Lightweight Directory Access Protocol (LDAP) ============================================ Introduction ------------ TRiA supports using Lightweight Directory Access Protocol ("LDAP") authentication as a valid authentication server. This document details configuring TRiA for use with an LDAP instance as an authentication server for users to authenticate against when logging in. You will need Administrative credentials to your LDAP instance. LDAP Authentication Server Setup ================================ To create an LDAP Authentication Server: 1. Click ``Identity Management`` from the navigation sidebar, and then click ``Authentication Servers``, near the top of the window. 2. Click ``Add Server`` 3. Enter whatever you like for the nickname, and then select 'LDAP' for the ``Server Type``. 4. For ``Server Host/IP``, enter the server or hostname for the LDAP instance. This is often represented as 'dc.yourdomain.com'. Do not include any protocol or port information here. 5. For ``Server Port``, you should supply the port your LDAP instance is configured to listen at. Port '389' is supplied by default as it is the default LDAP port. If your LDAP is configured to use SSL, the default port is '636'. If your LDAP instance has been configured to use any other port, supply that value here. 6. Select the ``Secure Server`` checkbox if your LDAP instance has been configured to use SSL. 7. For ``Admin Username``, enter the Distinguished Name ("DN") of a user account with 'bind' privileges. The DN is usually represented as "CN=Your Name,OU=Your Organization,DC=YourCompanyName,DC=Com). 8. For ``Admin Password``, enter the password credential of the user account specified in ``Admin Username``. 9. For ``Base User DN``, enter the search string applicable to where user accounts are situated within the directory. Usually, this looks something like "CN=Users,DC=YourCompanyName,DC=Com". It is important here to provide the most specific possible search string. A search string of "DC=YourCompanyName,DC=Com" _might_ work depending on how the directory was configured, but will result in inefficient lookups which are taxing to the LDAP instance, and could result in timeouts while users attempt to authenticate. We will verify that the credentials you submitted are correct when you click ``Submit`` and that the account provided has the required 'bind' privilege. If an error message appears, please check that the values you entered are correct for the LDAP instance you are trying to authenticate to.