Utilizing certificate-based authentication provides stronger security, easier authentication, and an improved user experience when compared to credential-based authentication β but only when it is supported by an efficient onboarding method. Integrating LDAP as your IDP with SecureW2βs certificate onboarding solutions allows users to provision their devices with certificates in only a few steps.
By connecting LDAP with effective certificate onboarding, your network can accurately distribute certificates to network users and ensure that no unapproved users can gain access. Since certificates from SecureW2 cannot be removed or transferred from the device, only those with valid LDAP credentials will be able to receive a certificate.
The following demonstrates the steps involved to configure the integration:
- Configure the Identity Provider
- Begin by configuring the attribute mapping of the IDP. Here you will customize the fields that are populated by the attributes of your network users and will be used to define different user groups within your network.
- Configure the Network Policies
- Nearly all organizations have different user groups that require varying levels of access to networks, servers, data, etc. By onboarding with SecureW2, you can automatically separate users into groups by configuring their attributes to identify and segment users. For example, a university would configure the onboarding software to segment users based on their status as a student or a professor.
NOTE:Β You will perform all of these procedures in the SecureW2 Management Portal.
Configure the Identity Provider
To configure the identity provider (IDP):
- From yourΒ SecureW2 Management Portal, go toΒ Identity ManagementΒ >Β Identity Providers
- ClickΒ Add Identity Provider
- ForΒ Name, enter a name
- Click theΒ TypeΒ dropdown and selectΒ LDAP
- ClickΒ Save
- Select theΒ ConnectionsΒ tab and clickΒ Add Connection
- ForΒ Name, enter a name
- ForΒ Hostname, enter β54.191.110.124β
- ForΒ Port, enter β389β
- ForΒ Admin DN, enter βsupport.securew2.comβ
- ForΒ Admin Password, enter the password
- ForΒ Subject Base DN, enter βDC=securew2,DC=netβ
- ForΒ Group Base DN, enter βDC=securew2,DC=netβ
- ForΒ Server timeout, enter β30β
- ClickΒ Test Connection
- After the connection is successfully tested, clickΒ Update
- Select theΒ BasicΒ tab
- ForΒ Subject Name Attribute, enter:
- βsAMAccountNameβ (users log in with only their username), orΒ βuserPrincipalNamesβ (users log in with their username and realm)
- ClickΒ Update
- Select theΒ Attribute MappingΒ tab and clickΒ Add
- ForΒ Local Attribute, enter βdisplayNameβ
- Click theΒ Remote AttributeΒ dropdown and selectΒ USER_DEFINED
- In the field that appears, enter βdisplayNameβ
- ClickΒ NextΒ ->Β Add
- ForΒ Local Attribute, enter βupnβ
- Click theΒ Remote AttributeΒ dropdown and selectΒ USER_DEFINED
- In the field that appears, enter βupnβ
- ClickΒ NextΒ ->Β Add
- ForΒ Local Attribute, enter βemailβ
- Click theΒ Remote AttributeΒ dropdown and selectΒ USER_DEFINED
- In the field that appears, enter βemailβ
- ClickΒ Next
- Select theΒ GroupsΒ tab and clickΒ Add
- ForΒ Local Group, enter a name
- ForΒ Remote Group, enter βCN=SECUREW2-STAFF,CN=Users,DC=securew2,DC=netβ
- NOTE: The value for Remote Group is case sensitive
- ClickΒ NextΒ ->Β Update
- To ensure that everything is working properly, select the Connections tab and test the connection again
Configure LDAP IDP Profile Policy
To configure the profile policy:
- From yourΒ SecureW2 Management Portal, go toΒ Policy ManagementΒ >Β Profile
- ClickΒ Add Profile Policy
- ForΒ Name, enter a name
- ClickΒ Save
- Select theΒ ConditionsΒ tab
- Click theΒ ProfileΒ dropdown and select the profile you created in the previous section
- Select theΒ SettingsΒ tab
- Click theΒ Identity ProviderΒ dropdown and select the IDP you created in the previous section
- ClickΒ Update
Configure LDAP IDP User Role Policy
To configure the user role policy:
- From yourΒ SecureW2 Management Portal, go toΒ Policy ManagementΒ >Β User Roles
- ClickΒ Add Role
- ForΒ Name, enter a name
- ClickΒ Save
- Select theΒ ConditionsΒ tab
- Click theΒ Identity ProviderΒ dropdown and select the IDP you created in the section βConfigure the Identity Providerβ
- ClickΒ Update
Configure the Enrollment Policy
To configure the enrollment policy:
- From yourΒ SecureW2 Management Portal, go toΒ Policy ManagementΒ >Β Enrollment
- ClickΒ Add Enrollment Policy
- ForΒ Name, enter a name
- ClickΒ Save
- Select theΒ ConditionsΒ tab
- In theΒ User RoleΒ list, select the user role you created in the previous section
- In theΒ Device Role list, selectΒ DEFAULT DEVICE ROLE POLICY 1
- ClickΒ Update
SecureW2 offers a cost-effective solution to streamline device onboarding and strengthen network security. Head over to ourΒ pricing pageΒ to learn more.

