Using an external LDAP data store
This section describes the process and options available to an BMC Atrium Single Sign-On administrator when using an external Lightweight Directory Access Protocol (LDAP) server to provide group and attribute values for authenticated users. Users and groups cannot be managed from the BMC Atrium Single Sign-On server because the LDAP server access is read-only.
Configuring an external data store is primarily needed when access to group membership information is required. The LDAP authentication module can be used to retrieve user attributes without configuring an external data store. For more information, see Using LDAP for authentication.
An external LDAP server is used to augment the information available to BMC products. For more information about the configuration options available with the LDAP data store, see the OpenSSO documentation.
The following topics provide instructions for using an external LDAP data store: