USER GUIDE. Lightweight Directory Access Protocol (LDAP) Schoolwires Centricity



Similar documents
Lightweight Directory Access Protocol (LDAP) Schoolwires Centricity2

Using LDAP Authentication in a PowerCenter Domain

NovaBACKUP xsp Version 15.0 Upgrade Guide

ing from The E2 Shop System address Server Name Server Port, Encryption Protocol, Encryption Type, SMTP User ID SMTP Password

Security Assertion Markup Language (SAML) Site Manager Setup

HP Device Manager 4.7

Configuring Sponsor Authentication

Open Thunderbird. To set up an account in Thunderbird, from the Tools menu select Account Settings; choose account; then click Next.

Installing and configuring Microsoft Reporting Services

Designing IT Platform Collaborative Applications with Microsoft SharePoint 2003 Workshop

Remote Desktop Gateway. Accessing a Campus Managed Device (Windows Only) from home.

Authentication Methods

Training module 2 Installing VMware View

Device Log Export ENGLISH

SonicOS Enhanced 3.2 LDAP Integration with Microsoft Active Directory and Novell edirectory Support

Skyward LDAP Launch Kit Table of Contents

Product Summary RADIUS Servers

HOW TO CONFIGURE SQL SERVER REPORTING SERVICES IN ORDER TO DEPLOY REPORTING SERVICES REPORTS FOR DYNAMICS GP

Administrator Guide. v 11

Lenovo Partner Access - Overview

LDAP User Guide PowerSchool Premier 5.1 Student Information System

BlackBerry Enterprise Server for Microsoft Office 365 preinstallation checklist

Configuration Guide. Remote Backups How-To Guide. Overview

Use the below instructions to configure your wireless settings to connect to the secure wireless network using Microsoft Windows Vista/7.

Setting Up Scan to SMB on TaskALFA series MFP s.

How To Enable A Websphere To Communicate With Ssl On An Ipad From Aaya One X Portal On A Pc Or Macbook Or Ipad (For Acedo) On A Network With A Password Protected (

PassKey Manager. Schoolwires Centricity

CA Performance Center

Setting up LDAP settings for LiveCycle Workflow Business Activity Monitor

Security Guidelines for MapInfo Discovery 1.1

WHMCS LUXCLOUD MODULE

Configuring SonicWALL TSA on Citrix and Terminal Services Servers

Requirements Collax Security Gateway Collax Business Server or Collax Platform Server including Collax SSL VPN module

How To Take Advantage Of Active Directory Support In Groupwise 2014

Compiled By: Chris Presland v th September. Revision History Phil Underwood v1.1

How to Secure a Groove Manager Web Site

Authentication Integration

Protected Trust Directory Sync Guide

setup information for most domains hosted with InfoRailway.

Step-by-Step Setup Guide Wireless File Transmitter FTP Mode

Integrating LANGuardian with Active Directory

HP Device Manager 4.6

Security. TestOut Modules

SCOPTEL WITH ACTIVE DIRECTORY USER DOCUMENTATION

DEPLOYMENT GUIDE Version 1.0. Deploying the BIG-IP Edge Gateway for Layered Security and Acceleration Services

NSi Mobile Installation Guide. Version 6.2

Alcatel-Lucent Extended Communication Server Active directory synchronization : installation and administration

LDAP Implementation AP561x KVM Switches. All content in this presentation is protected 2008 American Power Conversion Corporation

How to Configure Active Directory based User Authentication

Avatier Identity Management Suite

Central Administration QuickStart Guide

NovaBACKUP xsp Version 12.2 Upgrade Guide

Deploying RSA ClearTrust with the FirePass controller

Implementing and Administering Security in a Microsoft Windows Server 2003 Network

Setup 1of 2: AKO (NOT E ) Setup on Outlook 2010

How To - Implement Single Sign On Authentication with Active Directory

To enable an application to use external usernames and passwords, you need to first configure CA EEM to use external directories.

