Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Sigbjorn
Advisor
Advisor

API for LDAP Account units

Are there plans to implement API calls for LDAP account units?

I'm hoping to automate updating the service account password used to authenticate to the domain controller in a AD Query setup.

 

Or is there an 'unsupported' way to do this with the generic-object api ?

0 Kudos
12 Replies
Timothy_Hall
Legend Legend
Legend

You can probably do this with dbedit, but I wouldn't recommend going that route.

In case you haven't seen it, LDAP/AU objects are listed in the following thread along with other operations that can't be performed through the Management API, and must instead be accomplished through the SmartConsole/SmartDashboard:

https://community.checkpoint.com/t5/API-CLI-Discussion-and-Samples/Functionality-API-vs-SmartConsole...

 

Gateway Performance Optimization R81.20 Course
now available at maxpowerfirewalls.com
0 Kudos
PhoneBoy
Admin
Admin

@Omer_Kleinstern any insights?

0 Kudos
Omer_Kleinstern
Employee
Employee

We do not currently support LDAP Account units in Management API, it is in the future plans.

Unfortunately, it is not possible to do via generic-object API.

0 Kudos
JozkoMrkvicka
Mentor
Mentor

May I guess? not supported even with R81 ?

Kind regards,
Jozko Mrkvicka
0 Kudos
PhoneBoy
Admin
Admin

It wasn't listed in the R81 EA notes at least.
0 Kudos
Sigbjorn
Advisor
Advisor

Thank you for the feedback.. We'll have to make a manual routine then.

0 Kudos
cezar_varlan1
Collaborator

I would make a movie of this process but it would hit the top 10 - how to waste time doing nothing useful charts. 

 

When you define de LDAP server you need to first have an object defined. Then the object is selected from a drop-down list with no filter/search (think of a customer that has 20000 objects defined) and how you can choose just the starting letter. If the starting letter is for example naming convention for location and it is an A, how many scrolls is that?

 

Try to do this with countless Smart Console jams and blocks with maybe 5 min waiting time.

Then think of the customer having multiple geographies and 30+ AD Servers to add.

 

This takes me roughly 2 days to complete and hope that the Smart Console does not go "Not Responding" permanently.

0 Kudos
cezar_varlan1
Collaborator

Do try this, then please escalate and solve it. I will post the recording in a few days, it will be fun.

 

0 Kudos
JozkoMrkvicka
Mentor
Mentor

I will name the relevant host object starting with "aaaaa", so it will be very first in the drop-down menu. Once selected and published, rename the "aaaaa" host object to your desired name based on naming convention.

Kind regards,
Jozko Mrkvicka
0 Kudos
(1)
pmo
Explorer

Hi Omer, 

>it is in the future plans

Any news about this?

Is it possible in R81.10 or R81.20 API to create LDAP Account Units?

0 Kudos
Timothy_Hall
Legend Legend
Legend

Doesn't appear possible in the latest R81.20/v1.9 API, see my post here:

Functionality - Mgmt API vs. SmartConsole - Revisited for R81.20/v1.9

Gateway Performance Optimization R81.20 Course
now available at maxpowerfirewalls.com
PhoneBoy
Admin
Admin

Not in R81.10 or R81.20.
I recommend engaging with your local Check Point office around this requirement.

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events