beautypg.com

Viewing ldap user details – H3C Technologies H3C Intelligent Management Center User Manual

Page 100

background image

91

All LDAP users matching the query conditions are displayed in the All Bound User list.
To clear the query criteria, click Reset. The All Bound User list displays all LDAP users.

Viewing LDAP user details

You can follow the same procedure to view LDAP user details in the All Bound User list and Bound User

list of a specific synchronization policy. The following information uses the All Bound User list as an

example.
To view an LDAP user details in the All Bound User list:

1.

Click the User tab.

2.

On the navigation tree, select Device User > LDAP Users from the navigation tree.
The All Bound User list displays all LDAP users.

3.

Click the account name of an LDAP user whose detailed information you want to view.
The page includes the following parameters and fields:

{

Account Name—Account name of the LDAP user.
When an LDAP user is blacklisted, the account name of the user is followed by Blacklisted
Users.

{

User Name—Real name of the LDAP user.

{

Status—LDAP user account state. Options are:

Normal—The user account can be used for device login.

Cancelled—The user account is already deleted and cannot be used for device login.

{

Group Authorization Policy—Authorization policy used by the device user group to which the
user belongs. The field displays the name of an existing authorization policy or CLI Access Not

Supported. The following guidelines apply:

Click the policy name to view its details. For more information, see "

Viewing LDAP

synchronization policy details

."

The CLI Access Not Supported option indicates device users of the group can log in to a
device, but they cannot execute any command.

If no authorization policy is specified for the device user group, this field displays the
authorization policy assigned to its parent group.

{

User Authorization Policy—Name of the authorization policy used by the user. Click the name
of the policy to view its details (see "

Viewing authorization policy details

" for more information).

If this field displays CLI Access Not Supported, the user can log in to the device but cannot
execute any command.
If no authorization policy is specified for the user, the user will use the authorization policy
assigned to the device user group.
If different authorization policies are assigned to the user and the device user group to which
the user belongs, the policy configured for the device user takes effect.

{

Creation Date—Date when the LDAP user was created, in the format YYYY-MM-DD.

{

Last Logoff—Date and time when the LDAP user last logged off, in the format YYYY-MM-DD
hh:mm.
If the user has never logged in to a device, this field displays the time when the user account

was created.