11.07.2015 Views

Administrator's Guide - Kerio Software Archive

Administrator's Guide - Kerio Software Archive

Administrator's Guide - Kerio Software Archive

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Chapter 7 Domains7.6 Setting of Directory Services<strong>Kerio</strong> MailServer can also work with accounts or groups that are managed through an LDAPdatabase (currently, Microsoft Active Directory and Apple OpenDirectory database — a databasefor Apple Mac OS X — are supported). Using LDAP, user accounts can be managed from onelocation. This reduces possible errors and simplifies administration.Example: A company uses a Windows 2000 domain with Active Directory as well as <strong>Kerio</strong>MailServer. A new employee was introduced to the company. This is what has been done untilnow:1. A new account has been created in Active Directory.2. The user has been imported to <strong>Kerio</strong> MailServer (or an account using the same name hasbeen created and this name was verified by the Kerberos system).If LDAP database is used, only the step 1 would be followed.Note: <strong>Kerio</strong> MailServer allows internally managed user accounts (stored in LDAP database) tobe added within the same email domain as Active Directory users. This can be helpful whencreating an administrator account that will be available even when the directory server cannotbe accessed.In the Directory service tab, LDAP parameters can be defined.Active DirectoryTo enable <strong>Kerio</strong> MailServer to cooperate fully with Active Directory (i.e. to enable the databaseto store all data about user accounts — see chapter 13.2), install <strong>Kerio</strong> Active DirectoryExtensions on the Active Directory server. For details see the chapter 29.Map user accounts and groups...Use this option to enable/disable cooperation with the LDAP database (if this option isinactive, only local accounts can be created in the domain).TypeType of LDAP database that will be used by this domain (Active Directory).HostnameDNS name or IP address of the server where the LDAP database is runningFor communication, the LDAP service uses port 389 as default (port 636 is used as defaultfor the secured version). If a non-standard port is used for communication of <strong>Kerio</strong>MailServer with the LDAP database, it is necessary to add it to the DNS name or the IPaddress of the server (e.g. mail1.company.com:12345 or 212.100.12.5:12345).Note: If the secured version of LDAP service is used for connection, it is necessary toenter also the DNS name to enable the SSL certificate’s verification.70

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!