LDAP settings
Navigate to Comms > Communications > Authentication Processing to access LDAP settings.
LDAP Sync Agent settings
The LDAP Sync Agent Settings generates an encryption key file that is required by the LDAP Sync Agent to encrypt data transmitted between the sync agent and the Virtual Server. This section also includes settings that determine how the Virtual Server handles Operator accounts under certain conditions described below.
Begin by clicking the LDAP Sync Agent Settings hyperlink, enable or disable the options, then download the Sync Agent key file and install with your LDAP Sync Agent.
-
Persist Operators Against Sync— By default, synchronized user accounts are removed from the Virtual Server when removed from a synchronized group in your external data source (LDAP/AD). If this option is unchecked, users that have been promoted to Operator will also be removed. Selecting this option ensures that unintended changes to the LDAP account do not prevent the Operator from logging into the Virtual Server management UI. If checked, Operator accounts must be manually removed.
-
Use Delayed Sync Removal— By default, this option delays the removal of synchronized LDAP user accounts flagged for deletion from the Virtual Server for 24 hours. Conversely, if this option is disabled, accounts deleted in the LDAP directory are removed immediately and permanently from the SAS user database upon synchronization, along with all user/token associations.
When this option is enabled, it provides a “safety net” that protects against accidental or erroneous deletions, and saves the time and effort of re-establishing valid user accounts. The deleted user accounts are marked as “disabled” during the 24-hour period, and these users are not be able to authenticate. However, Operators have the ability to either re-enable the account or expedite the deletion manually if they are certain the removal is valid.
When used in conjunction with this option, enabling sync notifications provides the Operators with the opportunity to review synchronization activities and determine the validity of user account changes and deletions. If a sync event is detected, the Virtual Server sends an alert to Operators indicating that all detected changes will occur in 24 hours unless they intervene.
-
Resolve Duplicate Usernames During Sync— By default, this option is disabled.
When this option is enabled, duplicate username conflicts are automatically resolved during an LDAP sync. Duplicate username conflicts can occur if Use Delayed Sync Removal is enabled and a username is removed and then re-added to the AD between LDAP sync cycles.All tokens previously assigned to users with duplicate usernames are automatically revoked during this process.
LDAP Sync Agent hosts
This lists all LDAP sync agents that are allowed to synchronize with this Virtual Server.
Comms > Authentication Processing > LDAP Sync Agent Hosts
Click Add to create a new entry in the table, and then enter the name of the remote agent and its source IP address. The sync agent can send LDAP changes when Sync Permissions are set to Allowed. Use the following links:
-
Sync Permissions— Toggle between Allowed and Denied.
-
Remove— Remove a sync agent from the list.
View sync history
View synchronization activity. On this report, the Processed Groups column displays the number of changed groups that were processed during the sync batch. The Processed Users column displays only the number of users in this batch sent to be synced since the last successful sync. Each synchronization batch contains up to 500 attributes. How many users fit into a batch depends on how many attributes are configured for syncing.