AD user authentication with DLP Reporting and Updating API
Created: 30 Nov 2012 | 7 comments
Hello,
I am currently working on implementing a web service client against the DLP Reporting and Updating API version 11.6 and it looks like it doesn't work with AD authentication and that it only accepts single DLP user accounts. Since our implementation uses AD authentication, we are required to be able to contact the web service using an AD account.
Any help or advice on how to properly pass an AD account credential (username, password and domain) to the webservice or any workarounds available, would be greatly appreciated.
Thanks!
Discussion Filed Under:
Comments 7 Comments • Jump to latest comment
HI,
Check this thread
https://www-secure.symantec.com/connect/forums/active-directory-authentication-whole-group
https://www-secure.symantec.com/connect/forums/dlp-and-ad-intergration
Thanks In Advance
Ashish Sharma
SEPM Knowledgebase Documents
what is teh AD OS?
Cheers!
Pete
Help Link: http://www.symantec.com/business/support/overview.jsp?pid=54619
hi HX,
As DLP having very strong and secure authentication mecahnism, you need to configure and verify below facts. you can directly create user account to DLP apps/AD Auth/SPC are some option.After succesfull integration with AD u must add them in DLP enble.
AD Authentication and a LDAP query are two different things. To perform an AD authentication you need to configure the krb5.ini file (windows) or the krb5.conf file (Linux). then run a command. See the admin guide for DLP 10.5 and search for krb5 and it will take you to the page for AD Authentication.
Domain user names entered for login must match the user names defined in DLP.
Users must be part of a role in DLP to be able to login
Hello,
I have same issue. AD user authentication is works correctly. But AD authentication isn't work from my own application, that connect with Reporting API. I can connect only with Administrator account. How I can use username from AD for the Reporting API?
For both of you having problems, double check that the role and/or users are enabled to use the API.
JGT
--
John G. Thompson
JOAT(MON)
The role isn't reason of this issue.
I contacted with team of Symantec Support and got a link to the Article ID 53354 of the Data Loss Prevention Knowledgebase.
From the Knowledgebase:
Information from that article is a direct answer to the question.
Hi HX is your query is resolved or need more solution. Please let us further..
Would you like to reply?
Login or Register to post your comment.