On top of the page you see the link to the user login page. Copy this link address and give it to your users.
Below the link you can specify several options.
Table 6.1. General options
Server address | The address of your LDAP server |
LDAP suffix | The part of the LDAP tree where LAM should search for users |
LDAP user + password | The DN and password which is used to search for users in the LDAP database. It is sufficient if this DN has only read rights. If you leave these fields empty LAM will try to connect anonymously. |
LDAP search attribute | Here you can specify if your users can login with user name + password, email + password or other attributes. |
HTTP authentication | You can enable HTTP authentication for your users. This way the web server is responsible to authenticate your users. LAM will use the given user name + password for the LDAP login. To setup HTTP authentication in Apache please see this link. |
Login attribute label | This is the description for the LDAP search attribute. Set it to something which your users are familiar with. |
Login caption | This text is displayed at the login page. You can input HTML, too. |
Main page caption | This text is displayed at self service main page where your users change their data. You can input HTML, too. |
Page header | This HTML code will be placed on top of all self service pages. E.g. you can use this to place your custom logo. Any HTML code is permitted. |
Additional CSS links | Here you can specify additional CSS links to change the layout of the self service pages. This is useful to adapt them to your corporate design. Please enter one link per line. |
On the bottom you can specify what input fields your users can see. It is also possible to group several input fields.
Settings
You can allow your users to reset their passwords themselves. This will reduce your administrative costs for cases where users forget their passwords.
To enable this feature please activate the checkbox "Enable password self reset link":
You can now configure the minimum answer length for password reset answers. This is checked when you allow you users to specify their answers via the self service. Additionally, you can specify the text of the password reset link (default: "Forgot password?"). The link is displayed below the password field on the self service login page.
Next, please enter the DN and password of an LDAP entry that is allowed to reset the passwords. This entry needs write access to the attributes shadowLastChange, pwdAccountLockedTime and userPassword. It also needs read access to uid, mail, passwordSelfResetQuestion and passwordSelfResetAnswer. Please note that LAM Pro saves the password on your server file system. Therefore, it is required to protect your server against unauthorised access.
Please also specify the list of password reset questions that the user can choose.
You can inform your users via mail about their password change. The mail can include the new password by using the special wildcard "@@newPassword@@". Additionally, you may want to insert other wildcards that are replaced by the corresponding LDAP attributes. E.g. "@@uid@@" will be replaced by the user name.
LAM Pro can send your users an email with a confirmation link to validate their email address. Of course, this should only be used if the email account is independent from the user password (e.g. at external provider). The mail must include the confirmation link by using the special wildcard "@@resetLink@@". Additionally, you may want to insert other wildcards that are replaced by the corresponding LDAP attributes. E.g. "@@uid@@" will be replaced by the user name.
There is also an option to skip the security question at all if email verification is enabled. In this case the password can be reset directly after clicking on the confirmation link. Please handle with care since anybody with access to the user's mail account can reset the password.
New fields for self service page
There are two new fields that you may put on the self service page for your users. These fields allow them to change the reset question and its answer.
This is an example how can be presented to your users on the self service page:
Password reset link
After activating the password self reset feature there will be a new link on the self service login page. The text can be configured as described above (default: "Forgot password?").
When a user clicks on the link then he will be asked for identification with his user name and email address.
LAM Pro will use this information to find the correct LDAP entry of this user. It then displays the user's security question and input fields for his new password. If the answer is correct then the new password will be set. Additionally, pwdAccountLockedTime will be removed and shadowLastChange updated to the current time if existing.