• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

OpenLDAP for WebGUI authentication

Scheduled Pinned Locked Moved webGUI
3 Posts 2 Posters 3.2k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • P
    paklids
    last edited by Jul 5, 2013, 9:48 PM Jul 5, 2013, 9:44 PM

    I have not had any success so far using any of the recommendations using OpenLDAP.

    I can auth the OpenLDAP user but am unable to get a group listing for that user in Diagnostics->Authentication. Using a packetcapture I can see that OpenLDAP is replying with information about the user (but not the user's group information).

    1 Reply Last reply Reply Quote 0
    • D
      doktornotor Banned
      last edited by Jul 5, 2013, 9:49 PM

      I guess you misunderstood the feature. Did you create the exact same group you want to use for authentication on your pfSense box? You will not get anything out of it otherwise. The query only returns a group if you have a matching group set up locally (with assigned privileges as required.)

      1 Reply Last reply Reply Quote 0
      • P
        paklids
        last edited by Jul 5, 2013, 10:11 PM

        I did but it did not work at the time. Tried it again with some tweaks and it looks like it may work well enough for us to use.

        I'm working with our LDAP administrator and was able to determine that the "Group member attribute" must be an attribute that you add at the user level (an attribute that all the group members would share) and points to the group that they all belong to. A better description might be "User memberof attribute".

        1 Reply Last reply Reply Quote 0
        1 out of 3
        • First post
          1/3
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
          This community forum collects and processes your personal information.
          consent.not_received