Tab | Field | Value | Comment |
Basics | Make this domain available to | Notes Clients and Internet Authentication/Authorization |
- Required
- LDAP Clients is optional
|
Basics | Group Authorization | Yes or No |
- Select Yes if you want to use Active Directory groups in database ACLs.
|
Basics | Attribute to be used as name in an SSO token | $DN |
- Required only if there is an IBM® WebSphere® SSO server authenticating users against Active Directory so that users' LTPA tokens contain their Active Directory names.
- Requires "Map names in LTPA token" to be enabled in the Web SSO Configuration document.
- Ensures proper SSO operation for servers that authenticate users against Active Directory.
|
Basics - SSO configuration | Windows single sign-on for Web clients | Enabled |
- Enables efficient name lookups based on users' Active Directory logon (Kerberos) names. In combination with "Attribute to be used as Notes Distinguished Name", allows the user's Kerberos identity to be associated with the Domino name.
|
Basics - SSO configuration | Kerberos realm | Active Directory domain |
- Specify in upper case characters, for example, AD.ACME.COM.
|
Naming Contexts (Rules) | Trusted for Credentials | Yes | -- |
LDAP | Attribute to be used as Notes Distinguished Name | <attribute> |
- Attribute in Active Directory that stores users' Notes distinguished names.
- A directory administrator may need to extend the Active Directory schema to add an attribute for this name if there is no existing attribute that already contains the Notes distinguished name. Alternatively it may be feasible to use the altSecurityIdentities attribute, if not already in use for another purpose.
- A directory synchronization tool such as IBM® Tivoli® Directory Integrator can be used to populate the attribute with the Notes names.
- The value stored in the attribute must adhere to valid distinguished name syntax. In Active Directory use LDAP comma (,) separators in the Notes names rather than the Notes forward slash (/) separators; for example:
cn=Betty Zechman,ou=Marketing,o=Renovations
rather than
cn=Betty Zechman/ou=Marketing/o=Renovations
- Used to link this Active Directory record to a Notes distinguished name for determining user access to Domino resources.
|
LDAP | Type of search filter to use | Active Directory | -- |