I am trying to help our network person setup the checkpoint fw to use domino’s LDAP services for authentication. It works if I am a user and login. The CP FW downloads all the ou’s and compares the user id against the list however the groups are not in specific ou’s and CP seems to be unable to see these groups. Although I can use an LDAP browser an find cn=groupname, then see the list of users. I am now reading a ream of docs on Domino Ldap from the admin help et al but was wondering if anyone else has tried to do this.
Thanks in advance
Richard A Forbes
richard.forbes@apw.com
Subject: RE: Ldap and Checkpoint FW
After reading the domino admin doc on Domino directories it really became quite obvious what needed to be done. I quote “the first value in the ListName field defines the distinguished name for a Domino Group,” After that it was all down hill.
Subject: Ldap and Checkpoint FW
The CP FW downloads all the ou’s and compares the user id against the list however the groups are not in specific ou’s and CP seems to be unable to see these groups. Although I can use an LDAP browser an find cn=groupname, then see the list of users.
Traditionally, many Domino Group documents live at the root.
I am now reading a ream of docs on Domino Ldap from the admin help et al but was wondering if anyone else has tried to do this.
I am not familiar with Checkpoint, but you probably want to see their documentation to find out if there is a way to specify an empty base (e.g., no hierarchy) for Group directory entries.
Best of luck