Create User elements

The User element defines who your users are and how they can identify themselves to get access to networks and services as defined in your Engine Access rules.

You create Users as members of a User Group. You do not have to specify all user parameters separately for each individual User. A User that is a member of a User Group can inherit, for example, the Authentication Method and account expiration time from the User Group. Each User Group must belong to an LDAP Domain. We recommend creating a separate user account used for each user. Each user can belong to several User Groups within the LDAP Domain. User-specific properties can override properties defined at the User Group level.

You can import and export Users and User Groups through an LDIF file to or from some other Management Server.

Note: Although you cannot edit User Group memberships in the User element properties, each user can belong to several User Groups. After creating the User element, drag and drop it to other User Groups to add more group memberships.

For more details about the product and how to configure features, click Help or press F1.

Steps

  1. Select User Authentication.
  2. Browse to Users.
  3. Add a user to a User Group in one of the following ways:
    • Right-click a User Group and select New > Internal User (for the internal stonegate parent group).
    • Right-click a User Group and select New Internal User (for a User Group under the internal stonegate parent group).
  4. In the Name field, enter a unique name to identify the User in the directory.
    The name is used as the common name (CN) for the User. The distinguished name (DN) is inherited from the LDAP Domain to which the User belongs. The DN and CN in the internal LDAP database can be different from the DN in the user certificate when using certificate based authentication.
  5. (Optional) Change the Activation settings for the user account.
  6. Click the Authentication tab.
  7. Click Add to select the client certificate in Authentication Methods for the user.
  8. Enter the user identifier in the Subject, Alternative Name, or CN field.
    Note: When Distinguished Name is used, it must be entered in a specific format where the components are separated with a comma and exactly one space character, and there are no spaces around the equality signs. For example "DC=com, DC=example, CN=Lisa Smith". The OpenSSL x509 tool shows Distinguished Names in the desired format when using option "-nameopt utf8". For example, run "openssl x509 -text -nameopt utf8 -noout -in certificate.pem" and look for the Subject line in the output. When an IPv6 address from the Subject Alternative Name list is used, it must be entered in the short format and in lowercase, as described in Section 4 of RFC 5952. For example the IPv6 Address 2001:DB8:0:125:150:10:1:111 should be entered as 2001:db8::125:150:10:1:111.
  9. Click OK.

Result

The user account is created. If the user is stored in the internal LDAP database, the information is automatically synchronized to the local databases on the Firewalls unless user database replication has been disabled.