Ad Widget

Collapse

Zabbix LDAP User and Groups

Collapse
This topic has been answered.
X
X
 
  • Time
  • Show
Clear All
new posts
  • Anynetsolution
    Junior Member
    • Apr 2016
    • 8

    #1

    Zabbix LDAP User and Groups

    Hello Community

    I have activated LDAP authentication in Zabbix.
    I have various questions.
    Does the user have to be registered locally on the Zabbix server so that Zabbix can access the LDAP user? Doesn't really make sense to me.

    I also wanted to create a group configuration and have made a group mapping.

    The "LDAP group pattern" is ZabbixAdmins
    There is also a group with this name on the LDAP system.
    Under User Groups I have defined "Zabbix administrator LDAP users", which has LDAP as frontend access.

    And the user role is "Super admin role"

    I have two test users. One who is a member of the group and one who is not. The problem is as follows

    Regardless of whether I add the additional user in LDAP to the group, on the one hand he does not get the role and on the other hand the user must be registered locally in Zabbix and be a member of the local group "Zabbix administrator LDAP users". That makes no sense.
    How do I have to configure the local user, if this is necessary, and how can I ensure that the LDAP system group also takes effect?

    If I create a user locally and add it to the local group "Zabbix administrator LDAP users" which has LDAP front-end access, then I can log in with the user from the LDAP source.

    Can someone give me an explanation on how to configure this correctly?
  • Answer selected by Anynetsolution at 14-12-2023, 12:10.
    cyber
    Senior Member
    Zabbix Certified SpecialistZabbix Certified Professional
    • Dec 2006
    • 4807



    If only LDAP sign-in is configured, then the user must also exist in Zabbix, however, its Zabbix password will not be used
    If you use JIT, then it does not have to be present...
    I do not use it myself, but I have strong feeling, that any of those group mappings will also work only in case of JIT. With just plain authentication, all you config is done inside Zabbix and just authentication is done through LDAP.

    Comment

    • cyber
      Senior Member
      Zabbix Certified SpecialistZabbix Certified Professional
      • Dec 2006
      • 4807

      #2


      If only LDAP sign-in is configured, then the user must also exist in Zabbix, however, its Zabbix password will not be used
      If you use JIT, then it does not have to be present...
      I do not use it myself, but I have strong feeling, that any of those group mappings will also work only in case of JIT. With just plain authentication, all you config is done inside Zabbix and just authentication is done through LDAP.

      Comment

      Working...