1. Synchronization Options
The following screenshot provides a section preview of the modal window used during the creation of a new LDAP connector within the Axigen webadmin interface. The same options are available in the connector properties page, once it was created:- Server type. Specifies the type of LDAP server to use while performing the synchronization. This option can take two values only:
- “OpenLDAP” – Enable this option if you plan on using an OpenLDAP type of server.
- “ActiveDirectory” – Enable this option if you plan on using an Active Directory service.
- Timeout. Specifies the maximum allotted time for each lookup being performed. Once this set value is exceeded, the lookup is terminated and a timeout is returned and logged.
- Synchronization direction. This option specifies the source and destination of the sync. It can have one of the following values:
- “Axigen to LDAP” – By using this setting only information from the Axigen storage is synced to LDAP. Any changes made in LDAP do not get saved at all and are discarded.
- “LDAP to Axigen” – By using this setting only information from the LDAP database is synced to Axigen. Any changes made in Axigen do not get saved at all and are discarded.
- “Both ways” – By using this option you will let both Axigen and LDAP update the entry configuration. While this option is enabled, the “Conflict resolution” option must be set up correctly.
- Conflict resolution. This option is only available if the synchronization direction is set to “Both ways” and specifies which of the two possible sources takes precedence in case a conflict arises. It can take one of the following three values:
- “Axigen wins” – By using this option, Axigen changes take precedence over LDAP changes.
- “LDAP wins” – By using this option, LDAP changes take precedence over Axigen changes.
- “No change” – By using this option, all conflicts are ignored and the changes discarded.
2. Directory Lookup Options
The following screenshot provides a section preview of the modal window used during the creation of a new LDAP connector within the Axigen webadmin interface. The same options are available in the connector properties page, once it was created:Option names and functions:
- Account base DN. This setting refers to the top of the directory tree that is used in the sync process for the user account objects.
- Enable Group Synchronization. While this option is enabled group synchronization is activated for the LDAP connector in question. If this option is disabled, the “Group base DN” option is not available.
- Group base DN. This setting refers to the top of the directory tree that is used in the sync process for the group objects. This option is not available while the “Enable Group Synchronization” option is disabled.
- Use custom schema. While this option is enabled, a custom LDAP schema file may be loaded and used during the sync process. If this option is disabled, the “Custom schema file” variable is not available. Do not enable this option if you plan on using Active Directory instead of LDAP.
- Custom schema file. This setting contains the path to the custom schema file to use. This option is not available while the “Use custom schema” option is disabled.
3. Domain-specific Options
The following screenshot provides a section preview of the domain-related options within the Axigen webadmin interface. The same options are available for all domains by entering their properties page, once they were created:
Option names and functions:
- Enable LDAP synchronization. While this option is enabled, syncing for accounts and/or groups can take place for the objects part of this domain. While this option is enabled, a correct LDAP connector must also be specified.
- LDAP connector. This option is not available unless the “Enable LDAP synchronization” option is active. To set the domain to synchronize with a LDAP service, you have to choose the correct connector from the drop-down list.
