Ad Widget

Collapse

LDAP auth with multiple Base DNs

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • CK1
    Junior Member
    • Jan 2012
    • 1

    #1

    LDAP auth with multiple Base DNs

    I have successfully configured LDAP authentication against one subdomain of our Win2003 active directory. Are there any plans to support LDAP authentication against multiple subdomains? Our AD has a root domain, i.e. "mydomain.com" and below that root domain multiple subdomains, i.e. "emea.mydomain.com", "apac.mydomain.com" and "ncsa.mydomain.com". I have tried to set "mydomain.com" as the Base DN, but that doesn't find any user account.
  • Zaniwoop
    Senior Member
    • Jan 2010
    • 232

    #2
    Hi, this can be done, as we have a similar setup.

    The trick is you need to use the Global Catalog. This basically entails using port 3268 as the LDAP port and you point your DN to root (mydomain.com).

    The only issue we have had is, if you have the same login name in two different subdomains, it will fail on that login.
    Attached Files

    Comment

    • NicoZanferrari
      Junior Member
      • Jun 2011
      • 23

      #3
      Thank you, Zaniwoop. I've added this useful info on the wiki page http://www.zabbix.com/wiki/howto/con...authentication

      Comment

      • marakshin
        Junior Member
        • Feb 2011
        • 27

        #4
        If in organization using a mail system with AD Integration (Such as MS Exchange), you may use e-mail adres for authenticate users in zabbix:
        Use a field "mail" instead of samaccountname, zabbix can authenticate users with same login names (e.g. [email protected] and [email protected]).
        As for me - it a solution.

        also we can use a field userPrincipalName (useful, if email addresses are not like domain names - e.g. [email protected] and [email protected])
        Last edited by marakshin; 12-10-2012, 04:38. Reason: add info about userPrincipalName

        Comment

        • Zaniwoop
          Senior Member
          • Jan 2010
          • 232

          #5
          great idea!

          Comment

          • tbennett
            Junior Member
            • Oct 2009
            • 4

            #6
            LDAP to W2008R2 GC

            When setting this up I get error:

            ldap_bind(): Unable to bind to server: Invalid credentials [include/classes/class.cldap.php:114]
            LDAP: cannot bind by given Bind DN

            Is there anything I need to configure on the Windows Server?

            Thanks,
            Terrance

            Originally posted by CK1
            I have successfully configured LDAP authentication against one subdomain of our Win2003 active directory. Are there any plans to support LDAP authentication against multiple subdomains? Our AD has a root domain, i.e. "mydomain.com" and below that root domain multiple subdomains, i.e. "emea.mydomain.com", "apac.mydomain.com" and "ncsa.mydomain.com". I have tried to set "mydomain.com" as the Base DN, but that doesn't find any user account.

            Comment

            Working...