...
Configure LDAP Directory Manager
Image Modified
Figure 1: Configure LDAP Directory Manager
Name | Value |
---|
URL | - ldap://IP_ADDRESS:389
- ldaps://IP_ADDRESS:636
|
Admin Username (Principal) | LDAP username with read permission to LDAP/AD. Example: cn=admin,dc=joget,dc=org |
Admin Password (Credential) | admin |
| DC=joget,DC=org |
Users
Image Modified
Figure 2: Users Properties
Name | Value | Screen (Click to view) |
---|
User Base DN | User Base DN Info |
---|
| If you set the "User Base DN" to your LDAP Root DN, it means that the search will start from the Root DN until it finds all the results that matched the search filter. So, setting the "User Base DN" precisely is very important as it will decide where the search is starting from. It will save all the unnecessary search between the Root DN to your "User Base DN". Code Block |
---|
| DC=joget,DC=org |
Code Block |
---|
title | Under the Root DN, you have the following DN: |
---|
| DC=HR,DC=joget,DC=org
DC=Product Department,DC=joget,DC=org
DC=Operation,DC=joget,DC=org
DC=Users,DC=joget,DC=org |
If your users are all under "DC=Users,DC=joget,DC=org", you should set this to "User Base DN". By doing this, it will not go through all the other entries and it's child entries before reaching "DC=Users,DC=joget,DC=org". |
|
Figure 2: Users Properties |
User Import Search Filter | (objectClass=person) Info |
---|
| Code Block |
---|
| (&(objectClass=person)(|(cn=admin)(cn=cat)(cn=jack)(cn=john)(cn=jackie))) |
This mean all the LDAP entries which have "objectClass" attribute equals to "person" and "cn" attribute equals to either "admin", "cat", "jack", "john" or "jackie" are Joget users. So, when a login is performed by "admin", the search filter will add additional filter and become "(&(&(objectClass=person)(|(cn=admin)(cn=cat)(cn=jack)(cn=john)(cn=jackie)))(cn=admin))". You will notice an extra (cn=admin) is added to the search filter to make sure it return only the "admin" user. |
Info |
---|
| User license determines on how many eventual users (sorted alphabetically) from your LDAP/AD can log in into the system. You can make use of this attribute to control amount of users returned from your LDAP. |
Please refer to other LDAP Search Filter syntax. |
Attribute Mapping - Username | cn |
Attribute Mapping - First Name | givenName |
Attribute Mapping - Last Name | sn |
Attribute Mapping - Email | mail |
Attribute Mapping - Status |
|
Attribute Mapping - Time Zone | 8 |
Attribute Mapping - Locale | en_US |
Employment
Image Modified
Figure 3: Employment Properties
Name | Value |
---|
Attribute Mapping - Employee Code |
|
Attribute Mapping - Job Title |
|
Attribute Mapping - Report To |
|
Map To "Report To" Entry Attribute |
|
Attribute Mapping - Groups |
|
Map To LDAP Group Entry Primary Attribute | dn Info |
---|
| A distinguished name (usually just shortened to “DN”) uniquely identifies an entry and describes its position in the DIT. ... DNs are comprised of zero or more comma-separated components called relative distinguished names, or RDNs. Directory Service | DN Entity Name |
---|
OpenLDAP | entryDN | Microsoft AD | distinguishedName |
|
|
Attribute Mapping - Departments |
|
Map To LDAP Department Entry Primary Attribute | dn |
Attribute Mapping - Grade |
|
Map To LDAP Grade Entry Primary Attribute | dn |
Attribute Mapping - Metas | Additional attributes to retrieve using #user.USERNAME.meta.KEY# or #currentUser.meta.KEY#
Name | Description |
---|
Key | Key name | Attribute | Attribute name in LDAP |
|
Group
Image Modified
Figure 4: Group Properties
Name | Value |
---|
|
|
Group Import Search Filter | (objectClass=groupOfNames) Please refer to other LDAP Search Filter syntax. |
| cn |
| description |
Attribute Mapping - Description | description |
Attribute Mapping - Users | member |
Map To LDAP User Entry Primary Attribute | dn |
Department
Image Modified
Figure 5: Department Properties
Name | Value |
---|
Department Base DN |
|
Department Import Search Filter | (objectClass=groupOfNames) Please refer to other LDAP Search Filter syntax. |
Attribute Mapping - ID | cn |
Attribute Mapping - Name | description |
Attribute Mapping - Description | description |
Attribute Mapping - HOD | owner |
Attribute Mapping - Users | member Info |
---|
| If the department object itself contains the users that belong to the department, define the attribute name here. For example, in the figure below, we can define "member" as the value here. There's no need to define anything else in "Employment" tab earlier for this case. 
|
|
Map To LDAP User Entry Primary Attribute | dn
|
Grade
Image Modified
Figure 6: Grade Properties
Name | Value |
---|
|
|
Grade Import Search Filter | Please refer to other LDAP Search Filter syntax. |
|
|
|
|
Attribute Mapping - Description |
|
Attribute Mapping - Users |
|
Map To LDAP User Entry Primary Attribute |
|
Admin Role
Image Modified
Figure 7: Admin Role Properties
Name | Value |
---|
Admin Role Base DN |
|
Admin Role Import Search Filter | (&(objectClass=person)(cn=admin)) Please refer to other LDAP Search Filter syntax. |
Attribute Mapping - Users | cn |
Map To LDAP User Entry Primary Attribute | dn |
Advanced
Image Modified
Figure 8: Advance Properties
...