Navigation

    Netgate Discussion Forum
    • Register
    • Login
    • Search
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search

    User Assigned Privileges Question

    General pfSense Questions
    2
    2
    548
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • R
      rharris last edited by

      Hello All,

      I'm a noob to the forums and pfsense in general so I apologize if this is a stupid question. I've researched and can't seem to find a solution. I've created two active directory groups (Admin and Read-only). I'm using LDAP to connect back to the AD server. I can login just fine with my domain credentials. Now I want to setup privileges. