Hi Mike,

I am sad ☹

That feature would be awesome for our installation. Would it be posible to do 
it changing the LDAP or the database extensions? Is this a feature that might 
be released in a far future?

Thanks for your help,
Pablo

De: Mike Jumper <[email protected]>
Enviado el: sábado, 18 de enero de 2020 5:14
Para: [email protected]
Asunto: Re: LDAP groups

On Fri, Jan 17, 2020 at 3:05 AM Pablo Uribe Bastero 
<[email protected]<mailto:[email protected]>> wrote:
Hi,

I have noticed a problem while syncing our LDAP and I don’t know if it is a 
misconfiguration or a Bug. I have been able to synchronize the user and groups 
from the Microsoft Active Directory, but the users that belong to a group it is 
not shown on Guacamole. Do you know what could it be?

It is neither misconfiguration nor a bug - the LDAP support does not expose 
group memberships in the same way that the database support exposes group 
memberships. A user's effective memberships are queried upon login for the sake 
of determining permissions but are otherwise not exposed.

In general, the details of various objects within the Guacamole admin interface 
are only displayed when those objects can be modified, which is not the case 
for Guacamole's read-only LDAP support.

- Mike

Reply via email to