-
Notifications
You must be signed in to change notification settings - Fork 468
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
LDAP credentials invalid #1011
Comments
The module does not provide LDAP connection logs. "Credentials invalid" error is the sign of incorrect "Bind DN" or "Bind Username". Admin user must be located in "Bind DN" and must have "inetOrgPerson" object class. |
Just to correct @freescout-helpdesk, there is no requirement on object class to be able to bind. You can use a SimpleSecurityObject (DSA), a regular account with elevated permissions (administrator like). You'll need to provide some details like your LDAP backend, and some information on what your bind DN / username is. If you have access to the LDAP server as well you should be able to see what is being queried and what is wrong. |
Right, |
Is it a requirement that the user be at the same level as the "Bind DN" or can be at an OU lower than the Bind DN. I'm using the exact same username and password on the same server when performing a query via either ldapsearch via the command line or trying to get the schema information via the plug in. The username is being accepted via ldapsearch and returning data. However, I get invalid credentials when trying via the plugin. On the AD server I'm not getting a corresponding Audit failure credential validation. I do get a credential validation failure on the AD with ldapsearch if I put in the incorrect password in the command line. |
The admin user must be at the same level as the "Bind DN". |
OK, I moved the user to the bind dn and I'm still getting invalid credentials for the module but it is still working for the ldapsearch from the command line. I'm still not seeing the request at the AD with a failed login attempt. Interestingly if I connect to the test LDAP from the documentation https://www.forumsys.com/tutorials/integration-how-to/ldap/online-ldap-test-server/ I can connect to that. As we are using Active Directory with several LDAP security measures in place, ie., LDAP server signing requirements, LDAP server channel bindings etc in group policy, could these be getting in the way. |
Everything is possible. Have you managed to solve the issue? |
No I haven't been able to locate the issue. I currently don't have the time to try and track the issue. |
Hi, I just battled with this myself. I read the documentation, but it wasn't clear to me. I finally realized that the So take the full DN (for example):
and put everything after the I re-read the extension instructions, and they were not clear to me. But it's working now! |
I having issues with LDAP returning credentials invalid with the LDAP module. I need the ability to look at the logs but they are not there for the LDAP module. Where are they located so I can see why it is returning this error. When connecting with ldapsearch with the same credential set I'm able to list the user base from the AD both with no encryption and TLS/SSL so the issue seems to be with freescout.
The text was updated successfully, but these errors were encountered: