You are not logged in.

Announcement

 Téléchargez la dernière version stable de GLPI      -     Et vous, que pouvez vous faire pour le projet GLPI ? :  Contribuer
 Download last stable version of GLPI                      -     What can you do for GLPI ? :  Contribute

#1 2023-06-05 18:45:19

victorsina
Member
Registered: 2023-06-05
Posts: 2

Autentication integration with Active Directory on SAMBA LINUX SERVER

Hi All

First for all, thanks for this great software.

I have an issue regarding AD integration, but our AD is not running on windows, instead of that runs on a LINUX SAMBA server.
I follow the steps described in the howto, without succes.

This is the configuration

Untitled.jpg

And the AD UO configuration



But the test always fail.

Any help will be appreciated.

Thanks
Victor

Last edited by victorsina (2023-06-07 19:55:17)

Offline

#2 2023-06-06 12:05:59

Kaya84
Member
Registered: 2019-06-13
Posts: 217

Re: Autentication integration with Active Directory on SAMBA LINUX SERVER

First of all try with http://jxplorer.org/ if u can connect to LDAP.

Then check logfiles for error details.

Offline

#3 2023-06-06 20:04:32

victorsina
Member
Registered: 2023-06-05
Posts: 2

Re: Autentication integration with Active Directory on SAMBA LINUX SERVER

Hi Kaya84

Thanks for your time.
Ussing jxplorer show me that the ldap implemented into SAMBA have this configuration as default:

Default: ldap server require strong auth = yes

I modified to No and the glpi ldap integration connects and work.
But, Im courious regarding security implications on this parameter?
Is possible to use the options:

allow_sasl_over_tls or yes  with the glpi ldap integration?

I saw that is possible to download the tls certificate and use it into glpi.
I will try on that to secure the communication.

Thanks for all.

Regards
Victor

Offline

#4 2023-06-07 14:07:58

Kaya84
Member
Registered: 2019-06-13
Posts: 217

Re: Autentication integration with Active Directory on SAMBA LINUX SERVER

If Samba server and glpi server are on the same LAN my opinion is that there are no problems to worry about (u must be on the switch to make paket sniffing ).

Otherwise, u need to import the certificate and try something about it.

Offline

Board footer

Powered by FluxBB