Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Enjoy members-only rewards and discounts
  • Create and access a list of your products
  • Manage your Dell EMC sites, products, and product-level contacts using Company Administration.

Dell EMC OpenManage Enterprise 3.9 User's Guide

Directory services integration in OpenManage Enterprise

Pre-requisites/supported attributes for LDAP Integration

Directory Services enables you to import directory groups from AD or LDAP for use on the console. OpenManage Enterprise supports integration of the following directory services:
  1. Windows Active Directory
  2. Windows AD/LDS
  3. OpenLDAP
  4. PHP LDAP
Table 1. OpenManage Enterprise Pre-requisites/supported attributes for LDAP IntegrationSupported attributes for LDAP Integration
Attribute of User Login Attribute of Group Membership Certificate Requirement
AD/LDAP Cn, sAMAccountName Member
  • Subject to Domain Controller Certificate needs to have FQDN. SAN field can have IPv4 and/or IPv6 or FQDN.
  • Only Base64 certificate format is supported
OpenLDAP uid, sn Uniquemember Only PEM certificate format is supported
PHP LDAP uid MemberUid
You must ensure that the following user pre-requisites are met before you begin with the directory service integration:
  1. BindDN user and user used for 'Test connection' should be the same.
  2. If Attribute of User Login is provided, only the corresponding username value assigned to the attribute is allowed for appliance login.
  3. User used for Test connection should be part of any non-default group in LDAP
  4. Attribute of Group Membership should have either the 'userDN' or the short name (used for logging in) of the user.
  5. When MemberUid is used as 'Attribute of Group Membership,' the username used in appliance login will be considered case sensitive in some LDAP configurations.
  6. When search filter is used in LDAP configuration, user login is not allowed for those users who is not part of the search criteria mentioned.
  7. Group search will work only if the groups have users assigned under the provided Attribute of Group Membership .
NOTE If the OpenManage Enterprise is hosted on an IPv6 network, the SSL authentication against domain controller using FQDN would fail if IPv4 is set as preferred address in DNS. To avoid this failure, do one of the following:
  • DNS should be set to return IPv6 as preferred address when queried with FQDN.
  • DC certificate needs to have IPv6 in SAN field.

Rate this content

Accurate
Useful
Easy to understand
Was this article helpful?
0/3000 characters
  Please provide ratings (1-5 stars).
  Please provide ratings (1-5 stars).
  Please provide ratings (1-5 stars).
  Please select whether the article was helpful or not.
  Comments cannot contain these special characters: <>()\