11.1. Connecting to Authentication Servers

The Connection Broker can authenticate users against Microsoft Active Directory and OpenLDAP authentication servers. To authenticate users, you first register your domain with your Connection Broker.

  1. Go to the Setup > Authentication Servers menu.

  2. Click the Add Authentication Server link.

  3. In the Add Authentication Server form, select Active Directory from the Type drop-down list.

  4. Enter the name for this server in the Connection Broker in the Authentication Server name edit field, as shown in the below image.

  5. In the Domain edit field, enter the domain name associated with this Active Directory server.

    ../_images/intg-leostream-edit-auth-server.png
  6. In the Connection Settings section, shown in the following figure, use the following procedure to integrate with your Active Directory authentication server.

    ../_images/intg-leostream-connect-auth-server.png
    1. From the Specify address using drop-down menu, select Hostname or IP address.

    2. Enter the authentication server hostname or IP address in the Hostname or IP address edit field.

    3. Enter the port number in the Port edit field.

    4. Check the Encrypt connection to authentication server using SSL (LDAPS) checkbox if you need a secure connection to the authentication server.

  7. In the Search Settings section, shown in the following figure, enter the username and password for an account that has read access to the user records. Leostream does not need full administrator rights to your Active Directory authentication server.

    ../_images/intg-leostream-search-auth-server.png
  8. In the User Login Search section, ensure that the Match Login name against this field edit field is set to sAMAccountName. This is the attribute that the Connection Broker uses to locate the user in the authentication server, based on the information the user enters when logging into Leostream.

  9. Click Save.