8.1.1 Configure the LDAP authentication service

Information

By default, the Universal Control Plane is configured to use the managed user authentication service. UCP should instead be configured to use one or more external LDAP endpoints for authenticating users as this can enable more granular control over authentication and authorization.

Rationale:

UCP's built-in managed user authentication system only supports user creation, deletion and disablement. By using an external LDAP endpoint, you can have more control over the users, groups and other hierarchical organizations that can access and manipulate resources via UCP.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

You can configure LDAP integration via the UCP 'Admin Settings' UI by following the instructions here. LDAP integration can also be enabled via a configuration file by following the instructions here.

Impact:

None.

Default Value:

By default, the built-in managed user database is enabled.

See Also

https://workbench.cisecurity.org/files/2433