18.01.2015 Views

Technical Reference Manual - InduSoft

Technical Reference Manual - InduSoft

Technical Reference Manual - InduSoft

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Project Security<br />

To make this option work, you must first extend the server's LDAP schema to contain additional<br />

information about the project security system. See Extending the LDAP schema to allow saving<br />

of security rights.<br />

Once that is done, click Modify to provide your LDAP server credentials and then select Enable.<br />

In the LDAP Query Customization tab of the dialog, you can further customize how LDAP server queries are<br />

formed:<br />

LDAP Query Customization<br />

By default, the LDAP server provides a list of all registered users and groups, so in a large or complex network<br />

environment, that can result in an impractically long list to manage when you're configuring your project<br />

security system. To restrict the list of users and groups, you may customize the LDAP query to eliminate<br />

anyone who should never have access to your project: click Modify to provide your LDAP server credentials,<br />

select Enable, and then configure the Search Base and Filter Query settings. For the proper syntax, consult the<br />

LDAP server documentation.<br />

Also, some non-standard LDAP implementations — such as Linux-based LDAP servers and Active Directory<br />

Application Mode (ADAM) in Windows Server 2003 — use different entity identifiers and attributes. Those can<br />

be customized in this dialog, but again, it should only be done by an experienced LDAP administrator.<br />

Example of alternate attributes in ADAM<br />

LDAP Server User name attribute Group name attribute User lock attribute<br />

Active Directory sAMAccountName sAMAccountName userAccountControl<br />

Active Directory Application Mode (ADAM) Name Name userAccountControl<br />

Extending the LDAP schema to allow saving of security rights<br />

In order to save IWS project security rights back to a Domain (LDAP) server, the server's LDAP schema must<br />

be extended to contain the additional information.<br />

The server must already be configured and running on your network, and you must have sufficient privileges<br />

to make changes to the server configuration.<br />

In this procedure, you will create a new attribute called "proprietarySCADAInfo" to contain the IWS project<br />

security rights, and then you will add the attribute to the "person" and "group" classes in the server<br />

configuration. These classes correspond to users and groups in the project security system.<br />

Please note this procedure only shows how to extend the schema in Microsoft Active Directory running on<br />

Windows Server 2003. The exact procedure is different for other LDAP servers and operating systems, but the<br />

basic steps should be essentially the same. Please consult your LDAP server documentation.<br />

Page 380<br />

<strong>InduSoft</strong> Web Studio

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!