Categories
Configuration Knowledge Support Documentation Support exacqVision Enterprise exacqVision Client exacqVision Server Products Uncategorized exacqVision Integrations

Enterprise Manager supports LDAP authentication with Azure Active Directory 

Azure Active Directory supports the LDAP interface when properly configured, and therefor LDAP can be used to sync the ExacqVision Enterprise Manager software with the Azure AD instance.

Background Information: Lightweight Directory Access Protocol (LDAP) is an application protocol for working with various directory services. Directory services, such as Active Directory, store user and account information, and security information like passwords. The service then allows the information to be shared with other devices on the network. Enterprise applications such as email, customer relationship managers (CRMs), Video Management Software (VMS – ExacqVision), and Human Resources (HR) software can use LDAP to authenticate, access, and find information.

Azure Active Directory ( sometimes referred to as Azure AD) supports this pattern via Azure AD Domain Services (sometimes referred to as AD DS). This allows organizations that are adopting a cloud-first strategy to modernize their environment by moving off their on-premises LDAP resources to the cloud. ExacqVision has supported the use of LDAP authentication since early versions, and now has been enhanced to support the use of LDAP authentication when integrated with Azure Active Directory as a modern solution to cloud based computing.

When a network hosting Enterprise Manager on-premise has been properly configured for communication with an Azure Active Directory instance by verifying no port restrictions or other environmental variables inhibit communication – ExacqVision Enterprise Manager has the ability to support the use of LDAP authentication with Azure Active Directory as of December 15th, 2022 – and subsequent releases thereafter.  

Products 

  • ExacqVision Enterprise Manager version 22.12.0.0 and up

Minimum Requirements for ExacqVision Enterprise Manager Software: 

  • Enterprise Manager version must be 22.12.0.0 or later
  • Your network configuration must be properly configured to communicate with your Azure AD instance
  • you must have Azure Active Directory credentials with access to the following Active Directory parameters – as supplied by your Local IT Department or Network Administrator: objectClass (specifically “group” & “user”), userPrincipalName , sAMAccountName , inetOrgPerson , krbPrincipalName

Configuration Steps for Enterprise Manager: 

  • Properly configure the network to communicate with Azure Active Directory instance without restriction.
  • Verify you possess the minimum credential requirements needed to complete the integration as listed above (supplied by your Local IT Department or Network Administrator) and login to Enterprise Manager user interface with administrative privileges
  • Navigate to the Domain settings page
  • Under “Add Domain” enter the address of the Azure Active Directory instance in the “Hostname or IP” field and enter the above mentioned credential criteria with the proper port number, security protocol, Search Criteria information, and Attribute names information in their corresponding fields – as supplied by your Local IT Department or Network Administrator
  • Apply the changes.

Expected Results 

The above steps when executed properly will sync with the Azure AD Instance, allowing LDAP authentication in ExacqVision Enterprise Manager.

For more information on how to configure ExacqVision Enterprise Manager for use with LDAP authentication please see the ExacqVision Enterprise Manager user manual.

Categories
Knowledge Support Support exacqVision Client

Enable Local Users Accounts is Disabled Within the exacqVision Client

Description 

The Enable Local User Accounts check box is grayed out (Disabled) on the Enterprise or Configure System ActiveDirectory/LDAP tabs.

Product 

  • exacqVision Client

Steps to Reproduce 

  1. Within the exacqVision Client navigate to either :

Expected Results 

  • The Enable Local User Accounts checkbox is enabled 

Actual Results 

  • The Enable Local User Accounts checkbox is grayed out (disabled)

Solution

  • This is expected behavior
  • The Enable Local User Accounts checkbox will be grayed out (disabled) if the user is currently logged in as a local user.   
  • This is done to prevent users from accidently locking themselves out of the system.
  • To enable the Local User Account checkbox, you must first login as an Active Directory/LDAP user.

Categories
Knowledge Support Support exacqVision Server exacqVision Hardware exacqVision Integrations

AES encryption method support for the LDAP connection

ExacqVision Server software is not supporting the AES encryption method in the connection with LDAP earlier than version 21.12.6

If you are using an earlier version of the ExacqVision Server, you will be able to communicate with LDAP using the RC4 encryption method only

To determine if you are using the AES encryption or not.

Check the logs from Exacq server for the StreamPi plugin, and if you are using the AES encryption and the Server is not able to decode it then it would show you these logs

StreamPI   Warning   Encryption type: aes-cts-256-sha1-96 (occurs 58811 times)
StreamPI   Warning   Unable to decode encrypted ticket (occurs 33140 times)
StreamPI   Warning   Unable to decode encrypted element (occurs 22007 times)

Another method to check

From the Active directory in the DC, go to the binding user and right-click on it then properties, then navigate to the Account tab

If you are using the AES encryption, then you should have the AES 128 or AES 256 or both checked

Categories
Knowledge Support Support exacqVision Client exacqVision Server Categories Products Uncategorized

Setting a primary group to an LDAP user

Issue

If you have an LDAP group listed on the ExacqVision server, and you set this group as a primary group for a specific user. The Active Directory will not authorize this user to log in on ExacqVision software.

Solution

Remove this group from being the primary group of the user, or add this user to the ExacqVision server users directly.

<br>

Categories
Knowledge Support Support exacqVision Client exacqVision Server Categories

Setting the listed LDAP group on Exacq as the primary group for a specific user will not allow the user to log in

If you have an LDAP group that is listed on Exacq and set this group as the primary group for a specific user, this user will not be able to log in on Exacq Software.

The workaround for this issue:

  1. Setting another group as an admin for this user.
  2. Adding another group in which that user is a member.
  3. Adding this LDAP user to the ExacqVision users.

<br>

Categories
Knowledge Support Support exacqVision Server Categories Products

Does exacqVision Work with Nested Active Directory Groups?

Yes with server version 6.8 and later.

The admin needs to select Active Directory (Nested) as the schema in the AD/LDAP configuration screen.

<br>

Does-exacqVision-Work-with-Nested-Active-Directory-Groups.pdf