Skip to main content
Data Infrastructure Insights

Configuring an LDAP Directory Server Collector

Contributors netapp-alavoie

Workload Security uses directory data to resolve identities in file-access activity. User Directory collectors do not provide a Test Connection function.

Configure the User Directory Collector before the ONTAP SVM Data Collector

Add User Directory dialog with Active Directory and LDAP Directory Server options.

Table 1. Choose the directory that stores the identities you need Workload Security to resolve.
Select Use it when

Active Directory

Users are stored in Active Directory and monitored activity is SMB; or Unix users are stored in Active Directory with uidNumber values and perform NFS activity.

LDAP Directory Server

Unix users are stored primarily in an LDAP directory and monitored activity is NFS.

Both

Identities are split across Active Directory and LDAP. Add one collector for each authoritative directory so all monitored identities can be resolved.

This page covers LDAP Directory Server

Use this collector for Unix identities maintained in LDAP and used for NFS access.

Before you begin

  • Sign in as a Data Infrastructure Insights Administrator or Account Owner.

  • Deploy and connect a Workload Security Agent that can reach the directory server.

  • Collect the LDAP Directory Server IP address or FQDN, Search Base, Bind DN, and Bind password.

  • Allow the Agent to reach the directory service. Typical ports are 389 for LDAP or StartTLS and 636 for LDAPS; use the port configured on your server.

  • Use a Bind DN account that can search the required directory scope and read every attribute mapped in the collector.

Add the LDAP Directory Server collector

1. Go to Workload Security > Collectors > User Directory Collectors and select + User Directory Collector.

2. Select LDAP Directory Server and select Continue.

3. Complete the connection fields and attribute mappings described below.

4. Review Advanced Configuration if service accounts use object classes that are not included in the default search.

5. Validate the configuration with ldapsearch or an LDAP browser, then select Save Collector.

LDAP Directory Server collector form showing connection fields

LDAP Directory Server collector fields and default attribute mappings.

Connection fields

Field Requirement What to enter

Name*

Mandatory

A unique collector name.

Agent

Mandatory

A connected Agent that can reach this LDAP server.

Server IP/Domain Name*

Mandatory

The LDAP server IP address or FQDN.

Search Base*

Mandatory

The base DN containing the users to import, such as cn=accounts,dc=example,dc=com. Use a narrower OU/CN DN only when the search should be limited to that subtree.

Bind DN*

Mandatory

The full DN of an account permitted to search the base, such as uid=ws-reader,cn=users,cn=accounts,dc=example,dc=com.

Bind Password*

Mandatory

The password for the Bind DN account.

Protocol

Defaulted

LDAP, LDAPS, or LDAP with StartTLS. Select the protocol used by your server.

Port*

Mandatory

The numeric directory port; commonly 389 or 636.

Mandatory attribute mappings

Fields marked with an asterisk must have valid mappings. Keep the defaults unless your LDAP schema uses different attribute names.

Workload Security field Default LDAP attribute Purpose

Display Name*

name

Name displayed in Workload Security

UNIXID*

uidnumber

Resolves numeric Unix user IDs in NFS activity

User Name*

uid

Unix login or account name

Optional attribute mappings

Select Include Optional Attributes only for profile data you want to import. Each mapping must match the actual LDAP schema, including case where the server treats it as significant.

Profile value Default LDAP attribute

Email Address

emailaddress

Telephone Number

telephonenumber

Role

title

State

st

Country

co

Department

departmentnumber

Photo

photo

Manager DN

manager

Groups

memberof

Advanced Configuration: include the accounts you need

The Search Query controls which LDAP objects are imported. The default query includes common Unix and person object classes:

(|(objectClass=posixAccount)(objectClass=person)(objectClass=nsperson))

Computer accounts, device accounts, application identities, or service accounts that use another objectClass remain unresolved. Inspect the object in an LDAP browser or with ldapsearch, then extend the query only for the required object types. For example:

(objectClass=posixAccount)
(objectClass=person)
(objectClass=nsperson)
(objectClass=device)
(objectClass=applicationProcess)
(objectClass=applicationEntity))
Your LDAP schema is authoritative

Object classes and attribute names vary by directory implementation. Confirm the object's actual schema and ensure the mandatory mappings have values before saving. Do not broaden the query more than necessary.

Validate the configuration

Test Connection is not available for User Directory collectors

Validate network access, bind credentials, search scope, query results, and mapped attributes from a host with equivalent access before you save the collector.

Use ldapsearch

Run a scoped search using the intended Bind DN. Replace the examples with your directory values and add the collector's Search Query as the LDAP filter.

ldapsearch -o ldif-wrap=no -LLL -x -H ldap://ldap.example.com:389 -D
"uid=ws-reader,cn=users,cn=accounts,dc=example,dc=com" -W -b
"cn=accounts,dc=example,dc=com"
'(|(objectClass=posixAccount)(objectClass=person)(objectClass=nsperson))'
name uidNumber uid
  • The bind succeeds with the exact account and password that the collector will use.

  • The search returns the expected human, computer, or service account.

  • Every mandatory mapped attribute exists and has a value on the returned object.

  • The Agent has the same DNS resolution and network path to the directory server.

After you save

  • The LDAP sync starts when the collector starts or restarts.

  • A directory with approximately 300,000 users can take about 15 minutes to sync.

  • User data refreshes automatically every 12 hours.

  • If the directory becomes unavailable, previously fetched user details remain, but new or changed users cannot be fetched until connectivity is restored.

  • User data is retained for 13 months without a refresh. User-directory data cannot be deleted independently of the tenant.

Troubleshooting

Message or symptom What to check

Invalid credentials provided for the LDAP server.

Verify the Bind DN and password. Also confirm that the account can search the configured Search Base.

Failed to get the object corresponding to DN=… provided as search base.

Correct the Search Base. Use the exact domain, DN, OU, or other supported scope.

Failed to establish LDAP connection.

Verify the LDAP server IP/FQDN, DNS resolution, protocol, port, and firewall path from the Agent.

Failed to retrieve LDAP users…connection is null.

Restart the collector. If it recurs, validate connectivity and the search with ldapsearch from an equivalent network location.

Collector is RETRYING or reports AGENT008.

Verify the server address and Search Base; then confirm the Agent can reach the directory service.

A user or optional attribute is not displayed.

Verify that the Search Query includes the object and that the mapped attribute name matches the directory schema, including case where applicable. Save to restart and resync.

AcceptSecurityContext error, data 52e.

Verify the credentials and Search Base. In Active Directory, data 52e indicates invalid credentials.

ldap-port has type STRING rather than NUMBER.

Enter a numeric port
value, such as 389 or 636.