To simplify administration, Crystal Enterprise supports LDAP authentication for user and group accounts. Before users can use their LDAP user name and password to log on to ePortfolio, you need to map their LDAP account to Crystal Enterprise. When you map an LDAP account, you can choose to create a new Crystal Enterprise account or link to an existing Crystal Enterprise account.
Before setting up and enabling LDAP authentication, ensure that you have your LDAP directory set up. For more information, refer to your LDAP documentation.
By default, each supported server type's server attribute mappings and search attributes are already set.
You can add more than one LDAP host of the same server type by repeating this step. If you want to remove a host, highlight the host name and click Delete. For more information on multiple hosts, refer to Managing multiple LDAP hosts.
If your LDAP Server allows querying and comparing for anonymous users, leave this area blankCrystal Enterprise servers and clients will bind to the primary host via anonymous logon.
Although groups can be mapped from multiple hosts, only one set of referral credentials can be set.
If this field is set to zero, no referrals will be followed.
Note: If you are setting up LDAP authentication for the first time, before you add any groups, you must click Update before you can continue to the next step. This updates Crystal Enterprise with the LDAP host and base name.
You can add more than one LDAP group by repeating this step. To remove a group, highlight the LDAP group and click Delete.
Use this option when you know users have an existing Enterprise account with the same name; that is, LDAP aliases will be assigned to existing users (auto alias creation is turned on). For users who do not have an existing Enterprise account, or who do not have the same name in their Enterprise and LDAP account, they will be added as a user to the Enterprise account (with the user information that is stored in the LDAP account).
Use this option when you want to create a new account for each user. If the user has already created an account through the sign
| Crystal Decisions, Inc. http://www.crystaldecisions.com Support services: http://support.crystaldecisions.com |