LDAP authentication on an AnywhereUSB® Plus

Starting with Firmware version 21.5, a new “Login attribute” parameter was added. This parameter allows to match the name of the username on the Windows Active Directory server.
You can use this parameter to select the LDAP schema's proper attribute containing the username instead of the default Unix “UID.”



To provide administrative access to the Web User interface “Organization Unit/OU” attribute of the user`s account must match the local group name with administrative privileges on the AnywhereUSB® Plus device.
In this example, we use the default admin group:




 

In firmware release 24.3 became available LDAP authentication against the AD user group with help of “memberOf” attribute.

 

Customer must assign a full DN Groupname alias to the local group with administrative privileges on the AnywhereUSB® Plus device.

 

Please look at the example of the AD user group "CN=awusb_users,CN=Users,DC=mt,DC=local" configuration below:

 

 

Please note:
Enabling  config option "verify server certificate" would have the DAL device validate the SSL cert of the LDAP server against a list of known public CAs in the DAL firmware.  The list is found in /etc/ssl/certs/ca-certificates.crt on the DAL device.  If you are using your own self-signed cert, you must disable this config setting.
When you enable LDAP over SSL (port 636), the Active Directory Domain Controller (DC) presents its server certificate to the client.
The client  validates that certificate against its trusted root CAs.
If the certificate is invalid (expired, wrong hostname, untrusted CA), the client will reject the connection.
The Web Authentication TLS certificate upload section is unrelated to LDAP over TLS (LDAPs) authentication. It applies exclusively to the Web UI login process and has no effect on LDAP authentication configuration.

 

 

Last updated: Jul 07, 2026

Filed Under

Network

Recently Viewed

No recently viewed articles

Did you find this article helpful?