Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

More than one LDAP Server support #7087

Closed
loetmann opened this issue May 29, 2019 · 10 comments
Closed

More than one LDAP Server support #7087

loetmann opened this issue May 29, 2019 · 10 comments
Labels

Comments

@loetmann
Copy link

Describe the solution you'd like
I would like to see support for more than one LDAP server. Think for example of a school: We have one domain for the administrativ staff and one for the educational environment (classrooms, teachers, pupils etc.). They are running in two different isolated networks. While the sinpe-it users are located in the administrative domain, the persons behind asset-requests would ble in the edu-net.

Describe alternatives you've considered
AD Federation. But this is a mess having MS AD and Samba 4 AD domains :-(. Regarding the example above there are also heavy security concerns.

Additional context
An alternative would be support for SAML. ;-)

@stale
Copy link

stale bot commented Jul 28, 2019

Is this still relevant? We haven't heard from anyone in a bit. If so, please comment with any updates or additional detail.
This issue has been automatically marked as stale because it has not had recent activity. It will be closed if no further activity occurs. Don't take it personally, we just need to keep a handle on things. Thank you for your contributions!

@stale stale bot added the stale label Jul 28, 2019
@stale
Copy link

stale bot commented Aug 4, 2019

This issue has been automatically closed because it has not had recent activity. If you believe this is still an issue, please confirm that this issue is still happening in the most recent version of Snipe-IT and reply to this thread to re-open it.

@stale stale bot closed this as completed Aug 4, 2019
@6570
Copy link

6570 commented Sep 13, 2022

We have this issue as well; using LDAP to try to sync users but Google Workspace has our users split up by domain name (dc=example,dc=com; dc=example2,dc=com; dc=example3,dc=co) so we need a way to either specify multiple directories or multiple bases in order to move away from managing users manually

@6570
Copy link

6570 commented Sep 14, 2022

@snipe Would it be possible to have this issue reopened? #6685 seems to be for more for fallback/load-balancing whilst this would be multiple LDAP sources

@jessenoyes-cire
Copy link

I'd like to second having this issue reopened. Having multiple LDAP sources would save us a tonne of manual intervention, as we have 2 domains in our AD forest.

@OMFCP
Copy link

OMFCP commented May 16, 2023

Ran into a similar issue trying to get my child domains to sync via ldap. To get the users in my child domains to sync all I had to do was add the port for the ldap global catalog server connection 3268 to the end of my ldap server entry in the settings. I looked like ldap://server.domain:3268 and it immediately pulled in all users from all of my child domains.

@6570
Copy link

6570 commented May 16, 2023

@OMFCP Is that with Google Workspace?

@OMFCP
Copy link

OMFCP commented May 16, 2023

@OMFCP Is that with Google Workspace?

Sadly it is not. What I did find though is that if I set up my different child domains as "Companies" i could define the child domain path (dc=child,dc=parnent,dc=local) as the search OU path to correctly group my users. as far as having what appears to be 3 separate domains in Google Workspace from your earlier post (dc=example,dc=com; dc=example2,dc=com; dc=example3,dc=co), I'm not sure.

@OMFCP
Copy link

OMFCP commented May 16, 2023

@OMFCP Is that with Google Workspace?

Not sure if this would help but when adding a directory in your Directory Sync to sync Workspace with your On-Prem LDAP server you could try to point it to a Global Catalog, add the port 3268, and see if it changes how it shows up in your Google Workspace. It might add them as child domains instead of multiple "parent" domains.

@devinbaeten
Copy link

In our organization we have two domains, one for students and one for staff. Right now I have to manually sync students and staff separately. It would be much appreciated if we could have multiple LDAP configurations at once.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

5 participants