4.2 Configuring LDAP Settings

Self Service Password Reset enables you to configure settings to control interactions of Self Service Password Reset with the LDAP directory that contains your users. You can select a template to configure the settings. Self Service Password Reset provides templates to set default settings for your back-end directories. Changing the template only affects default values. You can change the template at any time. Changing a template does not affect the modified settings.

Self Service Password Reset provides the following templates for supported directories:

  • Active Directory

  • Oracle Directory Server

  • Identity Manager/ OAuth Integration

To configure Identity Manager/ OAuth Integration see, Identity Manager and Section 11.0, Integrating Self Service Password Reset with NetIQ Identity Manager and Section 9.0, Integrating Self Service Password Reset with NetIQ Access Manager.

Use the following information to configure the settings for the other LDAP directory templates.

4.2.1 Configuring the Global LDAP Settings

The Global settings control the interaction with an LDAP directory. These settings are not applicable to the user's LDAP profile. For more information about configuring LDAP for a profile see, Configuring LDAP Directory Profile.

To configure the Global LDAP settings:

  1. Log in to Self Service Password Reset at https://dns-name/sspr as an administrator.

  2. In the toolbar, click your name.

  3. Click Configuration Editor.

  4. Select the LDAP directory template for your LDAP directory.

    1. Click Default Settings > LDAP Vendor Default Settings, then select the LDAP directory you are using.

      NOTE:If you select NetIQ eDirectory, you can configure NMAS settings. See, Configuring NetIQ eDirectory Settings.

    2. In the toolbar, click Save changes.

  5. In the toolbar, click your name.

  6. Click Configuration Editor.

  7. Click LDAP > LDAP Settings > Global.

  8. Use the help information to configure the global settings for the LDAP directories.

  9. In the toolbar, click Save changes.

4.2.2 Configuring Microsoft Active Directory Settings

Self Service Password Reset allows you to change the settings for Microsoft Active Directory.

To change the Microsoft Active Directory settings:

  1. Log in to Self Service Password Reset at https://dns-name/sspr as an administrator.

  2. In the toolbar, click your name.

  3. Click Configuration Editor.

  4. Click Default Settings > LDAP Vendor Default Settings > Microsoft Active Directory.

  5. Select LDAP > LDAP Settings > Microsoft Active Directory.

  6. Configure the Active Directory settings use the help.

  7. In the toolbar, click Save changes.

4.2.3 Configuring NetIQ eDirectory Settings

You can use either eDirectory or eDirectory with NMAS as the back-end directory. These settings allow you to change the eDirectory setting configuring during the Configuration Guide.

Configuring eDirectory Challenge Set Options

When the back-end directory is eDirectory, you can configure NMAS. All NMAS operations require an SSL connection to the directory. Benefits of this configuration include:

  • Validation of passwords against the NMAS password policy.

  • Email notifications for failed password operations, such as when a password coming from a connected system does not comply with the password policies.

  • Better error messages when using universal password policies

  • Better error handling during the change password process

If you must apply the policy settings for the challenge sets that you configured in NMAS, perform the following:

To change the policy settings for the challenge sets:

  1. Log in to Self Service Password Reset at https://dns-name/sspr as an administrator.

  2. In the toolbar, click your name.

  3. Click Configuration Editor.

  4. Click LDAP > LDAP Settings > NetIQ eDirectory > eDirectory Challenge Sets.

  5. Define the eDirectory challenge sets using the help.

  6. In the toolbar, click Save changes.

Configuring the LDAP eDirectory Settings

Apart from configuring the NMAS extension, you can configure some additional parameters for eDirectory.

To configure NetIQ eDirectory:

  1. Log in to Self Service Password Reset at https://dns-name/sspr as an administrator.

  2. In the toolbar, click your name.

  3. Click Configuration Editor.

  4. Click Default Settings > LDAP Vendor Default Settings , then select NetIQ eDirectory.

  5. Click LDAP > LDAP Settings > NetIQ eDirectory > eDirectory Settings.

  6. Configure eDirectory settings using the help.

  7. In the toolbar, click Save changes.

4.2.4 Configuring the Oracle Directory Server Settings

Self Service Password Reset allows you to change settings for the Oracle Directory Server setting.

To change the Oracle Directory Server settings:

  1. Log in to Self Service Password Reset at https://dns-name/sspr as an administrator.

  2. In the toolbar, click your name.

  3. Click Configuration Editor.

  4. Click Default Settings > LDAP Vendor Default Settings > Oracle Directory Server.

  5. Select LDAP > LDAP Settings > Oracle DS.

  6. Configure the Oracle Directory Server settings using the help.

  7. In the toolbar, click Save change.