You are not logged in.

Announcement

 Téléchargez la dernière version stable de GLPI      -     Et vous, que pouvez vous faire pour le projet GLPI ? :  Contribuer
 Download last stable version of GLPI                      -     What can you do for GLPI ? :  Contribute

#1 2013-05-09 16:25:35

Lanberyuan
Member
Registered: 2013-05-09
Posts: 10

LDAP and Windows 2008 AD

I configure LDAP and filled out detail about field, and then the test is "Test successful (Main server : CNA)". But, I couldn't find/search user from AD when I want to be synchronization from Windows 2008 AD to GLPI users.

    There are 100 users in Windows 2008 AD, I won't add all (one by one) to GLPI; and I want user login GLPI use same password with Windows account's password.     May somebody help me?

Offline

#2 2013-05-09 17:00:27

Lanberyuan
Member
Registered: 2013-05-09
Posts: 10

Re: LDAP and Windows 2008 AD

Hi, I fixed it. thanks.

They are must like below:
BaseDN:DC=AAA,DC=com,DC=cn
rootDN: CN=glpi,CN=Users,DC=AAA,DC=com,DC=cn

If I only typed AAA.com.cn and glpi for both fields, the test is okay, but I still couldn't import uses from AD. Once I use correct string, they are okay.

Offline

#3 2013-05-10 10:30:57

joseluis.teixeira
Member
From: PT - GMR
Registered: 2013-05-07
Posts: 18

Re: LDAP and Windows 2008 AD

SETUP > Authentication > LDAP directories

Please verify that you have this on the Login Field.

Login Field : samaccountname

Active Directory Users and Computers
MyDomain.local
       |
       +---MyContainer
                      |
                      +------Users
                      +------Workstations
                      +------Printers

This will translate to:

BaseDN: OU=Users,OU=MyContainer,DC=MyDomain,DC=local

on the rootDN *IF* you don't allow anonymous binding you should put a admin user login as follows:

rootdn (for non anonymous binds) : MyDomain\administrator
Pass (for non-anonymous binds): ••••••••

Offline

#4 2013-05-10 16:36:22

samcro
Member
From: Munich, Bavaria, Germany
Registered: 2013-04-24
Posts: 216

Re: LDAP and Windows 2008 AD

thx jose,

my users are in different containers in my local domain, so that would translate in just the domain wouldnt it? i´m messing around with this for one week now and can´t seem to get it working...

MyDomain.local
          |
          +---MyContainer
          |                |
          |               +---OU (with users and PCs)
          |               +---OU (with users and PCs)
          |
          +---AnotherContainer
                           |
                           +---OU (with users and PCs)

i have to search for users in all containers so i defined my BaseDN like this: DC=MyDomain,DC=local
Test says succesful but "no users to import" when i search...

any advice will be appreciated!
thx in advance


GLPI 0.84.7 with FusionInventory on LAMP 14.04.1 LTS
~150 clients

Offline

#5 2013-05-10 18:04:11

joseluis.teixeira
Member
From: PT - GMR
Registered: 2013-05-07
Posts: 18

Re: LDAP and Windows 2008 AD

samcro wrote:

in all containers so i defined my BaseDN like this: DC=MyDomain,DC=local

You can setup 3 different LDAP directories: like follow

BaseDN: OU=OU1,OU=MyContainer,DC=MyDomain,DC=local
BaseDN: OU=OU2,OU=MyContainer,DC=MyDomain,DC=local
BaseDN: OU=OU1,OU=AnotherContainer,DC=MyDomain,DC=local

Don't forget to mark each:

Login Field : samaccountname
Active : yes


If you see just users from one particular OU, and not from others OU's then you can import the users directly from this link:
http://YourServer/glpi/front/ldap.import.php?action=show&mode=0&interface=expert

BaseDN: OU=OU1,OU=AnotherContainer,DC=MyDomain,DC=local
Search filter for users: (& (samaccountname=*) )

hit search


Hope that helps

Offline

#6 2013-05-13 10:06:30

Lanberyuan
Member
Registered: 2013-05-09
Posts: 10

Re: LDAP and Windows 2008 AD

Thanks for everyone, I fixed this.

Offline

#7 2013-05-13 11:17:32

samcro
Member
From: Munich, Bavaria, Germany
Registered: 2013-04-24
Posts: 216

Re: LDAP and Windows 2008 AD

thx again!!

problem was the marked filter:

asdf.jpg

this was mentioned in the official tutorial but seems to be wrong.
thanks for your help.


GLPI 0.84.7 with FusionInventory on LAMP 14.04.1 LTS
~150 clients

Offline

#8 2013-06-28 09:32:48

jargon
Member
Registered: 2013-06-28
Posts: 1

Re: LDAP and Windows 2008 AD

I'm having trouble with setting up AD authentication.
glpi: 0.83.91
Windows AD 2008

My options are different from the glpi ldap/ad documentation and from this thread. I don't know why.

Setup --> Authentication --> LDAP directories

Name:
ID:
Server:
Port:
Basedn:
Connection filter:
Default server:
Login field:
Surname:
First name:
Phone:
Phone 2:
Mobile phone:
Title:
Category(class):
Comments:
Email address 1:
Email address 2:
Email address 3:
Email address 4:
Use DN in the search:
Last update:
Select language:
User attribute containing it:
Filter to search in groups:
Group attribute containing it:
Search type:
Active:

That is all there is in my glpi 0.83.91. I see no RootDN anywhere.

Last edited by jargon (2013-06-28 09:36:56)

Offline

Board footer

Powered by FluxBB