User Manual
Pearl-2 User Guide                                      Configure LDAP user authentication
Alternatively, you can regain access to Pearl-2 if you apply the factory default configuration preset using the 
touch screen, Apply a configuration preset using the touch screen. The factory default configuration will 
change the current settings on Pearl-2, see TheFactory default configuration preset.
Configure LDAP user authentication
You can use the Lightweight Directory Access Protocol (LDAP) to authenticate users. Specify user roles by 
using group DNs for users who log in as an Administrator, Operator, or as a Viewer. 
The system has only one admin user and one operator. LDAP users must log in as either an admin or an 
operator and do not have their own private profiles. Any LDAPusers with the name admin, operator, or 
viewer are ignored and the local accounts are used instead. 
When enabled, LDAP authentication is an alternative to the regular system user names and passwords. You 
may still login as admin, operator or viewer using the passwords for those accounts. 
LDAPreplaces the local viewer account instead of working side-by-side with it when LDAPis 
enabled and the viewer account has no password (either there is no global viewer password 
configured or the channel overrides the global password with a blank password). In this case, the 
viewer must authenticate withLDAP and cannot use the default viewer account with a blank 
password to log in.
For security reasons, you should configure passwords for the local accounts. See Configure 
LDAP user authentication.
These instructions assume you have a pre-configured LDAP server. The server must support anonymous 
binding or have a special bind account with search access privileges. Note that Active Directory does not 
support anonymous binding. LDAP referrals, restrictions and failovers are not supported.
To configure LDAPauthentication:
1.  Login to the Admin panel as admin, see Connect to the Admin panel.
2.  From the Configuration menu, select Security. The Security configuration page opens.
3.  In the LDAPauthentication section, check Enable LDAPauthentication. Uncheck the check box 
to disable LDAP authentication.
168










