/build/static/layout/Breadcrumb_cap_w.png

K1000: LDAP Filter Issues

Trying to get LDAP setup on my K1000.  While all my strings are working find in LDAP browsers, when I run a test connection I keep getting the following error:

Testing "" connection to:  on Port: 

OK Connection Successful.

OK Setting Protocol Version 3 Successful.

OK Setting LDAP REFERRALS Option 0 Successful.

Error Anonymous Search Bind using LDAP supplied credentials Failed.

Error LDAP Test Failed. Closing connection.

 

I have the following setup:

The Search Base is as follows:

OU=IT,OU=CorpOU,DC=AD,DC=ACME,DC=com

 

The Search Filter is as follows:

(&(memberof=CN=Kace Admins Security Group,OU=IT,OU=CorpOU,DC=AD,DC=ACME,DC=com)(sAMAccountName=KBOX_USER))

 

The LDAP browser returns a username if I replace the KBOX_USER, which tells me the query should be right.  But when I replace the KBOX_USER and hit Test LDAP Connection in the LDAP server setup I get an error.  If I remove the group reference and just do sAMAccountName=KBOX_USER then the test is successful.  There is clearly a syntax issue with my filter (or a system bug) and for the life of me, I just can't find it.

 

Please help.


1 Comment   [ + ] Show comment
  • I originally posted this: (Edit at bottom)

    So this is just one of those silly things.

    When you run a test, you must have samaccountname=KBOX_USER. HOWEVER: When running the live LDAP, you need to replace it with Samaccountname=*.

    Why? Just the way it works. Anyhow: Give that a shot.

    HOWEVER: When looking at my Ldap imports, it is the opposite. When you test you use *, when you go live you use KBOX_USER
    Maybe that helps?? - Wildwolfay 10 years ago

Answers (1)

Posted by: raul102801 9 years ago
Orange Senior Belt
-1

Are you sure of this? I am having the same issue and if I understand correctly, for a production environment samaccountname=KBOX_USER (it will not let you apply without a KBOX_USER there) you would substitute that with the username you want to test and then enter the password for that user next to the Test LDAP Settings button. Is that not correct? I still can't get it to work but I know it will not let me save it with an * instead of KBOX_USER for samaccountname

Don't be a Stranger!

Sign up today to participate, stay informed, earn points and establish a reputation for yourself!

Sign up! or login

Share

 
This website uses cookies. By continuing to use this site and/or clicking the "Accept" button you are providing consent Quest Software and its affiliates do NOT sell the Personal Data you provide to us either when you register on our websites or when you do business with us. For more information about our Privacy Policy and our data protection efforts, please visit GDPR-HQ