Macromedia live cycle 7.2 Manual

Page of 123
Adobe LiveCycle
Getting Started with BAM Server
Installing and Configuring LiveCycle for JBoss
 Configuring LDAP settings for BAM Server     94
LDAP Principal DN Suffix: For the simple authentication method, the text you specify will be 
inserted after the user's login name:
For LDAP servers that require DN login, set this to the appropriate chain of values. The first 
character of the suffix must be a comma (","). For example:
,ou=Users,dc=domain,dc=name
For ActiveDirectory, which requires a simple login with an email address, set this to an at symbol 
(
@
) followed by the domain name that is set for ActiveDirectory.
LDAP Synchronization User: The user that binds to the server and reads the lists of users and roles. 
For security purposes, you must specify a user account that can only read the LDAP directory.
LDAP Synchronization Password: The password associated with the user specified for the LDAP 
Synchronization User option.
6. Click Test Connection. The connection and the user mapping and role mapping configuration are 
tested. If the connection settings are correct, a message will indicate that the connection was 
successful. If you have not yet configured LDAP User Mapping and LDAP Role Mapping, the message 
returns an error.
7. To set the LDAP Synchronization Schedule, use the Add ScheduleEdit Schedule, and Remove 
Schedule buttons to create the desired schedule. 
Note:
You should set synchronization for a time when the fewest number of users are likely to be 
logged in. 
8. Click OK
Configuring LDAP user mapping 
You can configure the user mapping parameters that determine which users are imported and 
synchronized from the LDAP server. The parameters you specify depend on the LDAP server provider that 
you are using. 
To configure the LDAP user mapping parameters:
1. Start BAM Workbench by typing 
http://[host name]:[port]/celequest/workbench
 in the 
URL line of a web browser.
2. Click the Administration Console tab, and then click System Settings.
3. Click the LDAP User Mapping tab. 
4. Specify values for the following parameters: 
LDAP User Base DN: The root of the tree that will be searched for users. For example: 
(Sun ONE)
 OU=people,DC=your domain,DC=com
 
(Active Directory)
 CN=Users,DC=yourdomain,DC=com
 
LDAP User Search Filter: The format that is appropriate for the type of LDAP server you are using. 
For example, your LDAP server could have a special group for Business Activity Monitor users. This 
filter could then ensure that only users with this group membership are imported.