Administer > Configuring installation and setup options > Lightweight Directory Access Protocol (LDAP)

Lightweight Directory Access Protocol (LDAP)

You can integrate HPE Service Manager to an LDAP directory service to share contact information across your network. Once you have enabled an LDAP integration to HPE Service Manager, you can then configure HPE Service Manager to automatically create operator records for LDAP users by either of the following methods:

  • Defining a user template for LDAP log ins
  • Defining a system default record for all log ins

Using either method, you can map fields in the operator record to contact information in the LDAP directory service. This mapping allows HPE Service Manager to create an operator record with all the available contact details defined in the LDAP directory service. If you create an LDAP user template, you can make changes to all users built from this template by editing the template operator record. If you create a system default record, then you must manually make changes to each individual operator record that HPE Service Manager creates. If you create both an operator template and a system default operator record, HPE Service Manager uses the operator template to create new operator records.

Caution Using the legacy listener with an LDAP integration is NOT supported.

Note HPE Service Manager denies access to LDAP users unless the system administrator defines either an operator template or a system default operator record.

After you have mapped fields in an operator record to a LDAP directory service, only users who are both LDAP administrators and HPE Service Manager system administrators can update and add new operator records. HPE Service Manager applies this restriction because HPE Service Manager synchronizes any changes you make to the operator record with the corresponding LDAP entry. In addition, if you create new operator records, then HPE Service Manager also creates new users in the LDAP directory.

Note Deleting an operator record does not cause HPE Service Manager to delete LDAP users. Only an LDAP administrator can delete LDAP entries.

Typically, HPE Service Manager system administrators will want to map only the operators file to an LDAP directory, however they can also map any other system table, for example, the contacts or device table, to an LDAP directory. You can map a HPE Service Manager table to only one LDAP server at a time, although you may specify a different LDAP server for each table.

When mapping between HPE Service Manager and LDAP directories, you can decide which data source you want to be primary. In cases where there are duplicate entries between data sources, HPE Service Manager displays only the data listed in the primary data source.