Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

For Indeed Certificate Manager Axidian CertiFlow system to operate properly, you must have certain access rights to access Active Directory objects and certification authorities are required. You . Depending on your company's security policy, you can distribute the privileges between several accounts, or create one service account with maximum rights for system management, depending on the requirements of the company security policy.

Create a user service account (say, servicecm) to use with Indeed Identity container. The said account is used to perform data saving operations in Active Directory. The following permissions must be set for the said account:

  • Full Control for the container that stores the system data (default name is “Indeed Identity”) and all of its descendant objects. To do so:

1. Open the Security property of the Indeed Identity container.
2. Click Add and specify the service account (servicecm).
3. Click Advanced, select the service account and click Edit.
4. Select the scope of This object and all descendant objects.
5. Set the Full control permission in the Permissions list.
6. Click ОК and then Apply.

  • Permission to Read all Properties:
1. Open

e.g. cfServiceAD) and grant it the necessary permissions to work with an object (domain, container, organizational unit) that contains Axidian CertiFlow users. This account will be used to read and write user attributes.

Go through these steps:

  1. Open Security property of the object (domain, container or organizational unit) that contains
the Indeed CM system
  1. Axidian CertiFlow users.
2. Select
  1. Click AdvancedAddSelect a principal.
  2. In the Enter the object name to select text box, enter the name of the service account (
servicecm
  1. cfServiceAD) and
then
  1. click
Edit
  1. OK.
3. Select the
  1. In the Applies to list box, select Descendant User objects
scope.
4. Set the
  1. .
  2. In the Permissions list, activate:
    • List contents
    • Read all properties

      Info

      By default, permission to read all user properties is granted to all accounts in the

Properties list checkbox.
7. Click ОК and then
    • domain.

5. Activate the following checkboxes in the Properties list:
      • Write: userAccountControl
      • Write: thumbnailPhoto or Write: jpegPhoto
      • Write: pwdLastSet
6. In the Permissions list, activate the Reset password
  1. In the Properties list, set the following permissions:
    • Write pwdLastSet - required to be able to reset user's password.
    • Write thumbnailPhoto or Write jpegPhoto - required to be able to Upload a photo to a user in Active Directory via the system interface.
    • Write userAccountControl - required to enable Enforce smart card logon option.
  2. Click ОК and
  1. Apply.
Warning

Set Assign the same set of privileges for to each object (domain, container or organizational unit) where Indeed CM users are located.that contains Axidian CertiFlow users.

In case the domain security policies forbid reading The permission to read all user properties is set for all domain accounts by default. If security policies prohibit reading of all user properties, then set the rights for the you can specify that the service account has permissions to only read only required properties, according to the Table 3.When configuring the permissions to read user properties different from default ones, it is also necessary to permit the service account (servicecm) to read the values of object attributes (i.e. Domain, container the necessary user attributes (Table 3) and object attributes (domain, container, or organizational unit) that contains Indeed CM Axidian CertiFlow users. These attributes are: cn, objectGUID, name and showInAdvancedViewOnly.

Go through these steps:

  1. In the ADSI edit snap-in, open the Security property of the object (domain, container or division) that contains Axidian CertiFlow users.
  2. Set the following in This object and all descendant objects field:
    • In Permissions check the List contents box.
    • In Properties check the following boxes:
      • Read сanonicalName
      • Read Distinguished Name
      • Read objectClass
      • Read objectGuid
      • Read showInAdvancedViewOnly
  3. Set the following in Descendant user objects: User objects field:
    • In Permissions check the List contents box.
    • In Properties select read/write the following sets of properties and attributes (Table 3):
      • Read personal Information
      • Read general Information
      • Read account restrictions
      • Read public Information
      • Write pwdLastSet
      • Write thumbnailPhoto or Write jpegPhoto
      • Write userAccountControl
Info

LDAP Display Names are listed below.

Granting access to the properties set significantly increases the system performance significantly and also simplifies the security management (see Property Sets).

Table 3

. Attributes used by

Indeed CM

Axidian CertiFlow to work with

user directory.

users catalog
Table auto

Attribute (LDAP Display


Name)

Common Name

Commentary

c

Country/Region Abbreviation or Country/Region Name

Is a part

Part of "Personal information" properties set.

сanonicalNameCanonical NamePart of "Public Information" properties set.
cnCommon Name
Is a part

Part of

the

"Public Information" properties set.

companyCompany
Is a part

Part of

the

"Public Information" properties set.

departmentDepartment
Is a part

Part of

the

"Public Information" properties set.

objectGUID
distinguishedName
ОbjectGUID
Distinguished NamePart of
Is a part of the
"Public Information" properties set.
givenNameGiven Name
Is a part

Part of

the

"Public Information" properties set.

lLocality Name
Is a part

Part of

the

"Personal Information" properties set.

mailE-mail Addresses
Is a part

Part of

the

"Public Information" properties set.

managerManager

Part of "Public Information" properties set.

objectClassObject ClassPart of "Public Information" properties set.
objectGUIDОbjectGUID

Part of "Public Information" properties set.

objectSidObject SidPart of "General Information" properties set.
otherMailboxOther MailboxPart of "Public Information" properties set.
proxyAddressesProxy AddressesPart of
Is a part of the
"Public Information" properties set.
pwdLastSetPwd Last SetPart of "User Account Restrictions" properties set.
sAMAccountNameSAM Account Name
Is a part

Part of

the

"General Information" properties set.

snSurname
Is a part

Part of

the

"Public Information" properties set.

st

State or Province Name

Is a part

Part of

the

"Personal Information" properties set.

streetAddressAddress (
или
or Street)
Is a part

Part of

the

"Personal Information" properties set.

telephoneNumberTelephone Number
Is a part

Part of

the

"Personal Information" properties set.

thumbnailPhoto

or jpegPhoto

Picture
Is a part

Part of

the

"Personal Information" properties set.

userAccountControl

User Account Control

Is a part

Part of "User Account Restrictions" properties set.

userPrincipalNameUser Principal Name
Is a part

Part of

the

"Public Information" properties set.