Configuring LDAP authentication

Kaspersky CyberTrace supports LDAP user authentication to allow logging in as a domain user. This section explains how to configure this type of authentication by using Kaspersky CyberTrace Web.

Kaspersky CyberTrace supports the use of Active Directory only if the domain controller is running Windows. The use of Active Directory with Linux-based domain controllers is possible, but not guaranteed.

The LDAP section allows you to perform the following actions:

Enabling LDAP authentication

To enable LDAP authentication,

Click the LDAP auth enabled toggle button.

The LDAP server will now be used for user authentication.

When LDAP authentication is enabled, you still can interact with Kaspersky CyberTrace under a local user account.

Testing the connection to the LDAP server

Go through the procedure below to make sure that a connection to the LDAP server is established.

To test the connection to the LDAP server:

  1. Click the Test connection with LDAP link.

    The Test connection with LDAP window opens.

  2. Specify the following settings:
    • User name for test connection
    • User password for test connection
  3. Click Test.

A connection test can be performed only if you specified all the necessary settings for connecting to the server.

Connection settings

In the Connection settings section of the LDAP tab, you can specify the following settings:

Accounts filtering

The Accounts filtering section contains filtering rules for administrator and analyst accounts.

You can configure the following properties:

If the AdministratorAccountsFilter and AnalystAccountsFilter elements of the kl_feed_service.conf file contain values, and the user that is trying to log in is not included in any of the specified groups, Kaspersky CyberTrace will return an error and deny access to the web user interface for this user.

Page top