« Back to Product

Documentation

IPS_SetUserBindDN

 bool IPS_SetUserBindDN (string $User, string $BindDN) 

Parameters

User

Name of the user (case-sensitive)

BindDN

Distinguished name the user logs in with at the LDAP server

Returns

If the function succeeds, it returns TRUE, otherwise FALSE.

Description

The function sets the BindDN (distinguished name) of the user User. When an LDAP user (user type 1, USER_TYPE_LDAP) logs in, a bind with this BindDN and the entered password is performed against the LDAP server configured in the Permission Control. The LDAP synchronization of the Permission Control sets the BindDN automatically.

The value can be set for every user type, but it is only evaluated for LDAP users.

Warning

This function is only available for licenses that include the RBAC feature (Permission Control). Otherwise it fails with "This function is only available for licenses with the RBAC feature enabled!". If there are more users than the license allows (10 users by default, the @admin user is not counted), it fails with "Your license is currently limited to 10 users. Please consider upgrading the license to more users!" (the number is the limit of the license).

The currently logged in user (see IPS_GetLoggedInUser) must be an administrator, i.e. the @admin user or a user with the @admin role. Otherwise the function fails with "Administrator permissions are required for this action!".

If the user does not exist, the function fails with "User with name '…' does not exist". The @admin user cannot be modified; trying to do so fails with "User @admin cannot be modified!".

Example

IPS_CreateUser('max', USER_TYPE_LDAP);
IPS_SetUserBindDN('max', 'uid=max,cn=users,dc=symcon');
IPS_SetUserActive('max', true);
Any questions?