Get a network trace of the LDAP calls and responses. Possibly it is an
apache issue, possibly the developer is a knucklehead. :)
 
--
O'Reilly Active Directory Third Edition -
http://www.joeware.net/win/ad3e.htm 
 
 

  _____  

From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] On Behalf Of Thommes, Michael M.
Sent: Friday, January 19, 2007 10:19 AM
To: ActiveDir@mail.activedir.org
Subject: [ActiveDir] OT: Apache LDAP authentication oddity



We have an application that is using an Apache server to do LDAP
authentications against our active directory.  (Yeah, I know; if only I were
king!  LOL!)  The application developer tells me that if he tries doing an
auth against our root base (dc=yyy,dc=zzz), the auth fails.  If he uses a
search base of "ou=xxx,dc=yyy,dc=zzz", the auth works.  The user account
that is being tested is some OU levels below this.  He is coding a subtree
scope and he is filtering on (objectclass=user and objectcategory=person).

 

It's like Apache needs to start at an OU structure.  I couldn't find much on
Google about this other than someone else was having the same issue last
Fall and just gave up in frustration.   The Apache documentation I could
find seemed to indicate that a search of "dc=yyy,dc=zzz" SHOULD work.

 

Any thoughts/pointers are appreciated!  Thanks!

 

Mike Thommes

Reply via email to