7.0 Self Service Guide

Preparing for GO!Enterprise MDM On-Demand Service

External Authentication with Windows 2003 Server with Routing and Remote Access service Authenticating Users Using SecurAccess Server by SecurEnvoy

Authentication and Single Sign On

Single Sign-On Guide for Blackbaud NetCommunity and The Patron Edge Online

How To Integrate Watchguard Xtm With Secur Access With Watchguard And Safepower 2Factor Authentication On A Watchguard 2T (V2) On A 2Tv 2Tm (V1.2) With A 2F

Quality Center LDAP Guide

Customer Tips. Xerox Network Scanning HTTP/HTTPS Configuration using Microsoft IIS. for the user. Purpose. Background

Implementing Microsoft Azure Infrastructure Solutions 20533B; 5 Days, Instructor-led

OneLogin Integration User Guide

PineApp Surf-SeCure Quick

How to Pop to Outlook

Server Installation, Administration and Integration Guide

ClockWork Enterprise 5

Course 20533B: Implementing Microsoft Azure Infrastructure Solutions

HELP DOCUMENTATION SSRPM WEB INTERFACE GUIDE

Initial Setup of Mac Mail with IMAP for OS X Lion

IDENTIKEY Appliance Administrator Guide

Group Management Server User Guide

Immotec Systems, Inc. SQL Server 2005 Installation Document

Update Instructions

1 Outlook Web Access. 1.1 Outlook Web Access (OWA) Foundation IT Written approximately Dec 2010

Configuring User Identification via Active Directory

ProxySG TechBrief LDAP Authentication with the ProxySG

PowerLink for Blackboard Vista and Campus Edition Install Guide

Configuring the Cisco ISA500 for Active Directory/LDAP and RADIUS Authentication

Integration of Active Directory in BMC Remedy ARS. Doc Title : Integration of Active Directory in BMC Remedy ARS

pcanywhere Advanced Configuration Guide

NETASQ ACTIVE DIRECTORY INTEGRATION

Work with PassKey Manager

Secure Data Transfer

BlackBerry Enterprise Service 10. Version: Configuration Guide

WINGS WEB SERVICE MODULE

Management, Logging and Troubleshooting

MICROSOFT ISA SERVER 2006

Copyright 2012 Trend Micro Incorporated. All rights reserved.

Lepide Active Directory Self Service. Configuration Guide. Follow the simple steps given in this document to start working with

INTRODUCTION... 2 Windows Windows Mac OS X Ubuntu Advanced routing Windows Mac OS X Ubuntu...

Upgrading User-ID. Tech Note PAN-OS , Palo Alto Networks, Inc.

Technical Overview. Active Directory Synchronization

Talk Internet User Guides Controlgate Administrative User Guide

Course 20533: Implementing Microsoft Azure Infrastructure Solutions

Update Instructions

Transcription:

USER GUIDE Lightweight Directory Access Protocol () Schoolwires Centricity

TABLE OF CONTENTS Introduction... 1 Audience and Objectives... 1 Overview... 1 Servers Supported by Centricity... 1 Benefits of Authentication... 1 Implementation of Authentication... 1 The Effects of on the Use of Centricity... 4 The Authentication Process... 4 Effects of on Users of Centricity... 6 After the Initial Implementation... 6 Cen_063008 Page i

Introduction T he Lightweight Directory Access Protocol () Authentication enhancement module allows user information to be maintained in one centralized location and enables single sign-on access. User credentials can be shared between the network and Centricity user management systems. Audience and Objectives We recommend that Site Directors, read this chapter. In this chapter, you will learn: The benefits of Authentication; How and Centricity interact; and, How to implement and administer Authentication; Overview is an Internet protocol that allows programs to look up information on a server. Used with Centricity, authenticates and synchronizes user information for Centricity that is stored on a remote directory (i.e., ) server. Servers Supported by Centricity Centricity currently supports the following directory servers: Novell edirectory Microsoft Active directory Open, an open source directory Benefits of Authentication The primary benefit of authentication is having a single source of user information for both the organization s directory server and Centricity. Consequently, maintaining user information requires less time. In addition, users of both services use the same sign-in name and password. Implementation of Authentication You or your network engineer will work with one of the Schoolwires developers to set up the authentication process for your organization. If Schoolwires hosts your website on one of its servers, you will need to open your firewall to allow the specific IP address and port provided by the Schoolwires developer to access the directory server. Once you have opened Cen_063008 Page 1

