Enable Directory Authentication to Enroll PGP Desktop Clients
|Article:TECH149805|||||Created: 2010-05-11|||||Updated: 2011-02-10|||||Article URL http://www.symantec.com/docs/TECH149805|
This article describes how to enable clients to enroll with the server using Directory Synchronization.
Directory Synchronization allows you to assign a consumers to a specific consumer group based on the consumer's presence in a specified LDAP directory, or based on matching directory attributes you specify.
|Note: This article applies to PGP Universal Server 3.x.|
Prior to enabling clients to use Directory Authentication, you must enable Directory Synchronization and configure an LDAP directory which the server will use to match user credentials. For more information on enabling Directory Synchronization see the following articles:
- Enable Directory Synchronization - PGP Universal Server 3.0
- User Principal Name for PGP Universal Server 3.0 Directory Synchronization
After configuring your Directory Synchronization settings, use the following steps to enable the clients to use directory authentication.
- Log in to the PGP Universal Server admin interface.
- Click Consumers > Directory Synchronization.
- On the Directory Synchronization page, click Settings. The Directory Synchronization Settings are displayed.
- Place a checkmark next to Enroll clients using directory authentication.
To change the behavior of Directory Synchronization when a user cannot be matched to a specific LDAP directory based on any consumer matching rules, select an option from the drop-down menu of choices. Your choices are:
- Look for the consumer in all ordered LDAP Directories - If the consumer cannot be matched to a specific directory, then search all LDAP Directories specified for this PGP Universal Server, in priority order. (You can define the order that directories are searched on the Directory Synchronization page.)
- Only look for the consumer in the first ordered LDAP Directory - If the consumer cannot be matched to a specific directory, then search only the first (highest priority) LDAP Directory specified for this PGP Universal Server. If not found in the first ordered directory, the consumer is rejected.
- Reject the consumer If the consumer cannot be matched to a specific directory based on the consumer matching rules, reject the consumer.
- Click Save.
|Note: You can also enable the Enable LDAP Referrals option which allows PGP Universal Server to query referred LDAP directories when searching for user information.|
Article URL http://www.symantec.com/docs/TECH149805