<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ACME LDAP Username matching in Operating System - OpenVMS</title>
    <link>https://community.hpe.com/t5/operating-system-openvms/acme-ldap-username-matching/m-p/5234104#M98348</link>
    <description>We are looking into setting up ACME LDAP on VMS 8.3 to authenticate against Active directory.  A question came up that I want to verify what I think is the correct answer.&lt;BR /&gt;&lt;BR /&gt;If AD accounts and VMS login usernames don't match, what happens?  Another way to ask this question is, "Do AC account usernames and the VMS login usernames have to match?"&lt;BR /&gt;&lt;BR /&gt;I did find the below as a restriction from the 2007 release notes and I believe that is what this means.  I just want to make sure I haven't missed some enhancement or note somewhere else.&lt;BR /&gt;&lt;BR /&gt;LDAP-to-OpenVMS username mapping is currently required to be one-to-one. That is, the username entered at login that matches an LDAP entry must have a corresponding record in the local systems's SYSUAF.DAT file.&lt;BR /&gt;&lt;BR /&gt;Thanks so much!</description>
    <pubDate>Thu, 08 Apr 2010 16:07:27 GMT</pubDate>
    <dc:creator>Mike R Smith</dc:creator>
    <dc:date>2010-04-08T16:07:27Z</dc:date>
    <item>
      <title>ACME LDAP Username matching</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/acme-ldap-username-matching/m-p/5234104#M98348</link>
      <description>We are looking into setting up ACME LDAP on VMS 8.3 to authenticate against Active directory.  A question came up that I want to verify what I think is the correct answer.&lt;BR /&gt;&lt;BR /&gt;If AD accounts and VMS login usernames don't match, what happens?  Another way to ask this question is, "Do AC account usernames and the VMS login usernames have to match?"&lt;BR /&gt;&lt;BR /&gt;I did find the below as a restriction from the 2007 release notes and I believe that is what this means.  I just want to make sure I haven't missed some enhancement or note somewhere else.&lt;BR /&gt;&lt;BR /&gt;LDAP-to-OpenVMS username mapping is currently required to be one-to-one. That is, the username entered at login that matches an LDAP entry must have a corresponding record in the local systems's SYSUAF.DAT file.&lt;BR /&gt;&lt;BR /&gt;Thanks so much!</description>
      <pubDate>Thu, 08 Apr 2010 16:07:27 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/acme-ldap-username-matching/m-p/5234104#M98348</guid>
      <dc:creator>Mike R Smith</dc:creator>
      <dc:date>2010-04-08T16:07:27Z</dc:date>
    </item>
    <item>
      <title>Re: ACME LDAP Username matching</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/acme-ldap-username-matching/m-p/5234105#M98349</link>
      <description>The username and the entry in Open Directory (OD) or Active Directory (AD) LDAP has to match; AFAIK, there's no provision for a username-to-LDAP "proxy" mapping mechanism here.  I've certainly not encountered it in my "adventures" here.&lt;BR /&gt;&lt;BR /&gt;Oh, and the ACME documentation is, um, weak.  &lt;BR /&gt;&lt;BR /&gt;Before you start this quest, check in with the HP OpenVMS Engineering folks.  It would not surprise me to learn that they have updated documentation.  &lt;BR /&gt;&lt;BR /&gt;I've certainly accumulated a pile of (local) documentation from my experiences.  To your advantage here, AD should be a bit easier to sort than OD, as AD is what HP most often seems to document here.&lt;BR /&gt;&lt;BR /&gt;I did successfully get the OpenVMS boxes authenticating to the Mac OS X Server and an OD infrastructure.&lt;BR /&gt;&lt;BR /&gt;Beyond any documentation updates that HP might have, here are some URLs you'll want to review:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://www3.sympatico.ca/n.rieck/docs/openvms_notes_ldap.html" target="_blank"&gt;http://www3.sympatico.ca/n.rieck/docs/openvms_notes_ldap.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://labs.hoffmanlabs.com/node/619" target="_blank"&gt;http://labs.hoffmanlabs.com/node/619&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://h71000.www7.hp.com/openvms/journal/v4/openvms_journal.pdf" target="_blank"&gt;http://h71000.www7.hp.com/openvms/journal/v4/openvms_journal.pdf&lt;/A&gt;&lt;BR /&gt;</description>
      <pubDate>Thu, 08 Apr 2010 16:30:30 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/acme-ldap-username-matching/m-p/5234105#M98349</guid>
      <dc:creator>Hoff</dc:creator>
      <dc:date>2010-04-08T16:30:30Z</dc:date>
    </item>
    <item>
      <title>Re: ACME LDAP Username matching</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/acme-ldap-username-matching/m-p/5234106#M98350</link>
      <description>Thanks so much for the reply, I got my initial information from your site which had the 2007 doc on it.  I will check the links you provided.</description>
      <pubDate>Thu, 08 Apr 2010 17:47:23 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/acme-ldap-username-matching/m-p/5234106#M98350</guid>
      <dc:creator>Mike R Smith</dc:creator>
      <dc:date>2010-04-08T17:47:23Z</dc:date>
    </item>
    <item>
      <title>Re: ACME LDAP Username matching</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/acme-ldap-username-matching/m-p/5234107#M98351</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;Yes, on V8.3 and V8.3-1H1, there is currently only one-to-one mapping.&lt;BR /&gt;&lt;BR /&gt;The next release of OpenVMS (V8.4 to be released), there is a proxy mechanism (i.e. mapping between directory server users and the sysuaf.dat (OpenVMS users). The documentation for the LDAP ACME is also getting updated on this OS version.&lt;BR /&gt;&lt;BR /&gt;Thanks and warm regards,&lt;BR /&gt;Prasad</description>
      <pubDate>Fri, 09 Apr 2010 07:00:34 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/acme-ldap-username-matching/m-p/5234107#M98351</guid>
      <dc:creator>sgprasad</dc:creator>
      <dc:date>2010-04-09T07:00:34Z</dc:date>
    </item>
    <item>
      <title>Re: ACME LDAP Username matching</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/acme-ldap-username-matching/m-p/5234108#M98352</link>
      <description>Thanks so much and to the earlier point, the documentation is a bit economical.  It will be great to see it enhanced.</description>
      <pubDate>Fri, 09 Apr 2010 11:42:02 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/acme-ldap-username-matching/m-p/5234108#M98352</guid>
      <dc:creator>Mike R Smith</dc:creator>
      <dc:date>2010-04-09T11:42:02Z</dc:date>
    </item>
    <item>
      <title>Re: ACME LDAP Username matching</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/acme-ldap-username-matching/m-p/5234109#M98353</link>
      <description>Per the answers given, the mapping is one to one.  In the event of a local account that is not in AD, one would not put the external authentication flag on that account which would keep it authenticating locally.</description>
      <pubDate>Fri, 09 Apr 2010 11:44:42 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/acme-ldap-username-matching/m-p/5234109#M98353</guid>
      <dc:creator>Mike R Smith</dc:creator>
      <dc:date>2010-04-09T11:44:42Z</dc:date>
    </item>
  </channel>
</rss>

