Ad Widget

Collapse

6.4.10 LDAP JIT provisioning does not work

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • Shaman0S
    Junior Member
    • Sep 2022
    • 11

    #1

    6.4.10 LDAP JIT provisioning does not work

    I was using 6.2.6 on production with BGmot patch. MS Active Directory as LDAP worked like a charm.

    Due to necessity I updated to 6.2.9 and then 6.4.10

    After update I set up JIT provisioning similar to what was set up in BGmot patch. This didn't work

    So I tried different settings for 'Group name attribute' (CN or cn), 'User group membership attribute' (memberOf or memberof), tried to create differently spelled ldap groups (no spaces, no underscores, no capital letters). Didn't work either.


    At the end of the day I set up fresh centos 9 + mysql + nginx + php-fpm host with 6.4.10 and made test setup as per https://blog.zabbix.com/just-in-time...ing-explained/

    Unfortunately this didn't work either. Upgraded to 6.4.11 - no luck.

    The most frustrating thing is when I press test button and try to test some login it authenticates and seems to detect group mapping OK.

    Has anyone succeeded to set up working JIT provisioning with 6.4.10 or 6.4.11?
    Appreciate your help in advance.​

    Click image for larger version

Name:	image.png
Views:	1279
Size:	63.9 KB
ID:	478208

    Click image for larger version

Name:	image.png
Views:	1041
Size:	159.5 KB
ID:	478209

    Click image for larger version

Name:	image.png
Views:	1037
Size:	136.9 KB
ID:	478210


    Last edited by Shaman0S; 02-02-2024, 00:04.
  • BGmot
    Junior Member
    • Aug 2017
    • 8

    #2
    Are you testing against my LDAP server container or your MS AD?
    What exactly happens when user3 tries to log in into WebUI?

    Comment

    • BGmot
      Junior Member
      • Aug 2017
      • 8

      #3
      Just tested with 6.4.11, works as expected.
      Make sure your default authentication method is set to LDAP, without that JIT does not work.
      Click image for larger version

Name:	image.png
Views:	1022
Size:	17.4 KB
ID:	478275

      Comment

      • Shaman0S
        Junior Member
        • Sep 2022
        • 11

        #4
        You nailed it! Thank you BGmot, it works with both test openldap and live MS AD.

        So in case someone bumps into the same problem, please ensure
        • Authentication tab, Default authentication set to LDAP
        • LDAP settings tab, Enable JIT provisioning checkbox is set.

        Comment

        • carlos.mcnulty
          Junior Member
          • Mar 2024
          • 1

          #5
          Hello, i have upgraded from 6.2 to 6.5 only to gain JIT but i have follow the youtube video from zabbix as well other guides and still won't get JIT provisioning.

          Iam able to test my user and others , the group is the correct in the AD (using LDAP on ms) , al the clicks on "use jit" are done.

          I hope someone can point me to the rigth direcction.

          Thank you.

          Carlos m
          Click image for larger version

Name:	zabbixjit.png
Views:	925
Size:	45.6 KB
ID:	481197
          Attached Files

          Comment

          Working...