Procedure
- Click Next.The LDAP Settings screen appears.
- Specify a meaningful description for the LDAP server.
- Complete the following to enable LDAP settings:
- For LDAP server type, select one of the
following:
-
Domino
-
Microsoft Active Directory
-
Microsoft AD Global Catalog
-
OpenLDAP
-
Sun iPlanet Directory
-
- To enable one or both LDAP servers, select the check boxes next to Enable LDAP 1 or Enable LDAP 2.
- Specify the names of the LDAP servers and the port numbers they listen on.
- Under LDAP Cache Expiration for Policy Services and EUQ services, type a number that represents the time to live next to the Time To Live in minutes field.
- Under LDAP Admin, type the
administrator account, its corresponding password, and the base-distinguished
name. See the following table for a guide on what to specify for
the LDAP admin settings.
LDAP admin settings
LDAP ServerLDAP Admin Account (examples)Base Distinguished Name (examples)Authentication MethodActive DirectoryWithout Kerberos: user1@domain.com (UPN) or domain\user1With Kerberos: user1@domain.comdc=domain, dc=comSimpleAdvanced (with Kerberos)Active Directory Global CatalogWithout Kerberos: user1@domain.com (UPN) or domain\user1With Kerberos: user1@domain.comdc=domain, dc=comdc=domain1,dc=com (if multiple unique domains exist)SimpleAdvanced (with Kerberos)Lotus Dominocn=manager, dc=test1, dc=comdc=test1, dc=comSimpleLotus Dominouser1/domainNot applicableSimpleSun iPlanet Directoryuid=user1, ou=people, dc=domain, dc=comdc=domain, dc=comSimpleOpen LDAPcn=manager, dc=test1, dc=comdc=test1, dc=comSimple - For Authentication method, click Simple or Advanced authentication. For
Active Directory advanced authentication, configure the Kerberos authentication
default realm, Default domain, KDC and admin server, and KDC port
number.

Note
Specify LDAP settings only if you will use LDAP for user-group definition, administrator privileges, or web quarantine authentication. - Select the Enable encrypted communication between IMSVA and LDAP check box and click Browse to upload a CA certificate file.
- For LDAP server type, select one of the
following:
