Ad Widget

Collapse

Zabbix configuration for AD LDAP authentication not working

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • cjbidwell
    Junior Member
    • Dec 2019
    • 16

    #1

    Zabbix configuration for AD LDAP authentication not working

    Hi all,

    I've been troubleshooting this for a long time trying to figure out why it's not working. I'm using RHEL8 with selinux enabled. I've set the associated setsebool parameters for zabbix. I don't get any errors relating to selinux. I've disabled it temporarily and retested and it still gives the same error.

    I've imported my active directory certificate and put into /etc/openldap/certs. Here is my ldap.conf:

    TLS_CACERTDIR /etc/openldap/certs
    TLS_REQCERT allow

    # Turning this off breaks GSSAPI used with krb5 when rdns = false
    SASL_NOCANON on

    Can anyone help me further troubleshoot this?

    What's interesting is that on my previous RHEL7 installation, it worked. ...and I thought I setup everything else exactly how
    I did on the RHEL7 instance. But I can't, for the life of me, figure out why this isn't working.

    Thanks!


    Click image for larger version

Name:	zabbix.png
Views:	4753
Size:	44.9 KB
ID:	414444
  • Hamardaban
    Senior Member
    Zabbix Certified SpecialistZabbix Certified Professional
    • May 2019
    • 2713

    #2
    I think you have a strange specified BaseDN
    Bind DN LDAP account for binding and searching over the LDAP server, examples:
    uid=ldap_search,ou=system (for OpenLDAP),
    CN=ldap_search,OU=user_group,DC=company,DC=com (for Microsoft Active Directory)
    Anonymous binding is also supported.

    Comment

    • cjbidwell
      Junior Member
      • Dec 2019
      • 16

      #3
      I don't believe it's that. Do you mean not having CN in my search? It's set the exact same way it was on my RHEL7 which did work.

      Comment

      • Hamardaban
        Senior Member
        Zabbix Certified SpecialistZabbix Certified Professional
        • May 2019
        • 2713

        #4
        Make sure that you have all the necessary packages installed. Look in the web server logs - are there any php errors?

        Comment

        Working...