the firewall, the Schoolwires developer will test the connectivity between the servers. You will also need to provide the developer with the following information: Which server you are using. The domain name or IP address for your directory. Whether you will be using a Secured Socket Layer (SSL). For ASP clients, this will determine which port you will need to open in your firewall. Note: If your website is hosted by Schoolwires and you will be using SSL, you must create a certificate on your server that Schoolwires will install on the server that hosts your Schoolwires website. The Distinguished Name (DN), which the path for the starting point for the search of your directory during the authentication process. The Login Name and password to use when Centricity accesses your directory server. Whether the formats for the sign-in name for your organization s directory server and Centricity are the same. If they are not, the authentication process will result in the creation of duplicate user profiles within Centricity. Consequently, if these do not currently match, the Schoolwires developer will run a script to match the format for the sign-in name for Centricity to that of your organization s directory server. The Distinguished Name for each directory group you wish to associate with a Schoolwires role and the role with which it will be associated. Cen_063008 Page 2

The Schoolwires developer will use this information to enter the parameters for on the Settings window accessible from Site Workspace Configure Site. See Figure 1 and Figure 2. Figure 1: Settings window: General tab Cen_063008 Page 3

Figure 2: Settings window: Groups tab After the set up is complete, the Schoolwires developer will test the authentication process (Test Authentication button). The Effects of on the Use of Centricity The Authentication Process When a user attempts to sign in to Centricity, authentication takes place in the following manner: 1. If that user is found in Centricity and marked as an user (Figure 3), the user will be authenticated against your organization s directory server. a. If that user is found on the directory server and the sign-in name and password match, the sign-in will be successful. b. If that user is not found on the directory server or the sign-in name and password do not match, the sign-in will fail and the user will need to contact the System Administrator. Cen_063008 Page 4

Login field only appears if your organization purchased the Enhancement Module. It is checked for users. 2. If that user is not found in Centricity, but is found on your organization s directory server, the user will be automatically added as an user within Centricity. The following information from the directory will be duplicated in the User Profile in Centricity: a. First name b. Last name c. Email address d. Sign-in Name Figure 3: User Profile when enabled e. Roles (Groups on the directory server) Note: Groups can be created within your organization s directory server and users can be assigned to them. During the implementation of, the Schoolwires developer sets up a table that cross references these groups within the directory server to roles in Centricity. If a user is assigned to a group on the directory server, then the user will be assigned the associated role in Centricity. 3. If that user is found in Centricity and not marked as an user (Figure 3), the user will be authenticated against the user database in Centricity. If the sign-in name and password match, the sign-in will be successful. 4. If that user is not found in Centricity or your organization s directory server or the sign-in name and password do not match, the sign-in will fail and the user will need to contact the System Administrator. Cen_063008 Page 5

Effects of on Users of Centricity Once authentication is implemented, you will notice the following effects: On the User Profile in Centricity for each user: o The Login box will be checked. (See Figure 3.) For new users, this happens during the authentication process. For existing users, the Schoolwires developer will run a script during implementation. o The password in Centricity will be a non-functioning, encrypted password. If you delete a user from the directory server, you do not need to delete that user from Centricity. The authentication will fail and that user will not be able to sign in to the website. However, you may want to purge this data from Centricity periodically. users of Centricity will still need to sign in. However, they will use the same sign-in name and password as they use for the network. When users of Centricity access their profiles (Access My Info), they will not have access to the Sign-in Name, Password or Confirm Password fields. If you make any changes to a User Profile (e.g., add a zip code, unlock a user) for an user, that user will not receive any confirmation from Centricity. The User Profiles for users of Centricity who are not users will be maintained within Centricity. They will be able to access their own profiles, including the Sign-in Name, Password and Confirm Password fields. They will receive the normal confirmation messages from Centricity. After the Initial Implementation Once the Schoolwires developer sets up authentication, there will be few reasons for a Site Director to access the Settings window from Site Workspace Configure Site. The main reasons for making changes are: You have added roles to your Schoolwires website. Your directory server has changed. The use of SSL has changed. However, we recommend that you contact Schoolwires prior to making any changes to the settings. Cen_063008 Page 6