Integrate Your LDAP Directory with MashZone NextGen
In many cases, users and authentication information for an organization is defined in an existing LDAP Directory. You can configure MashZone NextGen to use your LDAP Directory as the source for user and group information.
Note: | See the System Requirements for Software AG Products guide for information on MashZone NextGen support for specific LDAP Directory solutions. |
To configure your LDAP Directory as the MashZone NextGen User Repository:
2. Change MashZone NextGen configuration to use LDAP as the authentication provider.
a. Edit the userRepositoryApplicationContext.xml file in the MashZoneNG-config folder with any text editor.
b. Remove the comment markers around this statement: <import resource="/userRepositoryApplicationContext-ldap.xml">.
c. Comment out this statement: <import resource="/userRepositoryApplicationContext-jdbc.xml"> property.
Note: | You cannot use both default authentication and LDAP authentication. |
The configuration should look something like this:
<beans>
<!-- Choose between the interal JDBC repository and LDAP comment/uncomment
these two import statements -->
<import resource="/userRepositoryApplicationContext-ldap.xml">
<!-- <import resource="/userRepositoryApplicationContext-jdbc.xml"> -->
...
</beans>
3. Change MashZone NextGen configuration for the user attribute provider.
a. If it is not already open, edit the userRepositoryApplicationContext.xml file in the MashZoneNG-config folder with any text editor.
b. Find the userAttributeProvider bean:
<bean id="userAttributeProvider"
>
...
c. Remove comment markers around the ldapAttributeProvider bean reference in the providers property list.
The configuration should now look something like this:
<bean id="userAttributeProvider"
>
<property name="providers">
<list>
<ref bean="ldapAttributeProvider"/>
<ref bean="internalUserAttributeProvider"/>
</list>
</property>
</bean>
d. Save your changes to this file.
Important: | Do not restart the MashZone NextGen Server until all other LDAP configuration steps have been completed. |
4. Define configuration in the Admin Console in MashZone NextGen Hub for:
See also
Expose User Attributes from the User Repository in
MashZone NextGen for information on making LDAP user attributes accessible as
MashZone NextGen user attributes.
5. Add the built-in MashZone NextGen user groups to LDAP as new groups and assign at least one user as a MashZone NextGen administrator.
6. Restart the MashZone NextGen Server.
MashZone NextGen now uses LDAP as the user repository. You can now login using the user account assigned in earlier steps as a MashZone NextGen administrator.
To grant access to other users, add them to an appropriate built-in
MashZone NextGen user group in LDAP.
See Grant User Access to
MashZone NextGen
with Built-in Groups for instructions.