HP Identity Driven Manager Software Licenses User Manual

Page 132

Advertising
background image

3-70

Using Identity Driven Manager
Using the User Import Wizard

Editing IDM Configuration for LDAP Import

The IDM server includes several configuration files that contain information
used to import User information from LDAP files. The default configuration
settings will work if you are using MS Active Directory as the LDAP Server
directory. If you are using any other LDAP directory source (for example
Novell Edirectory) you will need to modify the

LDAP Directory

settings in:

~Program Files\Hewlett-Packard\PNM\server\config\IDMImportServerComp.scp

Following is an example of the

DMImportServerComp.scp file

for reference.

Comments are indicated by "//".

LDAP_SERVER_CONFIG {

PORT=389

//Port where LDAP server receives bind request.

SSL_PORT=636

// Port where LDAP server receives SSL bind requests.

BATCH_SIZE=50

// Internal to IDM.

COUNT_LIMIT=0

// Internal to IDM.

SASL_CONFIGURATION {

// This section is for SSL configuration: Digest MD5, Kerberos V5 and External.

QOP=auth-conf,auth-int,auth

// Quality of protection. Valid values are 1 and more of "auth-conf", auth-
int", "auth" separated by ",".

ENCRYPTION_STRENGTH=high,medium,low

// Strength of encryption. Valid values are 1 and more of "high", "medium",
"low" separated by ",".

MUTUAL_AUTHENTICATION=true

// If both LDAP server and IDM server wants to authenticate each other.

}

KERBEROS_JAAS_CONFIG {

// This section is for Kerberos authentication method.

KERBEROS_AUTH_MODULE=IDMKerberos

// Kerberos authentication module name. If this entry is changed, you must also
change the module name in idm_kerberos_jass.conf file.

KERBEROS_JAAS_CONFIG_FILE=config/
idm_kerberos_jaas.conf

// configuration file for JAAS Kerberos

configuration.

}
}

(Example continued on next page)

Advertising
This manual is related to the following products: