3.3  Directory Service

Apart from the internal database of user accounts, Kerio Workspace can also import accounts and groups from a directory service. Active Directory (Windows Server) and Open Directory (Mac OS X Server) are currently supported.

Using LDAP, user accounts can be managed from one location. This reduces possible errors and simplifies administration.

Example: A new employee was introduced to the company. Check the following example:

  1. A new account has been created in the directory service.

  2. Map users to Kerio Workspace.

With the directory services, you can synchronize not only users but also groups.

Note

If you created local users while testing Kerio Workspace whose usernames are the same as their directory service accounts, you can switch the local users and their content to the directory service accounts.

Active Directory Settings

The directory service is enabled in the following dialog window:

Add new Active Directory

Figure 3.2. Add new Active Directory


  1. In the Directory Service dialog, check the Map user accounts from a directory service option and fill in the following data:

    • Directory Service Type — select the directory service type from the dropdown menu

    • Domain Name — enter the name of the domain

  2. Next, define the directory service sources:

    • Connect to directory servers looked up in DNS (SRV records) — DNS records are used to look up directory servers.

    • Use the specified directory servers — set the directory servers manually. Enter the Hostname of the computer for the primary and backup directory servers.

    You may use Encrypted connection (SSL) to connect to the directory service servers.

  3. In section Account with read access to the directory service, enter the username and password of an account in Active Directory. In Active Directory, assign this account read rights.

  4. Use the Test Connection button to test the connection.

  5. Click OK to confirm the settings.