Administer > Configuring setup options > Lightweight Directory Access Protocol (LDAP)

Lightweight Directory Access Protocol (LDAP)

You can integrate ITSMA Service Management to an LDAP directory service to share contact information across your network. Once you have enabled an LDAP integration to ITSMA Service Management, you can then configure ITSMA Service Management to automatically create operator records for LDAP users by either of the following methods:

Using either method, you can map fields in the operator record to contact information in the LDAP directory service. This mapping allows ITSMA Service Management to create an operator record with all the available contact details defined in the LDAP directory service. If you create an LDAP user template, you can make changes to all users built from this template by editing the template operator record. If you create a system default record, then you must manually make changes to each individual operator record that ITSMA Service Management creates. If you create both an operator template and a system default operator record, ITSMA Service Management uses the operator template to create new operator records.

Caution Using the legacy listener with an LDAP integration is NOT supported.

Note ITSMA Service Management denies access to LDAP users unless the system administrator defines either an operator template or a system default operator record.

The Service Management server uses the LDAP Bind DN user that is defined in the “ldapbinddn” parameter to access LDAP. The privileges of this LDAP user determine whether the Service Management server can add or update LDAP accounts. When a system administrator adds or updates operators in Service Manager, whether the operator changes in Service Manager can be synchronized to LDAP or not is determined by the privileges of the LDAP Bind DN user.

Note Deleting an operator record does not cause ITSMA Service Management to delete LDAP users. Only an LDAP administrator can delete LDAP entries.

Typically, ITSMA Service Management system administrators will want to map only the operators file to an LDAP directory, however they can also map any other system table, for example, the contacts or device table, to an LDAP directory. You can map a ITSMA Service Management table to only one LDAP server at a time, although you may specify a different LDAP server for each table.

When mapping between ITSMA Service Management and LDAP directories, you can decide which data source you want to be primary. In cases where there are duplicate entries between data sources, ITSMA Service Management displays only the data listed in the primary data source.