Description
Configures authentication/authorization options for PDP.
Syntax
allow_empty_result count_in_non_ldap_group fetch_by_sid force_domain kerberos_any_domain kerberos_encryption reauth_agents_after_policy recovery_interval username_password |
Parameters
Parameter and Option |
Description |
---|---|
|
Shows the current configuration of fetching of local groups from the AD server based on SID. Configures that the fetching of local groups from the AD server based on SID should succeed, even if all SIDs are foreign. |
|
Shows and configures the identification of membership to individual users that are selected in the user picker and LDAP branch groups in SmartConsole. |
|
Shows and configures the fetching of local groups from the AD server based on SID. |
|
Shows and configures the PDP to match the identity's source, based on the reported domain and authorization domain. |
|
Shows and configures the use of all available Kerberos principles. |
get |
Shows and configures the Kerberos encryption type (in SmartConsole, go to Objects menu > Object Explorer > Servers > open the LDAP Account Unit object > go to General tab > click Active Directory SSO Configuration). |
|
Shows and configures the automatic reauthentication of Identity Agents after policy installation. |
|
Shows and configures the frequency (in seconds) of attempts to connect back to the higher-priority PDP gateway. |
|
Shows and configures the username and password authentication. |