VeraLab LDAP Configuration Guide

VeraLab guide · Download as PDF · All documentation

This guide is for VeraLab administrators who want people to sign in with their LDAP directory credentials. It walks you through configuring LDAP authentication for both the VeraLab web application (employee logins) and the VeraLab client on lab workstations, using a Windows-based OpenLDAP server as a working example.

When you finish, employees can log in to the web application with their LDAP accounts, and users of your lab computers sign in through the VeraLab login screen with the same directory credentials.

How VeraLab Uses LDAP

VeraLab Suite is a client-server application with two main components: a web-based application and a client software agent.

The web-based application provides real-time statistics dashboards, workflow automation functions, reporting and application administration. Once the VeraLab server installation is complete, open a browser and go to http://yourservername:8080/veralab.

VeraLab web application login page with the admin user name entered
The VeraLab web application login page.

Note: VeraLab Server comes with a built-in Administrator account, admin. The default password is password; we recommend changing it right after the installation.

The client software agent has no front-end interface. It monitors client events, such as users logging in and out and applications opening and closing, and responds to server commands. It can also add an authentication layer if your client computers do not have one yet:

The only prerequisites for that setup are network connectivity from the VeraLab Server to your LDAP directory server and the LDAP configuration properties described below.

Installing and Configuring OpenLDAP

For demonstration purposes, this guide uses the Windows-based OpenLDAP software available from the Userbooster site. Follow the vendor's installation instructions, or skip this section if you already have an LDAP directory installed and configured on your site.

You can accept all of the defaults in the installation guide. Once the installation is complete, check that the OpenLDAP service is up and running in Windows Services.

Windows Services console showing OpenLDAP Service started with Automatic startup type
OpenLDAP Service running in Windows Services.

To add and modify user accounts in the OpenLDAP directory, this guide uses the LDAP Admin client tool, available from ldapadmin.org.

  1. Create a new connection to the OpenLDAP server you just installed: click the Connect icon, then New connection.
    LDAP Admin toolbar Connect icon and the New connection icon in the Connections window
    Creating a new connection in LDAP Admin.
  2. Enter your OpenLDAP server connection details, such as the connection name and the host name or IP address. The default admin account that comes with Userbooster OpenLDAP is:
    FieldDefault value
    Usercn=Manager,dc=maxcrc,dc=com
    Passwordsecret
    LDAP Admin Connection properties dialog with connection name, host, port 389, base DN and Manager account filled in
    Connection properties for the OpenLDAP server.
  3. Connect to OpenLDAP using the newly created connection.
  4. OpenLDAP comes with no user accounts other than the built-in Manager, so add a few test accounts.
    LDAP Admin Properties dialog for a new test user with first name, last name, display name, username and home directory
    Adding a test user account in LDAP Admin.
  5. Once you add an account, right-click it and select Set Password.
    LDAP Admin right-click menu on a user entry with Set Password highlighted
    Setting the password for the test account.

Now you are ready to configure VeraLab with OpenLDAP.

Configuring the Web Application to Use LDAP

These steps let employees log in to the VeraLab web application with their LDAP credentials.

  1. Log in to VeraLab as the admin user and go to Tools → Settings. If you have only one LDAP directory and all of your user accounts are stored in a single subdirectory, you can reuse Common LDAP Settings for both the client LDAP configuration and employee web application logins.
    VeraLab Tools menu Settings page with the Common LDAP Settings link highlighted
    Tools → Settings, with the Common LDAP Settings link at the bottom.
  2. Click Common LDAP Settings. Enter the LDAP Server URL, the path to the directory where user accounts are stored and the user unique identifier attribute (usually uid, cn or sAMAccountName). After testing and verifying the connection to LDAP, click Save.
    Common LDAP Settings form with Server URL, Search Path, User ID Attribute, LDAP Lookup User DN and password fields
    The Common LDAP Settings form, filled in for the OpenLDAP example.
    FieldWhat to enterValue in this example
    Server URLldap://ldap_server_host:port, where ldap_server_host is your LDAP server FQDN or IP addressldap://neptune:389
    Search PathThe user Base DN, in LDAP Data Interchange Format (LDIF) syntax, e.g. OU=People,DC=example,DC=eduou=People,dc=maxcrc,dc=com
    User ID AttributeThe LDAP attribute used to find the user, most commonly uid, cn or sAMAccountNameuid
    LDAP Lookup User DNThe lookup account, e.g. CN=lookupadmin,OU=Service Accounts,DC=example,DC=edu, or lookupadmin@example.edu for MSADcn=Manager,dc=maxcrc,dc=com
    LDAP Lookup User PasswordThe lookup account's password. Leave blank if LDAP is set up for anonymous access.The Manager password

    Note: the LDAP Lookup account is used to search through LDAP directory accounts when authentication or other operations, such as retrieving additional account attributes, are required. It must have read permissions to search and retrieve account attributes in the LDAP containers you want to search. For Microsoft Active Directory you can use the user principal name; for all other LDAP servers use the full user DN.

