Domains

Purpose: Use the Domains screen to review and work with domains for LDAP authentication of users.

How to display this screen: Select Domains from the Home Screen or from the Systems Menu.

Note:             Only users with Domains authority can display this screen. See the Role Wizard for more information.

In this topic:

         Domain Configuration for LDAP Authentication

         Options at this screen

         Fields at this screen

Domain Configuration for LDAP Authentication

Overview: Use the steps below to set up Order Broker to support LDAP authentication, and then configure users for this authentication method:

1.      Specify the domain and LDAP connection string:

         At the Domains screen, enter the name of the domain in the Domain field and click New.

The name can be made up of alphanumeric or special characters, and there is no specific limit on its length; however, it must match the network domain name.

         At the New Domain screen:

         Optionally, flag the domain as the Default so it will default at the User Profile Configuration screen. If another domain was previously flagged as the default, that domain’s Default flag is cleared and the new domain becomes the default.

         Enter the LDAP connection string for Order Broker to use to verify the user at login. Your information technology staff can provide you with this information. Do not enclose the string in quotation marks.

         Click Save.

Warning: The screen displays a warning message if the domain does not use secure LDAP (LDAPS).

2.      Configure individual users for LDAP authentication:

         At the User Profile Configuration screen:

         Select the Use LDAP flag.

         If you have flagged a domain as the default, this domain defaults to the user’s Domain field; however, you can override the default.

         If the user’s LDAP user ID differs from his or her Order Broker user ID, complete the LDAP User Id field; otherwise, leave this field blank.

         Click Save.

Note:             The Reset Password option at the User Profiles screen is not available for users configured for LDAP authentication; however, you can still use the Disable Login option for these users.

Options at this screen

Option

Procedure

create a new domain

1.      Enter the domain name in the Domain field. Your entry can be made up of alphanumeric or special characters, and there is no specific limit on length; however, it must match the network domain name.

2.      Click New. You advance to the New Domain screen, where you enter the LDAP connection string and optionally flag the domain as the default. Your information technology staff can provide you with the LDAP connection string. Do not enclose the string in quotation marks. Click Save when you are done.

Important:                               Creation of the new domain is not complete until you click Save at the New Domain screen.

Note:  If the New Domain screen is already open in another tab, you advance to that screen, where the previously-entered information is displayed.

search for a domain

Enter a full or partial Domain to restrict your results to domains whose names start with your entry, and click Search. Case-sensitive for searching; for example, an entry of d does not match a domain of Default Domain.

change the default flag setting or LDAP connection string for an existing domain

Click the edit icon (edit_icon.png) for a domain to advance to the Edit Domain screen.

Note:  If the Edit Domain screen is already open in another tab, you advance to that screen, where the previously-selected domain is displayed.

delete a domain

Select the delete icon (delete_icon.png) next to a domain to delete the domain from Order Broker.

Note:  Order Broker does not prevent you from deleting the domain that is currently flagged as the default; however, you cannot delete a domain that is currently assigned to a user.

Fields at this screen

Fields

Description

Domain

A domain used for LDAP authentication. Required when you are creating a new domain record in Order Broker. Your entry can be made up of alphanumeric or special characters, and there is no limit on length. Case-sensitive for searching; for example, an entry of d does not match a domain of Default Domain.

Search Results

Domain

A domain used for LDAP authentication.

LDAP Connection String

The connection string for Order Broker to use to verify the user at login. Typically provided by your information technology staff. Should not be enclosed in quotation marks.

Default

If this check box is selected, this domain defaults at the User Profile Configuration screen when you set up a user for LDAP authentication. It is not necessary to flag a domain as the default.

Edit

Click the edit icon (edit_icon00146.png) for a domain to advance to the Edit Domain screen. At that screen, you can change an domain’s Default flag setting or LDAP connection string.

Note:  If the Edit Domain screen is already open in another tab, you advance to that screen, where the previously-selected domain is displayed.

Delete

Select the delete icon (delete_icon00147.png) for a domain to delete the domain from Order Broker.

 

 

________________________________