CLI Guide

Table 229. Details of cfgLDAPEnable (continued)
Default
0
cfgLDAPGroupAttribute (Read or Write)
Table 230. Details of cfgLDAPGroupAttribute
Description
Specifies which LDAP attribute is used to check for group membership. It must be an attribute of the group
class. If not specified then the member and unique member attributes are used.
Legal Values
String maximum length = 254
Default
Null
cfgLDAPGroupAttributeIsDN (Read or Write)
Table 231. Details of cfgLDAPGroupAttributeIsDN attribute
Description
When it is set to 1, iDRAC compares the userDN retrieved from the directory to compare to the members
of the group. If it is set to 0, the user name provides the login user to compare to the members of the
group. It does not affect the search algorithm for the bind. iDRAC always searches the userDN and uses
the userDN to bind.
Legal Values
1(TRUE) Use the userDN from the LDAP Server
0(FALSE) Use the userDN to provide the login user
Default
1
cfgLDAPPort (Read or Write)
Table 232. Details of cfgLDAPPort
Description
Port of LDAP over SSL. Non-SSL port is not supported.
Legal Values
165535
Default
636
cfgLDAPSearchFilter (Read or Write)
Table 233. Details of cfgLDAPSearchFilter
Description
To validate LDAP search filter, use the user attribute that cannot uniquely identify the login user within the
chosen baseDN. The search filter only applies to userDN search and not the group membership search.
Legal Values
String of maximum length = 254 characters
Default
(objectless=*)
Searches for all objects in tree.
iDRAC Property Database Group and Object Descriptions 195