LDAP management
LDAP configuration
By default, accessing the Controller user interface is restricted to people that have a user account defined through the MediaKind system center. You can also configure the user access by retrieving user credentials from an existing LDAP server directory.
-
Log in as a user with Administrative privileges.
-
Click in the upper right corner of the window.
-
Select Settings. The Settings page displays 5 tabs:
-
In the LDAP tab, configure the LDAP settings to integrate with the local LDAP server.
After changing the LDAP settings, for changes to take affect, the authentication service must be restarted. Either restart the Controller, or consult MediaKind Services for guidance on restarting the correct services for your deployment.
Loading LDAP certificates
If LDAP certificates are being loaded, configure LDAP on the settings page, then load the certificates.
For HA deployment, the following procedures must be done on both controller servers.
-
On the controller server, place the LDAPS certificates in /etc/pki/ca-trust/source/anchors/
-
Run the following command:
This will extract it to the standard OS trust store location (default path used in the controller UI):
- Edit the config file to set the right values:
The conf file must contain the fully qualified domain name for the LDAP server (same as in the certificate) and the IP address of that server.
- Run the script:
Running the script will restart the required containers.