|
      0WR7-09Y
      Registering Server Information
       
      To specify an Active Directory or LDAP server as an additional authentication device, you must register the information of the server used for authentication. Conduct a connection test as necessary.
      1
      Start the Remote UI. Starting the Remote UI
      2
      Click [Settings/Registration] on the portal page. Remote UI Screen
      3
      Click [User Management]  [Authentication Management].
      4
      Click [Server Settings]  [Edit].
      5
      Set the authentication server and domain information.
      [Use Active Directory]
      Select the check box when using Active Directory.
      [Set Domain List]
      Select whether the Active Directory information of the login destination is retrieved automatically or entered manually. To enter it manually, select [Set Manually] and add the domain of the login destination in [Active Directory Management].
      [Use access mode within sites]
      Select the check box if there are multiple Active Directory servers and you want to assign access priority to the Active Directory located in the same site as the machine. Change the settings for [Timing of Site Information Retrieval] and [Site Access Range] as necessary.
      [Number of Caches for Service Ticket]
      Specify the number of service tickets that the machine can hold. A service ticket is an Active Directory function that acts as a record of a previous login, which reduces the amount of time it takes for the same user to log in next time.
      [Use LDAP server]
      Select the check box when using an LDAP server.
      [Default Domain of Login Destination]
      Specify the domain that has connection priority.
      Manually specifying the Active Directory domain
      Registering LDAP server information
      6
      Enter the user information and set the privileges.
      [Save authentication information for login users]
      Select the check box to save the authentication information of users who log in via the control panel. After the settings are configured, the saved authentication information can be used for login, even if the machine is unable to connect to the server. Change the [Retention Period] setting as necessary.
      [User Attribute to Browse]
      Enter the data field (attribute name) on the referenced server that is used to determine user privileges (roles). Normally, you can use the preset value of "memberOf", which indicates the group that the user belongs to.*
      [Retrieve role name to apply from [User Attribute to Browse]]
      Select the check box to use for the role name the character string registered in the data field on the server specified in [User Attribute to Browse]. Before configuring, check the role names that can be selected on the machine, and register them on the server.
      [Conditions]
      You can set the conditions that determine user privileges. The conditions below are applied in the order that they are listed.
      [Search Criteria]
      Select the search criteria for [Character String].
      [Character String]
      Enter the character string that is registered to the attribute specified in [User Attribute to Browse]. To set the privileges based on the group that user belongs to, enter the group name.
      [Role]
      Select the privileges that apply to users who match the criteria.
      * Spaces and symbols (\ / : * ? | < > [ ] ; , = + @ " &) cannot be used.
      NOTE:
      The [Conditions] settings when using Active Directory servers
      "Canon Peripheral Admins" is set in advance as the Administrator user group. Assign different privileges to the other groups created on the server.
      7
      Click [Update].
      8
      Restart the machine. Restarting the Machine