Emergin, Inc. WirelessOffice Administrator LDAP/Active Directory Support Document Version 6.0R02 Product Version 6.0 DATE: 08-09-2004
Table of Contents Objective:... 3 Overview:... 4 User Interface Changes... 5 Server Configuration... 5 Security... 5 Database Setup... 6 LDAP Profile... 7 Domain User Account... 7
Objective: The purpose of this document is to provide the reader with information about new features added to the WirelessOffice Administrator, to support external recipient storage. In this case LDAP, Active Directory and Microsoft Exchange recipients are being supported. This document will cover features and user interface changes as well as requirements for the new supported databases.
Overview: Currently WO Administrator manages its own users and recipients database. For version 6.0 of the Emergin WirelessOffice suite, the support for external recipient s databases has being implemented. WO users can now send pages/event notifications to user accounts in LDAP, Active Directory or MS Exchange servers. The Administrator tool will allow administrators to indicate where recipient s information is to be collected from. The administrator can now select from the following database: WirelessOffice DB LDAP Directory Server Active Directory MS Exchange Simple modifications are required to the LDAP and Active Directory schemas in order to include new attributes into the user s accounts, in order to make these WirelessOffice recipients of pages and notifications. These changes are explained in the WirelessOffice LDAP Configuration document provided. Note: The use of secondary recipient storage is strictly read only. The WirelessOffice environment will not manage accounts in an LDAP/Active Directory environment for this release. These Users, Groups and Devices are read and used as recipients of event notifications only. To manage the LDAP/Active Directory the user most use the administrative tools provided by the Directory environment.
User Interface Changes For the new supported feature some changes where made to the user interface of the WO Administrator Tool. Here we will cover these changes and their implications. Server Configuration Security When security is enabled the administrator can now elect to authenticate login users from either the WirelessOffice database or from an LDAP/Active Directory server. A new option is now present in the General Tab of the Server Configuration dialog under Security, for administrators to indicate where authentication should be performed from, WirelessOffice or LDAP/Active Directory data source. When LDAP/Active Directory is selected as the authentication method the LDAP Profile window will be displayed for the user to provide the necessary profile values. Important: For WirelessOffice to be able to authenticate users from an LDAP/Active Directory environment, the user s authenticating credential must exist in the LDAP Directory as well as in the WirelessOffice database. This is due to security attributes
required by the WIrelessOffice environment that do not exist in the LDAP/Active Directory environment. The user s display name should be used as the login id for authentication purposes, when authenticating from an LDAP directory. Database Setup Users, Groups and Devices can now be retrieved from LDAP/Active Directory servers. Also users in an MS Exchange phonebook can be emailed from the WirelessOffice environment. On the Database Tab of the Server Configuration dialog a new group of options is included to allow administrators to select the source of the WirelessOffice recipients. Administrators can now choose from the standard WirelessOffice database an LDAP/Active Directory server or MS Exchange server.
LDAP Profile For the LDAP/Active Directory environment a Directory profile must be created. Here the user can specify information about the Directory server such as the type of server LDAP or Active Directory and other required information like Host Server, Port and Search Root. Due to environment differences the user is required to distinguish the LDAP Server type between a base LDAP environment, such as Netscape Directory Server or MS Active Directory. The host name can be provided, but if not, the system will identify the host that the WirelessOffice environment is running on. The LDAP default TCP Port is provided, but it can be changed if need be. A Search Root must be provided by the user to indicate where Users, Groups and Devices recipient folders are located. WirelessOffice will search for users in the Users folder, devices in the wodevices folder and groups in the wogroups folder. The creation of these folders is explained in detail in the LDAP Configuration document. Domain User Account The Domain User Account credentials are required to allow WirelessOffice service to authenticate into LDAP environment as a valid domain user. Notice that here the User Name is used and not the Login ID. If no Domain User Account credentials are provided and the Domain Server disallow anonymous binds access to the LDAP server will not be possible.