An LDAP authentication profile tells the event broker service how to reach an LDAP directory and how to search it: the LDAP servers to contact, the credentials to bind with, and the searches that resolve a user and their group membership.
Two profile names have a fixed meaning on the event broker service. The default profile authenticates clients and cannot be deleted. The management profile authenticates management users when an LDAP management access configuration exists, and cannot be deleted while one does. A profile with any other name is stored and applied to the event broker service, but nothing on the event broker service binds to it, so it has no effect until a future API binds it.
The API updates only the fields included in the request. The name of a profile cannot be changed. Each LDAP server is a separate field: including ldapServerOne, ldapServerTwo or ldapServerThree replaces the server in that position, and omitting one leaves that position unchanged. A position cannot be emptied once it is set.
Omitting adminPassword keeps the stored password. It cannot be cleared, because the profile cannot bind to the LDAP directory without one.
Your token must have one of the permissions listed in the Token Permissions.
Token Permissions: [
mission_control:access or services:put ]| Time | Status | User Agent | |
|---|---|---|---|
Retrieving recent requests… | |||
