Ad Widget

Collapse

Zabbix & Ldap

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • doesntmatter
    Junior Member
    • Jun 2019
    • 13

    #1

    Zabbix & Ldap

    In the Logon of Zabbix 4 I can select a default-logon like on screenshot:
    Click image for larger version

Name:	zabbix.JPG
Views:	776
Size:	35.9 KB
ID:	430365


    I want to use both bethodes, some user from internal (if the dc maybe brokes) and as defaukt Ldap. If I change this to LDAP - can I use DB anymore with Zabbix 4?

    Attached Files
  • doesntmatter
    Junior Member
    • Jun 2019
    • 13

    #2
    Ok, i tried with my testing-environment. Do somebody knows how to enable internal-login if default set to LDAP? Only to have one local emergency login if AD breaks?

    Comment

    • cflannigan
      Junior Member
      • Aug 2021
      • 9

      #3
      Hey.
      Your user groups determine if it is to use LDAP or internal for logging in.. You will see the below dropdown when you are in one of the groups which will determine how members of that group authenticate or not if its set to disabled.

      Click image for larger version  Name:	zabbix-auth.PNG Views:	0 Size:	11.4 KB ID:	430374

      What i do is create an internal admin group for those emergency accounts like the NOC teams etc..

      Comment

      • doesntmatter
        Junior Member
        • Jun 2019
        • 13

        #4
        Originally posted by cflannigan
        Hey.
        Your user groups determine if it is to use LDAP or internal for logging in.. You will see the below dropdown when you are in one of the groups which will determine how members of that group authenticate or not if its set to disabled.

        Click image for larger version Name:	zabbix-auth.PNG Views:	0 Size:	11.4 KB ID:	430374

        What i do is create an internal admin group for those emergency accounts like the NOC teams etc..
        very cool. I checked only or Group Zabbix Administrators - there is no possibility for set this information.But for new groups its fine :-)
        Last edited by doesntmatter; 25-08-2021, 11:19.

        Comment

        • johndoe2374
          Member
          • Aug 2021
          • 80

          #5
          Hello.

          Zabbix Administrators group is using default system-wide access method, looks like you can't change it for that group.

          I do it the next way:

          1. Use internal method for default Zabbix Administrator account and maybe some other admins, as they should have access at any time without depending on AD.
          2. Create another group "LDAP Users" and set LDAP method for them.
          3. Create domain users using their logins and put them into LDAP Users group straightaway, so it would allow you create user without specifying password. Now they will be able to log in using their domain passwords.

          I don't think you will be able to allow the same user use internal authentication and LDAP at the same time. Even if it would be possible, there's no point in that, as you'll have to specify some password for internal authentication method anyway.

          Comment

          • doesntmatter
            Junior Member
            • Jun 2019
            • 13

            #6
            cflannigan

            Do you now how to login with a given Domaine?

            - $Username only => works fine
            - $Domain\$Username => Not working
            - $Username@$Domain.local => not working

            Comment

            • cflannigan
              Junior Member
              • Aug 2021
              • 9

              #7
              Hey
              There is no way to configure this unless you look at the PHP for the web component. As far as i know it looks for the samAccountName or userPrincipalName to authenticate against so you would have to use that for LDAP. Perhaps that could be a feature request where you can configure those parameters if there is not one already.

              Comment

              • doesntmatter
                Junior Member
                • Jun 2019
                • 13

                #8
                Originally posted by cflannigan
                Hey
                There is no way to configure this unless you look at the PHP for the web component. As far as i know it looks for the samAccountName or userPrincipalName to authenticate against so you would have to use that for LDAP. Perhaps that could be a feature request where you can configure those parameters if there is not one already.
                Than I think it's a bug because the samAccountName is outdated since a loooonnng time (pre win 2000)
                User naming attributes identify user objects, such as logon names and IDs used for security purposes.


                => Where can I create bug reports or feature requests?

                Comment

                • cflannigan
                  Junior Member
                  • Aug 2021
                  • 9

                  #9
                  Sorry looks like im mistaken you can use the Search attribute section to specify what field to search for for users, i guess for AD it advises to use the sAMAcccountName, but you can always try another filed that is used in your LDAP schema.. As for a bug go to support.zabbix.com and you can create and account and open a bug or feature request.
                  Search attribute LDAP account attribute used for search:
                  uid (for OpenLDAP),
                  sAMAccountName (for Microsoft Active Directory)



                  Comment

                  • doesntmatter
                    Junior Member
                    • Jun 2019
                    • 13

                    #10
                    Originally posted by cflannigan
                    Sorry looks like im mistaken you can use the Search attribute section to specify what field to search for for users, i guess for AD it advises to use the sAMAcccountName, but you can always try another filed that is used in your LDAP schema.. As for a bug go to support.zabbix.com and you can create and account and open a bug or feature request.
                    Search attribute LDAP account attribute used for search:
                    uid (for OpenLDAP),
                    sAMAccountName (for Microsoft Active Directory)


                    uid ist not working too, so you are right :-)

                    Comment

                    • license@testoil.com
                      Junior Member
                      • Aug 2021
                      • 2

                      #11
                      Just as an FYI UID is not usually completed in an Active Directory standard user account. Recommendation is the sAMAccountName.

                      Comment

                      Working...