ldap_integration
Differences
This shows you the differences between two versions of the page.
Both sides previous revisionPrevious revisionNext revision | Previous revisionNext revisionBoth sides next revision | ||
ldap_integration [2009/08/20 08:34] – 172.26.0.166 | ldap_integration [2009/08/20 09:23] – 172.26.0.166 | ||
---|---|---|---|
Line 3: | Line 3: | ||
ILRI uses an Active Directory server for user authentication, | ILRI uses an Active Directory server for user authentication, | ||
+ | ===== Notes ===== | ||
+ | Try to search from a Linux machine which can talk to the AD server (HPC is behind firewall): | ||
< | < | ||
Enter LDAP Password: | Enter LDAP Password: | ||
ldap_bind: Invalid credentials (49) | ldap_bind: Invalid credentials (49) | ||
additional info: 80090308: LdapErr: DSID-0C090334, | additional info: 80090308: LdapErr: DSID-0C090334, | ||
- | According to the web this error means the user does not exist. | + | According to the web this error means the user does not exist. |
- | + | <file>HEX: 0×525 – user not found | |
- | <code>HEX: 0×525 – user not found | + | |
DEC: 1317 – ERROR_NO_SUCH_USER (The specified account does not exist.) | DEC: 1317 – ERROR_NO_SUCH_USER (The specified account does not exist.) | ||
- | NOTE: Returns when username is invalid.</ | + | NOTE: Returns when username is invalid.</ |
- | + | A note of possible interest regarding binding on Linux (from the [[http:// | |
- | ==== pam_cgiar_ldap.c ==== | + | < |
+ | only accept binds on that port. You cannot bind as a user on port 389. I | ||
+ | don't think they support TLS on port 389, but I have no tried in a long | ||
+ | time.</ | ||
+ | ===== pam_cgiar_ldap.c ===== | ||
+ | Someone hacked up a PAM module several years ago which could be dropped into a Linux server and allow AD authentication with minimal configuration. | ||
<note warning> | <note warning> | ||
This was working once, using a // | This was working once, using a // | ||
* Compile the code: '' | * Compile the code: '' | ||
- | * Link the code: '' | + | * Link the code: '' |
**pam_cgiar_ldap.c**: | **pam_cgiar_ldap.c**: |
ldap_integration.txt · Last modified: 2012/02/06 08:43 by aorth