TROUBLESHOOTING


Internet user authentication using an LDAP directory fails
To authenticate Internet users registered in a remote LDAP directory, make sure you complete these steps:

1. Select LDAP as the "Domain Type" in the Directory Assistance document.

2. Specify a "Domain Name" that is not the IBM® Lotus® Domino™ domain of the servers that use directory assistance and that is not used in another Directory Assistance document.

3. (Recommended) Enter "1" as the search order.

4. Set "Trusted for credentials" to Yes for at least one naming rule in the Directory Assistance document that corresponds to the names of the users to authenticate.

5. If the remote LDAP server requires a base DN, enter it in the field, "Base DN for search."

6. Select "Notes clients/Internet Authentication/Authorization" in the "Make this domain available to" field.

7. If you enabled "Channel encryption," make sure you've configured SSL properly.

8. If the LDAP directory server doesn't allow anonymous connections, make sure you've entered a user name and password in the "Optional Authentication Credential" section of the Directory Assistance document.

9. If the server authentication option "More name variations with lower security" is selected, make sure the server has access to the LDAP directory attributes cn, uid, sn, givenName, and objectClass.


See also