Skip to main content

LDAP Queries

An LDAP Query defines the directory-level logic that a USP Server instance uses to search and perform authentication against an external LDAP directory service.

LDAP authentication can be used as:

  • An Auth Source, allowing Users to authenticate to USP Manager against an LDAP directory.
  • An Inbound Authentication Source within a Rule, allowing USP Server instances to validate client credentials against enterprise identity systems.
info

LDAP Queries define the directory-level logic used to perform user lookups and authentication. They operate in conjunction with an LDAP Connection, which specifies the network-level access to the LDAP server.

LDAP Query Administration via USP Admin UI

Adding an LDAP Query

To add an LDAP Query, follow these steps:

  1. From the Sidebar, click Authentication > LDAP.
  2. Click LDAP Queries.
  3. Click Add LDAP Query.
  4. Complete the details for the new LDAP Query using the Field Descriptions table as a guide.
  5. Click Save.

Field Descriptions

NameDescriptionSpecificationsRequired
NameThe name of the LDAP Query.Yes
DescriptionThe description of the LDAP Query.No
Bind DNDistinguished Name (DN) used to bind to the LDAP server.Yes
Bind PasswordPassword for the Bind DN.Yes
Base DNBase DN for searching in the LDAP directory.Yes
User FilterLDAP search filter.For example, (objectClass=person).Yes
User ID AttributeThe LDAP attribute used for user identification.For example, uid.Yes

Editing an LDAP Query

To edit an LDAP Query, follow these steps:

  1. From the Sidebar, click Authentication > LDAP.
  2. Click LDAP Queries.
  3. Click the Name of the LDAP Query you want to edit.
  4. Click the Edit button above the LDAP Query details.
  5. Edit the details of the LDAP Query using the Field Descriptions table as a guide.
  6. Click Save.
warning

If you modify a LDAP Query that is currently in use by a USP Server instance, the changes will not take effect until you manually apply the updated configuration by pushing it to the server. To apply the changes:

  1. Navigate to Monitoring > Status.
  2. Click the Name of the associated USP Server instance.
  3. Go to the Configuration tab.
  4. Review the pending changes in the Updated Configuration column.
  5. If the changes are correct, click Push Configuration.

LDAP Query Metadata

LDAP Query details include all parameters given in the Field Descriptions table, plus the following read-only metadata:

NameDescription
IDUniversally Unique Identifier of this LDAP Query.
Created AtDate and time this LDAP Query was created.
Updated AtDate and time this LDAP Query was last updated.

Deleting an LDAP Query

To delete an LDAP Query, follow these steps:

  1. From the Sidebar, click Authentication > LDAP.
  2. Click LDAP Queries.
  3. Click the Name of the LDAP Query you want to delete.
  4. Click the Delete button above the LDAP Query details.
  5. You will be asked to confirm the deletion. Click Delete.
warning

USP Manager prevents deletion of an LDAP Query if it is currently referenced by a Rule or LDAP for Users.

Additionally, if the LDAP Query is used by a USP Server instance, the updated configuration must be manually applied. To apply the changes:

  1. Navigate to Monitoring > Status.
  2. Click the Name of the associated USP Server instance.
  3. Go to the Configuration tab.
  4. Review the pending changes in the Candidate Configuration - Preview section.
  5. If the changes are correct, click Push Configuration.

The changes do not take effect on the server until this step is completed.