LDAP directory tab
This tab displays the users and groups that are defined in the directories configured on the firewall.
To access data on a user or group in order to display or edit it, select the user or group in the CN grid (left side of the screen): the relevant information appears in the column on the right.
Refer to the section Allowed names to find out which characters are allowed and prohibited in various fields.
Rule grid
This grid consists of one to three columns:
- The CN column, displayed by default, which includes user and group names in identifier@directory format,
- The DN column, hidden by default, which displays the Distinguished Name of the user or group (CN, OU, O and DC fields describe the user or group in its reference directory),
- The TOTP column, hidden by default, which contains a green tick for each user authenticated by a TOTP (Time-based One Time Password ) method.
Details of a user
Account tab
| ID (cannot be modified) | Connection ID of the selected user. |
| Last name (cannot be modified) | Last name of the selected user |
| First name (cannot be modified) | First name of the selected user |
| E-mail address | E-mail address of the selected user. |
| Phone number | Telephone number of the selected user |
| Description | Description of the selected user. |
| Create or update password | By clicking on this link, you will be able to create the user’s authentication password in a specific window, which also displays the level of security. NOTE |
TOTP
This section appears only when the selected user authenticated on the firewall with a TOTP.
| TOTP code to be verified | In this field, enter the TOTP used to connect to services on the firewall that use TOTP authentication to verify its validity. |
| Reset enrollment | When you click on this button, the user’s TOTP enrollment will be reset: the next time this user connects to services on the firewall that use TOTP authentication, he or she will need to start the whole process of TOTP enrollment all over again. NOTE |
Certificate tab
This tab allows you to:
- Display the user's x509 certificate when it exists and has been published in the LDAP directory,
- Create the user's identity when it does not exist in the PKI,
- Delete the user's certificate from the LDAP directory.
Since the PKI does not have a certification authority by default, you will need to create one in order to manage user’s certificates: go to the Objects module > Certificates and PKI > Add button > Add a root authority.
This certificate will be useful in two cases: SSL authentication and VPN access to the firewall with a mobile IPsec client. This certificate can also be used by other applications.
Member of these groups tab
This tab allows including the user in one or several groups:
- Click on Add.
A new line will appear at the top of the table. - Select the arrow to the right of the field.
A drop-down menu will display the list of existing groups. - Click on the desired group, and confirm your selection by clicking on Apply.
The user is added to the table.
To remove a group, select it and click on Delete.
The maximum number is 50 groups per user.
Details of a group
Details
| Name of the group (cannot be modified) | Name of the selected group. |
| Description | Description of the selected group. |
The grid below the Details frame shows the users that belong to the selected group.
To add a user to the group:
- Click on Add.
A new line will appear at the top of the table. - Select the arrow to the right of the field.
A drop-down menu displays the list of users found in the directory. - Click on the desired user, and confirm your selection by clicking on Apply.
The user is added to the table. - Click on Apply to save the changes.
To remove a user from the group, select it and click on Delete.
Possible operations
Search bar
To search for a user or user group, enter all or part of the user's first name, last name and/or login: all users and/or user groups with names that contain the characters entered will be displayed.
EXAMPLE
If you type “a” in the search bar, the list below it will show all users and/or user groups with first names and/or last names containing an “a”.
Filter
This button allows you to select the type of CN to display. A drop-down menu offers the following choices:
| Groups and users | Represented by the icon , this option makes it possible to display users and user groups in the list. |
| Users | This option is represented by the icon , which makes it possible to display only users in the list. |
| Groups | This option is represented by the icon , which makes it possible to display only user groups in the list. |
Directory filter
When several directories are configured on the firewall, this button filters the display of users and/or groups according to the directory selected.
Add user
- To create a user, click on Add a user, then select the relevant directory.
- Enter at least the user's ID and Last name, and assign a Password.
To associate a certificate with this user, you will need to indicate a valid e-mail address.
The following are the various fields that are available when creating a user:
Account
| ID (login) |
User’s login. This field is mandatory. |
| Name |
User name. This field is mandatory. |
| First name | User's first name. |
| User’s e-mail address, This will be useful for creating certificates for the user. |
|
| Phone number | User’s telephone number |
| Description | Description of the user |
NOTE
The fields “ID”, “First name” and “Last name” cannot be modified after the user is created.
Authentication password
| Password |
Enter the user’s password. This field is mandatory. |
| Confirm password |
Enter the password again. This field is mandatory. |
| Password strength | A gauge indicating the robustness of the password will appear. |
- Click on Next, then select any available groups in the reference directory that you wish to assign to the user.
- Click on Finish to confirm the creation of the user.
Add group
- To create a group, click on Add a group, then select the relevant directory.
- Enter at least the Group name.
The following are the various fields that are available when creating a group:
Details
| Group name |
Give your group a name in order to identify it in the grid. This field is mandatory. NOTE
|
| Description | You can provide a description of the group and modify the contents of the description whenever necessary. This field is optional but you are advised to fill it in. |
Members
| Initial member |
Select the first member to be added to the group. This field is mandatory: new groups cannot be empty. |
- Click on Create to confirm the creation of your user.
Deleting users or groups
Groups or users that do not have certificates issued by the firewall's PKI
- Select the user or group to be deleted.
- Click on Remove.
A window will appear with the message “Delete the user <name of user>?“. - Select Yes to proceed.
Users who have certificates issued by the firewall's PKI
- Select the user to remove.
- Click on Remove.
A window will appear with the message “Delete the user <name of user>?“. - Enter the CA passphrase (password of the authority that issued the certificate).
- Select the checkbox Export CRL after revocation if you wish to keep a copy of the CRL.
- In this case, select the File format of the CRL export:
- Base64 format (PEM),
- Binary format (DER).
- Click on Apply.
- If you have chosen to export the CRL, a window will open with a link to download the CRL export file.
Check usage
Represented by the icon
, this button will show you which groups users belong to, as well as where the user or group is used in the rest of the configuration.
Filtering:
- Select the user or group for which you wish to check usage.
- Click on Check usage.
The menu directory on the left will show you the user/group (via its ID) in the tab Users and groups, and displays the list of groups to which this user belongs, as well as its use in the configuration of the firewall.
Reset user’s TOTP enrollment
This button is enabled only when the selected user authenticated on the firewall with a TOTP.
When you click on this button, the user’s TOTP enrollment will be reset: the next time this user connects to services on the firewall that use TOTP authentication, he or she will need to start the whole process of TOTP enrollment all over again.
NOTE
Users with administration privileges cannot be deleted from the TOTP database.
Access privileges module
This shortcut makes it possible to display the user's access privileges directly in the Users > Access privileges module.
Interactive features
Some operations listed in the taskbar can be performed by right-clicking on the table of users/groups (CN table):
- Deleting (the user or the selected group),
- Checking usage (of the user or the selected group),
- Resetting the selected user’s TOTP enrollment.
, this option makes it possible to display users and user groups in the list.
, which makes it possible to display only users in the list.
, which makes it possible to display only user groups in the list.