Cisco Cisco Email Security Appliance C170 Guida Utente

Pagina di 570
Chapter 4      LDAP Queries
4-242
Cisco IronPort AsyncOS 7.3 for Email Advanced Configuration Guide
OL-23081-01
 shows the default query strings and attributes that AsyncOS uses when 
it searches for group membership information on an Active Directory server.
Table 4-9
Default Group Membership Query Strings and Attribute: Active 
Directory
Server Type
Active Directory
Base DN
[blank] (You need to use a specific base DN to find 
the group records.)
Query string to determine if a 
user is a member of a group
(&(objectClass=group)(member={u}))
Note
If your LDAP schema uses distinguished names in the 
memberOf
 list instead of usernames, you can replace 
{u}
 with {dn}.
Attribute that holds each 
member's username (or a DN 
for the user's record)
member
Attribute that contains the 
group name
cn
 shows the default query strings and attributes that AsyncOS uses when 
it searches for group membership information on an OpenLDAP server.
Table 4-10
Default Group Membership Query Strings and Attributes: 
OpenLDAP
Server Type
OpenLDAP
Base DN
[blank] (You need to use a specific base DN to find 
the group records.)
Query string to determine if a 
user is a member of a group
(&(objectClass=posixGroup)(memberUid={u}))
Attribute that holds each 
member's username (or a DN 
for the user's record)
memberUid
Attribute that contains the 
group name
cn