Root DN until it finds all the results that matched the search filter. So, setting the "User Base DN" precisely is very important as it will decide where the search is starting from. It will save all the unnecessary search between the Root DN to your "User Base DN". Code Block |
---|
| DC=joget,DC=org |
Code Block |
---|
title | Under the Root DN, you have the following DN: |
---|
| DC=HR,DC=joget,DC=org
DC=Product Department,DC=joget,DC=org
DC=Operation,DC=joget,DC=org
DC=Users,DC=joget,DC=org |
If your users are all under "DC=Users,DC=joget,DC=org", you should set this to "User Base DN". By doing this, it will not go through all the other entries and it's child entries before reaching "DC=Users,DC=joget,DC=org". |
| Image Removed |
Figure 2: Users Properties |
User Import Search Filter | (objectClass=person) Info |
---|
| Code Block |
---|
| (&(objectClass=person)(|(cn=admin)(cn=cat)(cn=jack)(cn=john)(cn=jackie))) |
This mean all the LDAP entries which have "objectClass" attribute equals to "person" and "cn" attribute equals to either "admin", "cat", "jack", "john" or "jackie" are Joget users. So, when a login is performed by "admin", the search filter will add additional filter and become "(&(&(objectClass=person)(|(cn=admin)(cn=cat)(cn=jack)(cn=john)(cn=jackie)))(cn=admin))". You will notice an extra (cn=admin) is added to the search filter to make sure it return only the "admin" user. |
Info |
---|
| User license determines on how many eventual users (sorted alphabetically) from your LDAP/AD can log in into the system. You can make use of this attribute to control amount of users returned from your LDAP. |
Please refer to other LDAP Search Filter syntax. |
Attribute Mapping - Username | cn |
Attribute Mapping - First Name | givenName |
Attribute Mapping - Last Name | sn |
Attribute Mapping - Email | mail |
Attribute Mapping - Status |
|
Attribute Mapping - Time Zone | 8 |
Attribute Mapping - Locale | en_US |
Employment
Image AddedUser
Figure 3: Employment Properties
Name | Value | Screen (Click to view) |
---|
Attribute Mapping - Employee Code | Image Removed
Figure 3: Employment Properties |
|
Attribute Mapping - Job Title |
|
Attribute Mapping - Report To |
|
Map To "Report To" Entry Attribute |
|
Attribute Mapping - Groups |
|
Map To LDAP Group Entry Primary Attribute | dn Info |
---|
| A distinguished name (usually just shortened to “DN”) uniquely identifies an entry and describes its position in the DIT. ... DNs are comprised of zero or more comma-separated components called relative distinguished names, or RDNs. Directory Service | DN Entity Name |
---|
OpenLDAP | entryDN | Microsoft AD | distinguishedName |
|
|
Attribute Mapping - Departments |
|
Map To LDAP Department Entry Primary Attribute | dn |
Attribute Mapping - Grade |
|
Map To LDAP Grade Entry Primary Attribute | dn |
Attribute Mapping - Metas | Additional attributes to retrieve using #user.USERNAME.meta.KEY# or #currentUser.meta.KEY#
Name | Description |
---|
Key | Key name | Attribute | Attribute name in LDAP |
|
Group
Image Added
Figure 4: Group Properties
Name | Value | Screen (Click to view) |
---|
| Image Removed | Figure 4:
|
| PropertiesGroup Import Search Filter | (objectClass=groupOfNames) Please refer to other LDAP Search Filter syntax. |
| cn |
| description |
Attribute Mapping - Description | description |
Attribute Mapping - Users | member |
Map To LDAP User Entry Primary Attribute | dn |
Department
Image Added
Figure 5: Department Properties
Name | Value | Screen (Click to view) |
---|
Department Base DN | Image Removed
Figure 5: Department Properties |
|
Department Import Search Filter | (objectClass=groupOfNames) Please refer to other LDAP Search Filter syntax. |
Attribute Mapping - ID | cn |
Attribute Mapping - Name | description |
Attribute Mapping - Description | description |
Attribute Mapping - HOD | owner |
Attribute Mapping - Users | member Info |
---|
| If the department object itself contains the users that belong to the department, define the attribute name here. For example, in the figure below, we can define "member" as the value here. There's no need to define anything else in "Employment" tab earlier for this case. Image Modified |
|
Map To LDAP User Entry Primary Attribute | dn
|
...