• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

troubleshooting LDAP authentication

Scheduled Pinned Locked Moved OpenVPN
15 Posts 3 Posters 1.9k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • K
    KOM
    last edited by Jun 13, 2019, 3:10 PM

    Sorry, I don't have any other specific solutions as I don't use LDAP auth here.

    A 1 Reply Last reply Jun 13, 2019, 3:44 PM Reply Quote 0
    • M
      mcury
      last edited by mcury Jun 13, 2019, 3:14 PM Jun 13, 2019, 3:13 PM

      Try to set this at your smb.conf in your AD, at global parameters
      ldap server require strong auth = no

      then set a password without any special character

      dead on arrival, nowhere to be found.

      A 1 Reply Last reply Jun 13, 2019, 3:39 PM Reply Quote 0
      • A
        adamw @mcury
        last edited by Jun 13, 2019, 3:39 PM

        @mcury that didn't help

        1 Reply Last reply Reply Quote 1
        • A
          adamw @KOM
          last edited by Jun 13, 2019, 3:44 PM

          @KOM

          I'm also seeking help on Samba mailing lists and one of Samba guys has asked "It might also help if you can show how pfsense is trying to connect to AD."

          Can you provide some more details on what exactly happens to /system_authservers.php -> "Bind credentials" ?

          K 1 Reply Last reply Jun 13, 2019, 4:57 PM Reply Quote 1
          • K
            KOM @adamw
            last edited by Jun 13, 2019, 4:57 PM

            @adamw I'd love to help you but I'm not a coder and I have no idea how any of that works. I was just trying to help with references you might have missed.

            1 Reply Last reply Reply Quote 0
            • A
              adamw
              last edited by Jun 14, 2019, 12:14 PM

              I've solved my problem but can't post my (short) reply:

              ERROR
              Post content was flagged as spam by Akismet.com
              
              1 Reply Last reply Reply Quote 1
              • K
                KOM
                last edited by Jun 14, 2019, 1:35 PM

                I bumped your reputation by 1. Try again.

                1 Reply Last reply Reply Quote 0
                • A
                  adamw
                  last edited by Jun 14, 2019, 2:03 PM

                  The harder I try the fussier the antispam engine gets.
                  Now I can't even post 4 lines with a single code quote, no links or email addresses :(
                  Maybe I'll let it cool down a bit and try again on Monday.

                  1 Reply Last reply Reply Quote 1
                  • K
                    KOM
                    last edited by Jun 14, 2019, 2:07 PM

                    OK now you're at 5. I think I remember that 5 was the lucky number. Please try again.

                    1 Reply Last reply Reply Quote 0
                    • A
                      adamw
                      last edited by Jun 14, 2019, 2:17 PM

                      LDAP browser tool helped a bit and allowed me to see a more specific error:

                      [LDAP: error code 49 - 80090308: LdapErr: DSID-0C0903A9, comment: AcceptSecurityContext error, data 52e, v1db1]
                      

                      After a bit of research I've managed to connect using account@domain.co.uk format in "Bind credentials" username.

                      This might be worth adding to the pfSense-LDAP troubleshooting guide.

                      1 Reply Last reply Reply Quote 2
                      15 out of 15
                      • First post
                        15/15
                        Last post
                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                        This community forum collects and processes your personal information.
                        consent.not_received