User authentication
61
LDAP Server authentication
MVP Administrators can use their company’s LDAP server to authenticate user IDs and Passwords,
eliminating the need for MarkVision Client users to maintain separate login IDs and passwords for
use with MarkVision Professional.
If an administrator chooses to utilize LDAP authentication, when creating a new user account they
will only enter the user’s existing network login ID and leave the password field blank. Then, when a
user logs into MVP, they will enter the user ID and password that they use for their company’s local
network. The MarkVision Server then accesses the company’s LDAP server’s directory service and
authenticates the user’s login through either a simple bind protected by SSL, or a secure bind using
Kerberos.
Note: The only directory service that MarkVision Professional 11.0 currently supports is
Microsoft Active Directory.
When enabling LDAP server authentication, administrators have three modes of LDAP
authentication to choose from: Anonymous, simple (Default), and secure. The use of each of these
modes of authentication is determined by how the LDAP server is set up. To use simple LDAP
authentication, an MVP Server account will need to be set up on the LDAP server. Also, when using
simple LDAP authentication to utilize SSL, select the SSL check box and then select the appropriate
SSL certificate from the store to complete the setup.
If using secure (Kerberos) LDAP authentication, the need to set up an MVP Server account will be
determined by the current Kerberos configuration. For information on determining the need to set up
an MVP Server account for Kerberos, see your Kerberos documentation.
To enable LDAP Server authentication
LDAP Server authentication is only accessible through the Master Administrator account. If you are
upgrading from a previous version of MarkVision Professional, open the User Accounts and
Groups task under the MarkVision menu, or select User Accounts and Groups from the All Tasks
list. Select the administrator account and click Edit.
If MarkVision Professional is being installed for the first time, the option to set up LDAP Server
authentication will be available when creating the Master Administrator account.
Note: LDAP authentication works for all user accounts with the exception of the Master
Administrator account. As a result, the Master Administrator account will still need
to contain a password that is unique to MarkVision Professional. Make sure that
the administrator password is defined before proceeding with LDAP Server
authentication setup.
1 Once the Master Administrator account wizard has been accessed, enter a master
administrator account name and password, then click the Authenticate with an LDAP
Server check box.
2 Select the authentication mechanism to be used from the drop-down list. The options are
Anonymous, Simple, and Secure.