|
The VISULOX PORTAL Service knows an important role: administrator. Users in this role can use the VISULOX Portal Console of the VISULOX PORTAL Service.
This is normally not the case for users authenticated via LDAP.
|
|
VISULOX provides a service to automatically create the LDAP mirror in the datastore: alignRole
This article explains how to configure VISULOX for automatic assignment of the VISULOX PORTAL Console to a specific group of users.
Users who are found with searchadmin in the datasources are created for VISULOX PORTAL administrators.
In this example it is:
-searchadmin '(&(objectClass=person)
(memberOf=CN=PORTALADMIN,OU=Groups,OU=ToolBox,DC=tbsol,DC=de)
(|(distinguishedName=%SEARCH_STRING%)
(cn=%SEARCH_STRING%)
(givenName=%SEARCH_STRING%)
(uid=%SEARCH_STRING%)
(mail=%SEARCH_STRING%)
(sAMAccountName=%SEARCH_STRING%)
)
)'
Configuration
searchadmin is configured with a datasource object within VISULOX (See: How to work with VISULOX datasources).
The searchadmin string should be checked. This parameter holds the search string for admin group.
visulox datasource list -name tbsol -info
Datasources
----------------------------------------------------------------------------------------------------------------------
| name | parameter | value |
----------------------------------------------------------------------------------------------------------------------
| tbsol,0 | location | Stuttgart |
| tbsol,0 | host | office-ad.tbsol.de |
| tbsol,0 | type | ldap |
| tbsol,0 | username | CN=Logon,OU=ToolBox,DC=tbsol,DC=de |
| tbsol,0 | port | 389 |
| tbsol,0 | password | <hidden> |
| tbsol,0 | attributes | objectclass dn mail uid cn surname mobile memberOf c countryCode |
| tbsol,0 | base | OU=ToolBox,DC=tbsol,DC=de |
| tbsol,0 | disabled | false |
| tbsol,0 | mapping | MSAD |
| tbsol,0 | searchadmin | (&(objectClass=person)(memberOf=CN=Admins,OU=Applikation,OU=ToolBox,DC=tbsol,DC=de)) |
| tbsol,0 | searchapplication |
| tbsol,0 | searchgroup | (objectclass=group) |
| tbsol,0 | searchuser | (objectclass=person) |
| tbsol,0 | vlx_source | vB1LX |
----------------------------------------------------------------------------------------------------------------------
/opt/visulox/lib/utils/ldap.tcl -source TESTAD -objectclass admin
Test commands
visulox-portal role list_members --role global