  3. To enable LDAP authentication for employees, go to Setup → Users. If you installed VeraLab with the demo data you will see many seeded accounts; if you installed without it, you will see only the one Admin account. At this point these are all Native accounts.
    Employee Administration list in which every account, including Admin, has the Type Native
    Employee Administration: all accounts are Native before LDAP provisioning.
  4. Click the Provision LDAP Users link, then click the LDAP Settings link.
    Provision LDAP Users page with the LDAP Settings link highlighted above the search fields
    The Provision LDAP Users page.
  5. Select Inherit from Common Settings, or Do not inherit from Common Settings to override the common settings with new values.
    LDAP Settings for Employee provisioning with Inherit from Common Settings selected and the inherited values greyed out
    LDAP Settings for Employee provisioning, inheriting the common settings.
  6. The second option, Do not inherit from Common Settings, is needed if you use a different LDAP server or directory container for employee records. If you made any changes, click Test Connection, enter any valid account credentials and verify that the test connection is successful.
    Test Connection dialog with a test username and password, and an Authentication succeeded message
    Testing the connection: Authentication succeeded.
  7. Click Save and return to the Provision LDAP Users screen.
    Confirmation that LDAP settings have been saved, with the Provision LDAP Users link highlighted
    Settings saved; follow the Provision LDAP Users link back.
  8. Enter a username, first name or last name as search criteria and click Search LDAP. If a user record is found, it appears in the results. To provision the user, click Provision.
    Provision LDAP Users search by username returning one LDAP user with a Provision button
    Searching LDAP and provisioning a user.
  9. A new page opens. Fill out the required fields and assign roles and other permissions to the newly created user.
    Add New Employee form for an LDAP employee with email, pay rate, effective date and the Lab Assistant role selected
    Completing the new employee record and assigning a role.
  10. The new user appears in the list of employees with the account type LDAP.
    Employee Administration list showing the newly provisioned user with Type LDAP
    The provisioned employee, now listed as an LDAP account.
  11. Log out and log back in to the VeraLab web application with this account and the password that was set for the user in OpenLDAP.
    VeraLab login page with the LDAP user's username and password entered
    Logging in with LDAP credentials.
  12. The user's landing page is displayed; for the Lab Assistant role, for example, it is the Shift Panel page.
    Shift Panel page shown to a Lab Assistant after logging in, with Start Shift and End Shift buttons
    The Shift Panel landing page for a Lab Assistant.

Configuring the VeraLab Client for LDAP Authentication

These steps make lab workstations show the VeraLab login screen, where users sign in with their LDAP credentials.

  1. Enable Windows automatic logon on your Windows clients if it is not enabled already. For Windows 7, you can refer to this Microsoft article on automatic logon.
  2. Enable LDAP authentication for client stations: log in to the web application and go to Tools → Settings → Client Authentication Settings.
    VeraLab Tools menu Settings page with the Client Authentication Settings link highlighted
    Opening Client Authentication Settings.
  3. Enable client authentication and click Update Settings.
    Edit Client Authentication Settings with client LDAP authentication and the maintenance account both set to True
    Edit Client Authentication Settings.
    SettingDescription
    Enable Authentication for clients running LDAP version of VeraLab ClientSet to True to require LDAP credentials on client workstations.
    Enable Maintenance AccountSet to True to allow a maintenance account to bypass LDAP authentication.
    Maintenance Account UsernameUser name of the maintenance account.
    Maintenance Account PasswordPassword of the maintenance account.

    Note: the maintenance account is used to bypass LDAP authentication when the connection to the LDAP server is broken, or when you need to open a client screen without LDAP credentials, for example for a quick maintenance task.

  4. To use the Common LDAP Settings, or to change LDAP settings for clients, return to the same screen and click the Change LDAP Settings link.
    Edit Client Authentication Settings with the Change LDAP Settings link highlighted
    The Change LDAP Settings link.
  5. Select the option you want and click Save.
    LDAP Settings for Client Workstations Authentication with Inherit from Common Settings selected and the Save button highlighted
    LDAP Settings for Client Workstations Authentication.
  6. Download the LDAP-enabled client from the VeraLab downloads page. The LDAP-enabled client package comes with two files. Open Autologon.ini, enter the credentials of the local Windows account you used for automatic logon in step 1, then save the file and exit.
    [autologon]
    username=<local account username>
    password=<local account password>
  7. Run the setup package. Both files, veralab_client_setup_ldap.exe and Autologon.ini, must be in the same directory when you start the client installation. You must install the VeraLab client as a user with administrator privileges.
  8. Once installation is done, a new window opens automatically. Enter the VeraLab server connection details, such as the server name or IP address, and the Screen Unlock password. The Screen Unlock password is designed primarily for counter sign-on scenarios and is rarely used when LDAP authentication for client stations is enabled.
    VeraLab Guard Settings window with server hostname, connection password and Screen Unlock password fields
    VeraLab Guard Settings: server connection and Screen Unlock password.
  9. Register the client with the server by selecting the Room, Model and Image, then click Finish. Refer to the VeraLab Administrator's Guide for more information on setting up your VeraLab environment.
    VeraLab Guard Settings setup wizard confirming settings saved, room and station registered and the Guard service started
    Client registration complete; click Finish to exit the wizard.
  10. Now when you log out or reboot the client, you are presented with the VeraLab custom login screen and can use LDAP credentials to log on to the Windows session.
    VeraLab lock screen on a workstation with the Log On to VeraLab dialog asking for user name and password
    The VeraLab login screen on a client workstation.
  11. To see client sessions, log in to the VeraLab web application and go to Tools → Monitoring.
    VeraLab Monitoring page showing a workstation occupied by the LDAP user with the session time
    The LDAP user's session on the Monitoring page.

Getting Help

If you have any questions about LDAP configuration, please contact VeraLab Support at support@veralab.com or call 1-855-VERALAB (1-855-837-2522).

Related: VeraLab LDAP integration overview, LDAP and Active Directory sign-in scenarios, SSO integration with Microsoft Azure SAML and the VeraLab FAQ.