<?xml version="1.0" encoding="UTF-8" ?> 
<cheatsheet title="Using an LDAP directory server as a user registry">
	<intro 
		href="ldap_intro.htm">
        <description>
WebSphere Application Server security supports the implementation
of most major LDAP directory servers, which can act as the repository for
user and group information. These directory servers are called by the WebSphere servers
for authenticating a user and other security-related tasks (for
example, getting user or group information). This support is provided by using
different user and group filters to obtain the user and group information.
These filters have default values that you can modify to fit your needs. The
custom LDAP feature enables you to use any other LDAP server (which is not
in the product supported list of LDAP servers) for its user registry by using
the appropriate filters. 
&lt;br/&gt;
&lt;br/&gt;
To continue, click &lt;strong&gt; Start&lt;/strong&gt;.
</description>
	</intro>

	<item
        href="com.ibm.ws.console.security/guidedactivity/cheatsheets/nl/lang/ldap_tips.htm"
		title="Specify user ID and password for the LDAP  server">
		<action
			class="com.ibm.ws.console.security.forwardCmd.do?forwardName=LDAPUserRegistry.config.view&amp;sfname=userRegistries&amp;resourceUri=security.xml&amp;parentRefId=Security_1&amp;perspective=tab.configuration"/>
        
	<description>
            &lt;ol&gt;
            &lt;li&gt;Click &lt;strong&gt; Click to perform&lt;/strong&gt; to load the LDAP User Registry panel&lt;/li&gt;
            &lt;li&gt;Enter a valid user name in the Server User ID field. You can either enter the complete distinguished name (DN) of the user or the short name of the user as defined by the User Filter in the Advanced LDAP settings panel. For example, for IBM Directory Server enter &lt;strong&gt;cn=WAS admin,o=ibm,c=us&lt;/strong&gt; or &lt;strong&gt;WASadmin&lt;/strong&gt;, where &lt;strong&gt;WASadmin&lt;/strong&gt; is the user ID.&lt;/li&gt;
            &lt;li&gt;Enter the password of the user in the Server User Password field.&lt;/li&gt;
            &lt;/ol&gt;

            To continue, click &lt;strong&gt; Next step&lt;/strong&gt;.
    </description>
     </item>




    <item
        href="com.ibm.ws.console.security/guidedactivity/cheatsheets/nl/lang/ldap_tips.htm"
        title="Specifying the type of LDAP server">
        <action
            class=""/>
    
    <description>
    
                Select the type of LDAP server that is used from the Type list.
                            The type of LDAP server determines the default filters that are used by the WebSphere Application Server. 
                            If either the IBM Directory Server or the iPlanet Directory Server is selected, also select the 
                            checkbox for the Ignore case for authorization field below.

                For more information on using specific types of LDAP servers, see 
                &lt;a target="help" href="http://publib.boulder.ibm.com/infocenter/ws60help/index.jsp?topic=/com.ibm.websphere.base.doc/info/aes/ae/tsec_tmsad.html"&gt;Using specific directory servers as the LDAP server&lt;/a&gt;.

                 &lt;br/&gt;
                &lt;br/&gt;

                

                To continue, click &lt;strong&gt; Next step&lt;/strong&gt;.
    </description>
     </item>

    <item
        href="com.ibm.ws.console.security/guidedactivity/cheatsheets/nl/lang/ldap_tips.htm"
        title="Identifying the LDAP server">
        <action
            class=""/>
    
    <description>
    
                &lt;ol&gt;
                &lt;li&gt;Enter the fully qualified host name of the LDAP server in the Host field.&lt;/li&gt;
                &lt;li&gt;Enter the LDAP server port number in the Port field. 
                            The host name and the port number represent the realm for this LDAP server in the WebSphere Application Server cell. 
                            &lt;/li&gt;
                &lt;/ol&gt;

To continue, click &lt;strong&gt; Next step&lt;/strong&gt;.
    </description>
     </item>




    <item
        href="com.ibm.ws.console.security/guidedactivity/cheatsheets/nl/lang/ldap_tips.htm"
        title="Accessing the LDAP server">
        <action
            class=""/>
    
    <description>


            &lt;ol&gt;
            &lt;li&gt;Enter the Base distinguished name (DN) in the Base Distinguished Name field. 
                        The Base DN indicates the starting point for searches in this LDAP directory server. 
                        For example, for a user with a DN of &lt;TT&gt;cn=John Doe, ou=Rochester, o=IBM, c=US&lt;/TT&gt;, specify the Base DN as any of the following options (assuming a suffix of c=us):
                        &lt;TT&gt;ou=Rochester, o=IBM, c=us&lt;/TT&gt; or &lt;TT&gt;o=IBM c=us&lt;/TT&gt; or &lt;TT&gt;c=us&lt;/TT&gt;. 
                        This field can be case sensitive. Match the case in your directory server. 
                        This field is required for all LDAP directories except the Domino Directory. 
                        &lt;/li&gt;
            &lt;li&gt;Enter the Bind DN name in the Bind Distinguished Name field, if necessary. 
                         The Bind DN is required if anonymous binds are not possible on the LDAP server to obtain user and group information. 
                          If the LDAP server is set up to use anonymous binds, leave this field blank.&lt;/li&gt;
            &lt;li&gt;Enter the password corresponding to the Bind DN in the Bind password field, if necessary.&lt;/li&gt;
            &lt;li&gt;Disable the Reuse Connection field only if you use routers to send requests to multiple LDAP servers, and if the routers do not support affinity. 
                         Leave this field enabled for all other situations.&lt;/li&gt;

            &lt;li&gt;Click &lt;strong&gt;OK&lt;/strong&gt; to submit your changes made so far.&lt;/li&gt;
            &lt;/ol&gt;

    </description>
	</item>


    
</cheatsheet>