You are not logged in.

Announcement

 Téléchargez la dernière version stable de GLPI      -     Et vous, que pouvez vous faire pour le projet GLPI ? :  Contribuer
 Download last stable version of GLPI                      -     What can you do for GLPI ? :  Contribute

#1 2018-01-25 23:29:33

Guilherme.a
Member
Registered: 2018-01-25
Posts: 1

Authentication in multiple ADs / LDAP

I'm facing a small impasse and I wonder if anyone else has gone through this. In the company where I work GLPI implemented a little more than 6 months so I am new with the tool. The company already has a considerable size and for testing and evaluation we implemented only in our matrix, until then everything is OK, but now we will start to use in the branches, authentication is done through LDAP, that is where the problem comes from. Many users repeat themselves: "ATACADO-1" in more than one AD, the 1st "ATACADO-1" that logs in normally but if some "ATACADO-1" from another AD attempts to authenticate it of the "user or password "there is some other form of identification at the time of login for the system to recognize the domain, already tested ATACADO-1 @ domain, DOMAIN \ ATACADO-1 ... both to no avail. Has anyone ever experienced this??


Ps: sorry for my bad english xD

Offline

#2 2018-01-26 00:13:46

kurasul
Member
Registered: 2017-12-20
Posts: 162

Re: Authentication in multiple ADs / LDAP

hi guilerme
you need to implemant the SSO , so your glpi can automaticly find the right user with ldap connexion
regards


Kurasul // IT Manager  ============  https://discord.gg/qgDXNwS
OS + plugins: Ubuntu 16.04 // GLPI 9.2.1 // Php 7.0 // Sql + phpmyadmin // LDAP //
Fusion Inventory 9.2+1.0 //Cartographie 4.4.0 // Dashboard 1.4.0 // Gestion de baies 1.8.0 // Comptes 2.3.0 // Impression PDF
Imports fabricants 2.0.0 // Liste des taches 1.2.0 // Plus de rapports 1.4.0 // Arrêté du parc 2.4.0

Offline

#3 2018-01-31 10:06:52

mar1os
Member
Registered: 2013-11-26
Posts: 7

Re: Authentication in multiple ADs / LDAP

Use UPN instead of samaccountname, then user will have to log with full name (ATACADO-1@domain.name.com)
You can change it in Authentication -> Ldap directories -> login field (type in userprincipalname)

Offline

Board footer

Powered by FluxBB