Total Pageviews

Thursday 22 January 2015

GRC 10.1/10 - Configure LDAP Connector

This section will provide you detailed steps to configure LDAP connector, its Data Source and End User Verification.

Create LDAP Connector

Go to transaction SM59 and create a connector for LDAP by selecting connection type TCIP/IP.
 

Maintain also the Gateway Host and Gateway Server in this tab. When you successfully started the connector in the next step do a Unicode test (Utilities -> Test -> Unicode Test) and according to it's result set the Unicode flag.

LDAP Transaction Setup

Click on LDAP Connector button and enter following details. Click on Activate Button to activate the LDAP Connector.
Please note CONNECTOR NAME is same as RFC Program ID and APPLICATION SERVER will be the GRC server hostname with SID and Instance number (this can
be selected by pressing F4 in Application Server field)

Configure LDAP Server Setup using following values


.
Use Transaction LDAPMAP and go to change mode and press F6 (Proposal) to get default mapping.
IMG5
Go to SPRO transaction and GRC node

And define a connector for LDAP

and a logical group for ALL LDAP connectors:

Assign all LDAP connectors to this connection group

Assign the LDAP connection to all the scenarios: At least AUTH and PROV:


Assign the adaptor LDAP implementation class for both AUTH and PROV scenarios

Now maintain the Mappings of LDAP attributes:
Go to IMG node

First add LDAP connection group with app type as LDAP and active

Now assign the default connector for Provisioning and Authorization for that connection group:

Now maintain the group field mapping for PROV and AUTH actions one by one:
PROV Action Mapping:

AUTH Action Mapping:


NOTE: Please make sure field mapping is in upper case
And also maintain the group parameter mapping for PROV and AUTH actions one by one:
PROV Action Mapping:

AUTH Action Mapping:

Now maintain connector settings:


Assign Attribute to LDAP connection:

Group path can also be maintained here with GROUP PATH parameter
Maintain search data source:

Add the LDAP connector and sequence as search data source

Setting LDAP user search as realtime:
Under SPRO go to Maintain Configuration Settings as shown below:

Set the realtime LDAP search parameter to YES

NOTE: If LDAP realtime search is kept to YES then multiple user search data source will only search in LDAP systems only.
Setting LDAP as end user authentication system:

Set the setting “End User Verification” required to YES/NO

 

2 comments: