sk183461 - How to configure the Management Server to use credentials when it sends queries to an LDAP Server
How to configure the Management Server to use credentials when it sends queries to an LDAP Server
Solution
Background
If it is necessary to configure security policy that is based on users that are configured on an LDAP server, you must configure an LDAP Account Unit object.
By default, the connection from the Management Server (from the LDAP Account Unit) to the LDAP Server (the Domain Controller) is performed anonymously, although you configure the credentials in the LDAP Account Unit object.
Check Point can provide a hotfix package for the Management Server, so it connects to the LDAP Server (the Domain Controller) with the credentials you configured in the LDAP Account Unit object.
WARNING - The Management Server does not encrypt the credentials it sends to the LDAP Server. To prevent a possible leak of the LDAP credentials, install this hotfix only if the communication is secured between the Management Server and the LDAP Server in your environment.
Procedure to Enable the New Behavior
- This problem was fixed. The fix is included in:
- Jumbo Hotfix Accumulator for R81.10 starting from Take 183
If you choose not to upgrade, Check Point can supply a Hotfix. Contact Check Point Support to get a Hotfix for this issue.
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.
For faster resolution and verification, please collect CPinfo files from the Security Management Server and Security Gateways involved in the case.
Hotfix installation instructions:
Refer to sk168597 - How to install a Hotfix.
- Enable the new behavior:
Note - On a Multi-Domain Security Management Server, this applies to all configured Domain Management Servers.
Connect to the command line on the Security Management Server / Multi-Domain Security Management Server.
Log in.
If your default shell is Gaia Clish, then go to the Expert mode:
expertTemporarily set the environment variable
FWM_ENABLE_LDAP_CREDENTIALSwith the value1(digit "one") in the current session:Temporarily set the environment variable:
$MDS_FWDIR/scripts/reload_env_vars.sh -e "FWM_ENABLE_LDAP_CREDENTIALS=1"
Make sure this environment variable was set:
`grep -a 'FWM_ENABLE_LDAP_CREDENTIALS' /proc/$(pidof 'fwm')/environ`Permanently set the environment variable
FWM_ENABLE_LDAP_CREDENTIALSwith the value1(digit "one"):Permanently set the environment variable:
$MDS_FWDIR/scripts/override_server_setting.sh -e FWM_ENABLE_LDAP_CREDENTIALS 1
When possible, restart the Check Point services: - On a Security Management Server:
cpstop ; sleep 5 ; cpstart
On a Multi-Domain Security Management Server:
`mdsstop ; sleep 5 ; mdsstart` 3. Make sure this environment variable was set: `grep -a 'FWM_ENABLE_LDAP_CREDENTIALS' /proc/$(pidof 'fwm')/environ`
Procedure to Disable the New Behavior
Connect to the command line on the Security Management Server / Multi-Domain Security Management Server.
Log in.
If your default shell is Gaia Clish, then go to the Expert mode:
expertUnset set the environment variable
FWM_ENABLE_LDAP_CREDENTIALS(see sk165938):$MDS_FWDIR/scripts/reload_env_vars.sh -u FWM_ENABLE_LDAP_CREDENTIALS
$MDS_FWDIR/scripts/override_server_setting.sh -u FWM_ENABLE_LDAP_CREDENTIALSWhen possible, restart the Check Point services:
On a Security Management Server:
cpstop ; sleep 5 ; cpstartOn a Multi-Domain Security Management Server:
mdsstop ; sleep 5 ; mdsstart
Make sure this environment variable is not set:
grep -a 'FWM_ENABLE_LDAP_CREDENTIALS' /proc/$(pidof 'fwm')/environ
You should just get a new shell prompt line.
NOTE
This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.