LDAP directory tab

This tab displays the users and groups that are defined in the directories configured on the firewall.

To access data on a user or group in order to display or edit it, select the user or group in the CN grid (left side of the screen): the relevant information appears in the column on the right.

Refer to the section Allowed names to find out which characters are allowed and prohibited in various fields.

Rule grid

This grid consists of one to three columns:

  • The CN column, displayed by default, which includes user and group names in identifier@directory format,
  • The DN column, hidden by default, which displays the Distinguished Name of the user or group (CN, OU, O and DC fields describe the user or group in its reference directory),
  • The TOTP column, hidden by default, which contains a green tick for each user authenticated by a TOTP (Time-based One Time Password ) method.

Details of a user

Account tab

ID (cannot be modified) Connection ID of the selected user.
Last name (cannot be modified) Last name of the selected user
First name (cannot be modified) First name of the selected user
E-mail address E-mail address of the selected user.
Phone number Telephone number of the selected user
Description Description of the selected user.
Create or update password By clicking on this link, you will be able to create the user’s authentication password in a specific window, which also displays the level of security.

NOTE
To allow users to change their own passwords, go to the Users module > Authentication > Captive portal profiles tab > Advanced properties section > User passwords.

TOTP

This section appears only when the selected user authenticated on the firewall with a TOTP.

TOTP code to be verified In this field, enter the TOTP used to connect to services on the firewall that use TOTP authentication to verify its validity.
Reset enrollment When you click on this button, the user’s TOTP enrollment will be reset: the next time this user connects to services on the firewall that use TOTP authentication, he or she will need to start the whole process of TOTP enrollment all over again.

NOTE
Users with administration privileges cannot be deleted from the TOTP database.

Certificate tab

This tab allows you to:

  • Display the user's x509 certificate when it exists and has been published in the LDAP directory,
  • Create the user's identity when it does not exist in the PKI,
  • Delete the user's certificate from the LDAP directory.

Since the PKI does not have a certification authority by default, you will need to create one in order to manage user’s certificates: go to the Objects module > Certificates and PKI > Add button > Add a root authority.

This certificate will be useful in two cases: SSL authentication and VPN access to the firewall with a mobile IPsec client. This certificate can also be used by other applications.

Member of these groups tab

This tab allows including the user in one or several groups:

  1. Click on Add.
    A new line will appear at the top of the table.
  2. Select the arrow to the right of the field.
    A drop-down menu will display the list of existing groups.
  3. Click on the desired group, and confirm your selection by clicking on Apply.
    The user is added to the table.

To remove a group, select it and click on Delete.

The maximum number is 50 groups per user.

Details of a group

Details

Name of the group (cannot be modified) Name of the selected group.
Description Description of the selected group.

The grid below the Details frame shows the users that belong to the selected group.

To add a user to the group:

  1. Click on Add.
    A new line will appear at the top of the table.
  2. Select the arrow to the right of the field.
    A drop-down menu displays the list of users found in the directory.
  3. Click on the desired user, and confirm your selection by clicking on Apply.
    The user is added to the table.
  4. Click on Apply to save the changes.

To remove a user from the group, select it and click on Delete.

Possible operations

Search bar

To search for a user or user group, enter all or part of the user's first name, last name and/or login: all users and/or user groups with names that contain the characters entered will be displayed.

EXAMPLE
If you type “a” in the search bar, the list below it will show all users and/or user groups with first names and/or last names containing an “a”.

Filter

This button allows you to select the type of CN to display. A drop-down menu offers the following choices:

Groups and users Represented by the icon , this option makes it possible to display users and user groups in the list.
Users This option is represented by the icon , which makes it possible to display only users in the list.
Groups This option is represented by the icon , which makes it possible to display only user groups in the list.

Directory filter

When several directories are configured on the firewall, this button filters the display of users and/or groups according to the directory selected.

Add user

  1. To create a user, click on Add a user, then select the relevant directory.
  2. Enter at least the user's ID and Last name, and assign a Password.
    To associate a certificate with this user, you will need to indicate a valid e-mail address.
    The following are the various fields that are available when creating a user:

Account

ID (login)

User’s login.

This field is mandatory.

Name

User name.

This field is mandatory.

First name User's first name.
Mail User’s e-mail address,
This will be useful for creating certificates for the user.
Phone number User’s telephone number
Description Description of the user

NOTE
The fields “ID”, “First name” and “Last name” cannot be modified after the user is created.

Authentication password

Password

Enter the user’s password.

This field is mandatory.

Confirm password

Enter the password again.

This field is mandatory.

Password strength A gauge indicating the robustness of the password will appear.
  1. Click on Next, then select any available groups in the reference directory that you wish to assign to the user.
  2. Click on Finish to confirm the creation of the user.

Add group

  1. To create a group, click on Add a group, then select the relevant directory.
  2. Enter at least the Group name.
    The following are the various fields that are available when creating a group:

Details

Group name

Give your group a name in order to identify it in the grid.

This field is mandatory.

NOTE
You will not be able to change the name of the group after you have created it.

Description You can provide a description of the group and modify the contents of the description whenever necessary.
This field is optional but you are advised to fill it in.

Members

Initial member

Select the first member to be added to the group.

This field is mandatory: new groups cannot be empty.

  1. Click on Create to confirm the creation of your user.

Deleting users or groups

Groups or users that do not have certificates issued by the firewall's PKI

  1. Select the user or group to be deleted.
  2. Click on Remove.
    A window will appear with the message “Delete the user <name of user>?“.
  3. Select Yes to proceed.

Users who have certificates issued by the firewall's PKI

  1. Select the user to remove.
  2. Click on Remove.
    A window will appear with the message “Delete the user <name of user>?“.
  3. Enter the CA passphrase (password of the authority that issued the certificate).
  4. Select the checkbox Export CRL after revocation if you wish to keep a copy of the CRL.
  5. In this case, select the File format of the CRL export:
    • Base64 format (PEM),
    • Binary format (DER).
  1. Click on Apply.
  2. If you have chosen to export the CRL, a window will open with a link to download the CRL export file.

Check usage

Represented by the icon , this button will show you which groups users belong to, as well as where the user or group is used in the rest of the configuration.

EXAMPLE
Filtering:
  1. Select the user or group for which you wish to check usage.
  2. Click on Check usage.
    The menu directory on the left will show you the user/group (via its ID) in the tab Users and groups, and displays the list of groups to which this user belongs, as well as its use in the configuration of the firewall.

Reset user’s TOTP enrollment

This button is enabled only when the selected user authenticated on the firewall with a TOTP.

When you click on this button, the user’s TOTP enrollment will be reset: the next time this user connects to services on the firewall that use TOTP authentication, he or she will need to start the whole process of TOTP enrollment all over again.

NOTE
Users with administration privileges cannot be deleted from the TOTP database.

Access privileges module

This shortcut makes it possible to display the user's access privileges directly in the Users > Access privileges module.

Interactive features

Some operations listed in the taskbar can be performed by right-clicking on the table of users/groups (CN table):

  • Deleting (the user or the selected group),
  • Checking usage (of the user or the selected group),
  • Resetting the selected user’s TOTP enrollment.