Tab | Field | Value | Comment |
Basics | User name
(FullName) | Two-part Active Directory logon name |
- Specify the logon name shown in the user's Active Directory account user interface.
- Specify as the third or subsequent name in this field.
- Use exact case shown in Active Directory for the first name part. Use uppercase for the second name part, regardless of case shown in Active Directory.
For example: bzechman@AD1.SUBNET2.RENOVATIONS.COM
- Can optionally add name to krbPrincipalName field too.
- Used to link this Person record to the Active Directory Kerberos identity.
|
Basics | User name (FullName) | User's distinguished name in Active Directory |
rather than
uid=bzechman,ou=marketing,dc=renovations,dc=com
- Used to map Active Directory distinguished names in SSO LTPA tokens to Notes distinguished names for determining user access to Domino resources.
|
Basics | Internet Password (HTTPPassword) | password-hash |
- If Domino uses directory assistance to connect to the Active Directory server, this user password must be different than the user password in Active Directory.
- Enables Domino to verify user passwords in the Domino Directory in situations when Windows single sign-on is not available.
|
Administration (Client Information section) | Active Directory (Kerberos) logon name
(krbPrincipalName) | Two-part Active Directory logon name |
|
Administration (Client Information section) | LTPA user name | User's distinguished name in Active Directory |
- Required only if there is an IBM WebSphere SSO server authenticating users against Active Directory so that users' LTPA tokens contain their Active Directory names.
- Used to map Active Directory distinguished names in SSO LTPA tokens to Notes distinguished names for determining user access to Domino resources.
|