Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

Overview

...

Your HyperCloudTM Platform (HCP) can accept Lightweight Directory Access Protocol (LDAP) authentication if your organization had implemented remote authentication. The HCP portal can be configured to accept remote authentication providers like:

  • Lightweight Directory Access Protocol or LDAP 

  • Microsoft Azure Active Directory

Whenever a user attempts to log in to your CMP HCP portal, the portal authenticates the user against their LDAP or Microsoft Azure Active Directory. If authentication is:

  • Successful: the user is logged into the

    CMP

    HCP portal.

  • Unsuccessful:

    CMP

    HCP portal will verify the credentials against the database.

When to use remote authentication providers?

...

title
Info

Info

The process for configuring Microsoft Azure Active Directory account to support LDAP is beyond the scope of this document. Refer to the Microsoft Support Documentation, to know more about the process. 

You can use remote authentication providers to:

  • Set up

    specific configurations

    specific configurations for

    Individual Users

    Individual Users or User Groups within your

    CMP

    HCP portal.

  • Verify the

    CMP

    HCP user credentials against your corporate LDAP directory.

  • Prevent performance issues that arise out of downloading large groups-related information from your LDAP directory.

Enable

...

LDAP

...

To enable LDAP on your CMP HCP portal:

  1. Login to your

    CMP

    HCP portal.

  2. Navigate to Administration>Users>Identity Provider>New>LDAP/AD.

  3. Click 

    Click on LDAP/AD. You'll be redirected to the LDAP/AD Authentication Provider Details page. 


    Image Removed

  4. Complete the fields with information specific to your LDAP or Microsoft Azure Active Directory account. Refer to the field description

    table below

    table below

Field Name

                                                            Connection Details

URL 

Provide your organization's LDAP/AD URL.

Name 

Name 

Provide a name for your connection to help you identify the directory.

LDAP Bind User DN 

Provide an LDAP Bind User DN. This is the User Name a user needs to provide at the time of logging into the

CMP

HCP portal. By default, the User Bind DN lets you authenticate the login and password change operations.

LDAP Bind Password 

Provide the LDAP Bind Password. This is the user's login password.

Base Details

Filter 

Provide filter, if any.

Base DN 

Provide the value for the root distinguished name (DN) that needs to be used while running queries against the directory server.

Examples

  • o=example,c=com

  • cn=users,dc=ad,dc=example,dc=com

For Microsoft Active Directory, specify the base DN in the following format: 

  • dc=domain1,dc=local.

You will need to replace domain1 and local with your environment-specific configuration.
Microsoft Server has a "ldp.exe" tool that lets you find and configure your LDAP server structure. 

ADFS Details

ADFS Login URL

Enter the URL and Partner URL for your Identity Provider.

Providing the Active Directory Federation Services (ADFS) Login URL, lets you log in to your Identity Provider using

a single

a single sign-on (SSO.)  

Relying Party ID

Enter the details of the Relying Party ID.

5. Click on Save Changes. You can now import users from your remote authentication provider account.

6. Click on Test Connection. If the details you entered are correct, you'll get a Connection Successful and Base DN Verified status message to the right.