User's Manual 254 Document #: LTRT-89730
Mediant 3000
Parameter Description
ï‚§
TLS Context
[LdapConfiguration_Cont
extName]
Assigns a TLS Context for the connection with the LDAP server.
By default, no value is defined (None) and the device uses the default
TLS Context (ID 0).
For configuring TLS Contexts, see ''Configuring TLS Certificate Contexts''
on page 123.
Note: The parameter is applicable only if the 'Use TLS' parameter is
configured to Yes.
Verify Certificate
verify-certificate
[LdapConfiguration_Verif
yCertificate]
Enables certificate verification when the connection with the LDAP server
uses TLS.
ï‚§ [0] No = (Default) No certificate verification is done.
ï‚§ [1] Yes = The device verifies the authentication of the certificate
received from the LDAP server. The device authenticates the
certificate against the trusted root certificate store associated with the
associated TLS Context (see 'TLS Context' parameter above) and if
ok, allows communication with the LDAP server. If authentication fails,
the device denies communication (i.e., handshake fails). The device
can also authenticate the certificate by querying with an Online
Certificate Status Protocol (OCSP) server whether the certificate has
been revoked. This is also configured for the associated TLS Context.
Note: The parameter is applicable only if the 'Use TLS parameter is
configured to Yes.
Connection Status
[LdapConfiguration_Con
nectionStatus]
(Read-only) Displays the connection status with the LDAP server.
ï‚§ "Not Applicable"
ï‚§ "LDAP Connection Broken"
ï‚§ "Connecting"
ï‚§ "Connected"
Note: For more information about a disconnected LDAP connection, see
your Syslog messages generated by the device.
16.3.5 Configuring LDAP DNs (Base Paths) per LDAP Server
The LDAP Search DN table lets you configure LDAP base paths. The table is a "child" of
the LDAP Configuration table (see ''Configuring LDAP Servers'' on page 250) and
configuration is done per LDAP server. For the device to run a search using the LDAP
service, the base path to the directory’s subtree, referred to as the distinguished name
object (or DN), where the search is to be done must be configured. For each LDAP server,
you can configure up to three base paths.
The following procedure describes how to configure DNs per LDAP server through the
Web interface. You can also configure it through ini file (LdapServersSearchDNs).
 To configure an LDAP base path per LDAP server:
1. Open the LDAP Configuration table (Configuration tab > VoIP menu > Services >
LDAP > LDAP Configuration Table).
2. In the table, select the row of the LDAP server for which you want to configure DN
base paths, and then click the LDAP Servers Search DNs link, located below the
table; the LDAP Server Search Base DN table opens.