See below for configuring Active Directory for the Vault.

By default, the vault uses local authentication. You can change the authentication method as required.

To configure Active Directory

  1. Log in to the CSP Vault web GUI.
  2. In the top menu bar, click Settings.
  3. In the General Settings section, click Authentication.
  4. On the Authentication page, select LDAP as the Authentication Type.

  5. On the Domain tab, enter:

    • Domain Name—Enter the domain name for the service account.
    • Directory Service Type—Select Microsoft AD if you plan to use Microsoft AD directory services, or OpenLDAP for all non-Microsoft AD directory services.
    • Service Account Name—Enter the name of the service account for the given domain (for example, Administrator). 

      The service account needs read-only access to users and groups on the domain and any subdomain used.

    • Service Account Password —Enter the password for the service account.
    • UID Attribute—Enter the Security Manager Account Name (sAMAccountName) for the user. 

      This is the attribute of the user or group object that would be queried during search.

  6. Click Apply to save the changes.
  7. Click the Domain Controllers tab.
  8. Click +

  9. Add the following details in the Add Domain Controller window. 

  10. Click Save and Close.

Server URL

Select LDAP or LDAPS and enter the domain name or IP address. To include a port number, use the following syntax:

<ip>:<port>

STARTTLS

If you selected LDAP, check the checkbox if you want to use LDAP over TLS.

CA Certificate

The certificate chain of all the Trusted Certificate Authorities that can verify the SSL certificate used by the domain controller.

  • The CA certificate must be in Base64-encoded PEM format.
  • If the CA certificate file you are uploading contains just the certificate of the root certificate authority, make sure that the SSL certificate used by the Domain Controller contains the entire chain of intermediate CA certificates.

Click Load File to select the CA certificate that you want to use.

User Search Context (Base DN)

Enter the Distinguished Name (DN) of the node where the user search should start. For performance reasons, make the base DN as specific as possible. For example: 

dc=ldapserver,dc=com

This option applies to Cryptographic Security Platform Vault-managed account names that are authenticated through LDAP.

Group Search Context (Base DN)

Enter the Distinguished Name (DN) of the node where the search for Security groups should start. 

This option applies to AD Security groups being associated with an admin group.

Timeout

Set the timeout in seconds before connecting to an alternate domain controller.

  • If multiple domain controllers are specified, this is how long the Cryptographic Security Platform Vault waits for a response before re-sending the request to another domain controller.
  • If the DNS server is down, Cryptographic Security Platform Vault may take longer than the time specified here before it fails over to the next domain controller in the list or considers the authentication request failed.

This option only applies to the TCP/LDAP request. It does not apply to the DNS request before the LDAP server has been successfully contacted.