IBM Guardium

IBM Guardium

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  Import user from LDAP

    Posted 07/19/19 12:04 PM
    Hi community,
                How are you? We are triying to configure LDAP to import users in Guardium, we want to know how we can configure the schedule to import users from two LDAP Groups. We are trying to use this search filter:

    Search filter: (|(&(objectClass=group)(cn=<First Group name>))(&(objectClass=group)(cn=<Second Group name>)))

    object Class for user: |(objectClass=organizationalPerson)(objectClass=inetOrgPerson)(objectClass=person)

    But when we try to "run" this configuration it don't show any user to import. 

    Best regards,
    Rodrigo

    ------------------------------
    Rodrigo Diaz
    ------------------------------


  • 2.  RE: Import user from LDAP

    Posted 07/19/19 12:32 PM
    Here's an example of a pull from Multiple Groups exclude disabled:
    (|(&(memberOf=CN=GROUP_NAME,OU=DirecotryL1,OU=DirecotryL2,OU=DirecotryL3,DC=DOMAIN,DC=net)(!(userAccountControl=514)))(&(memberOf=CN=GROUP_NAME2,OU=DirecotryL1,OU=DirecotryL2,OU=DirecotryL3,DC=DOMAIN,DC=net)(!(userAccountControl=514))))

    ------------------------------
    Wendy Zemba
    ------------------------------



  • 3.  RE: Import user from LDAP

    Posted 07/19/19 01:25 PM
    Hi Wendy,
                Thanks for the information, we found an screeshot on a technote and we configured based on it and it works correctly! But now we are having another issue, there are any form to delete Guardium users? Because when we configured the LDAP as Scheduled, it creates Users from LDAP on Guardium users. And there are a lot of users that we don't need.

    Best regards,
    Rodrigo

    ------------------------------
    Rodrigo Diaz
    ------------------------------



  • 4.  RE: Import user from LDAP

    Posted 07/21/19 05:32 AM
    Hi,
    All new imported users should have inactive status, so there is no problem with additional, not used ones.
    You base on filter focused on groups - define the group content to users which should have access.
    You can also use an additional LDAP attribute for Guardium user identification.

    ------------------------------
    Zbigniew Szmigiero
    IBM
    Warsaw
    ------------------------------