Field | Description |
---|---|
Search Method | If users exist in multiple directories, select Criteria-based search across multiple directories. Otherwise, select Pattern to create the DN for users in a single directory. |
User Name Attribute | The attribute name that contains the user name, such as cn or name. |
User Search Base | When you search multiple directories, specify the starting directory that is used for searches, such as ou=employees,dc=mydomain,dc=com. |
Email Attribute | The attribute name that contains the email address, such as email or mail. |
User Search Filter | The LDAP filter expression to use when you search for group entries, such as (&(|(mail={0})(cn={0}))(objectclass=ePerson)). The user name replaces the {1} variable in the search pattern, and the full user DN replaces the {0} variable. If the value is not part of the DN pattern, enclose the value in parenthesis, for example, (accountName={0}). For more information, see the help information for your LDAP server and look for information about creating user search filters. |
Search User Subtree | When you search multiple directories, select this check box to search directories below the base directory. |
Field | Description |
---|---|
Search Method | To search for groups according to roles, select Look up group membership by searching for roles. To search for groups according to an attribute, select Look up group membership using this attribute, and specify the attribute in the User Group Attribute field. |
User Group Attribute | Specify the attribute that contains group names. This field is available only if you select Look up group membership using this attribute. |
Group Search Base | This field is available only if you select Look up group membership by searching for roles. |
Group Search Filter | Specify the LDAP filter expression for groups. You can use the {0} variable to represent the full user DN and the {1} variable to represent the user name. This field is available only if you select Look up group membership by searching for roles. |
Group Name | Specify the name of the entry that contains the user group names. This field is available only if you select Look up group membership by searching for roles. |
Search Group Subtree | Select this check box to search the full subtree for groups. This field is available only if you select Look up group membership by searching for roles. |