Active Directory Accelerator Guide

Active Directory Accelerator Guide

Import the Security Rules

Import the Security Rules

Import the predefined Active Directory accelerator security rules into the Management Console.
  1. Select the Management Console tree root node and click
    Tree
    Security Rule Set
    .
    The
    Add Rule Set
    window opens.
  2. Enter "LDAP Rule Set" as the rule set name and click
    OK
    .
    The LDAP Rule Set node appears in the Management Console tree.
  3. Select the LDAP Rule Set rule set and click
    Tree
    Security Rule Set
    .
    The
    Rule Editor
    opens.
  4. In the
    Rule Editor
    , click
    Action
    Import
    .
    The
    Import
    window opens.
  5. Navigate to the following directory:
    <Dynamic Data Masking installation>\Accelerators\ActiveDirectory\rules
  6. Select the LDAPRuleSet.xml file and click
    Import
    .
    The MatchTables rule folder appears in the
    Rule Editor
    .
  7. Expand the MatchTables rule folder to view the LDAPActualUser rule and the BlackList and WhiteList rule folders.
  8. Expand the BlackList folder to view the BlackList rules.
  9. Select the MaskIfLDAPMatch rule and click
    Action
    Edit
    .
    The
    Edit Rule
    window opens.
  10. In the class path field of the rule matcher, enter the file path to LDAP.jar.
    You can find LDAP.jar in the following location:
    <Dynamic Data Masking installation>\Accelerators\ActiveDirectory\lib\LDAP.jar
    You must enter the correct class path even if you disable the MaskIfLDAPMatch rule. The Rule Engine reads every rule in the rule set and returns an error if the class path is incorrect.
  11. Click
    OK
    .
    The
    Rule Editor
    closes.
  12. Expand the WhiteList folder to view the WhiteList rules.
  13. Select the StopIfLDAPMatch rule and click
    Action
    Edit
    .
    The
    Edit Rule
    window opens.
  14. In the class path field of the rule matcher, enter the file path to the LDAP.jar file.
    You can find the LDAP.jar file in the following location:
    <Dynamic Data Masking installation>\Accelerators\ActiveDirectory\lib\LDAP.jar
    You must enter the correct class path even if you disable the StopIfLDAPMatch rule. The Rule Engine reads every rule in the rule set and returns an error if the class path is incorrect.
  15. Click
    OK
    .
    The
    Rule Editor
    closes.
  16. Define tables with sensitive information in the MatchTables rule folder.
  17. Define LDAP users in the LDAPActualUser rule or disable the rule to mask data based on user groups or attributes you define in the BlackList and WhiteList rules.
  18. Define BlackList and WhiteList groups or attributes in the
    Rule Editor
    . Select a rule and click
    Action
    Edit
    to open the
    Edit Rule
    window.
  19. Click
    File
    Update Rules
    to save the security rules.
  20. Click
    File
    Exit
    to close the
    Rule Editor
    .

0 COMMENTS

We’d like to hear from you!