IBM Guardium

IBM Guardium

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  Adding Members from LDAP(AD) Doesn't Add Domain Name as Prefix

    Posted Wed January 15, 2025 09:19 AM

    Dear Team,

    I am trying to add a Group Members (Users) from Active Directory(LDAP) , However, after adding users from AD, what I noticed Is, Imported users doesn't have domain name as a prefix, due to this we cannot use it on the Policy Rule actions as it doesn't match the criteria. Refer screenshots for understanding. 

    Appreciate if someone can assist in this scenario. 



    For example,
    guardium.user - this is what Imported from the AD

    What we need is. DomainName\guardium.user
    IBM\guardium.user

    UsersLDAPImport1


    ------------------------------
    Sincerely,
    Akash Parmar
    +91-9601716334 - WhatsApp Available
    akash.dba [MS Teams]
    ------------------------------


  • 2.  RE: Adding Members from LDAP(AD) Doesn't Add Domain Name as Prefix

    Posted Wed January 15, 2025 10:50 AM

    Hi  Akash Parmar,

    You have to create a second group that pulls in the bind Variables. Here's the url to IBM's knowledge article on it: 

    https://www.ibm.com/support/pages/node/6208419.



    ------------------------------
    Wendy Zemba
    Sr. Consultant, Data Protection
    Converge Technology Solutions
    wendy.zemba@convergetp.com

    Need help with your Guardium deployment? Contact me directly to discuss engagement opportunities. Currently serving North America.
    ------------------------------



  • 3.  RE: Adding Members from LDAP(AD) Doesn't Add Domain Name as Prefix

    Posted Wed January 15, 2025 11:51 PM

    Hello Wendy, Good Day!

    Thank you for the Info. However, not able to open given URL. Could you please check it. Moreover, I have raised case with IBM Support but I don't know why they don't have any solution for this.



    ------------------------------
    Akash Parmar
    ------------------------------



  • 4.  RE: Adding Members from LDAP(AD) Doesn't Add Domain Name as Prefix

    Posted Thu January 16, 2025 07:01 AM
    Hello,

    copy & paste recommended link into address input field of browser window
    and remove trailing dot character  from this link ...

    Libor




  • 5.  RE: Adding Members from LDAP(AD) Doesn't Add Domain Name as Prefix
    Best Answer

    Posted Thu January 16, 2025 08:34 AM
      |   view attached

    I dropped the information from the IBM Knowledge article into a word document. Hopefully it is accessible.



    ------------------------------
    Wendy Zemba
    Sr. Consultant, Data Protection
    Converge Technology Solutions
    wendy.zemba@convergetp.com

    Need help with your Guardium deployment? Contact me directly to discuss engagement opportunities. Currently serving North America.
    ------------------------------



  • 6.  RE: Adding Members from LDAP(AD) Doesn't Add Domain Name as Prefix

    Posted Sun January 19, 2025 04:19 AM

    Hello Wendy, Good Day!

    Thank you very much for your support in this Issue. I really appreciate it. However, I have tried everything as mentioned on the Doc but still no luck. I don't know where I am doing a mistake here ...!  basically, I am trying to fetch users from OU called "Service Accounts" with domain name For Example, IBM\SVC_Guardium.



    ------------------------------
    Akash Parmar
    ------------------------------



  • 7.  RE: Adding Members from LDAP(AD) Doesn't Add Domain Name as Prefix

    Posted Sun January 19, 2025 05:50 AM

    I notice is the ADServiceAccounts (USERS) group has no members. You need to run the LDAP import and have members in that group first.



    ------------------------------
    Wendy Zemba
    Sr. Consultant, Data Protection
    Converge Technology Solutions
    wendy.zemba@convergetp.com

    Need help with your Guardium deployment? Contact me directly to discuss engagement opportunities. Currently serving North America.
    ------------------------------



  • 8.  RE: Adding Members from LDAP(AD) Doesn't Add Domain Name as Prefix

    Posted Sun January 19, 2025 06:46 AM

    Hello Wendy, Good Day!

    Thank you for sparing your valuable time to help me on this. However, I have Imported the users from LDAP but still it doesn't contain the domain name prefix , I have then made the changes as per the Doc & Re-Run the Import but, still no luck. Kindly assist if possible. thank you again!



    ------------------------------
    Akash Parmar
    ------------------------------



  • 9.  RE: Adding Members from LDAP(AD) Doesn't Add Domain Name as Prefix

    Posted Tue January 21, 2025 10:01 AM

    Let's walk through it because you're still missing a couple details.

    1. Create a USERS group, ADServiceAccounts. Configure for LDAP Import with the search filter to find your desired members. Example: memberof=cn=dbadmin,cn=users,dc=guardium,dc=local
    2. Run once now, but eventually you'll want to schedule this to run on a regular basis.
    3. Create an OBJECTS group, ADServiceAccounts_bindVariables. Configure for LDAP Import with the search filter to find the members in ADServcieAccounts group and append the domain. Example: 
      memberof=cn=:1,CN=Users,dc=:2,DC=local.
      This replaces literal search with contents of "_bindValues" group.
    4. Run once now, but eventually you'll want to schedule this to run approximately 5 minutes after DServiceAccounts group.

    If you still have issues, feel free to private chat me and I'll assist with your memberof configuration.



    ------------------------------
    Wendy Zemba
    Sr. Consultant, Data Protection
    Converge Technology Solutions
    wendy.zemba@convergetp.com

    Need help with your Guardium deployment? Contact me directly to discuss engagement opportunities. Currently serving North America.
    ------------------------------