CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Certifications And Exams > CCSA (Check Point Certified Security Administrator) > CCSA NGX Exam 156-215.1
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-07-07
Junior Member
 
Join Date: 2007-06-19
Posts: 19
Rep Power: 0
imslickrick2k has an average reputation (10+)
Default Distinguished Name (DN) not found in LDAP?

I'm seeing conflicting info on what the correct answer to this question..

Some say NGX takes the common-name value from the Certificate subject, and searches the LDAP account unit for a matching user id

Some say if the first request fails or if branches do not match, NGX tries to map the identity to the user id attribute

what is the correct answer here, i've research smartcentre.pdf and even the ATRG (advanced technical resource guide)

the ATRG states:

The Distinguished Name (DN) is a globally unique name for an entry, and is
constructed by concatenating the sequence of DNs from the lowest level of a
hierarchical structure to the root. The root becomes the relative DN. For
example, if searching for the name John Brown, the search path would start
with John Brown's Common Name (CN).

You would then narrow the search from that point, to the organization he works for, to the country. If John Brown (CommonName) works for the ABC
Company, one possible DN might be cn=John Brown, o=ABC Company, c=US. This is read as “John Brown of ABC Company in the United States.” A different
John Brown who works at the 123 Company might have a DN as follows:
cn=John Brown, o=123 Company, c=UK
The two common names “John Brown” belong to two different organizations,
with different DNs.

Still a little unclear.. can anyone help please

thanks,

Last edited by imslickrick2k; 2008-07-08 at 11:33. Reason: Title change
Reply With Quote
  #2 (permalink)  
Old 3 Weeks Ago
Junior Member
 
Join Date: 2008-11-06
Posts: 2
Rep Power: 0
Samildanach has an average reputation (10+)
Default Re: What is a concrete explanation for Distinguished Name not found in ldap

From the sybex NG book

"when a user authenticates, the enforcement module
first checks if any user objects exist in the VPN-1/FireWall-1 users database for
the username. If not, VPN-1/FireWall-1 then queries the LDAP server, looking
for a match on the username within the configured organization unit. Authentication
occurs via LDAP, and the user is either accepted or rejected."
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 01:18.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0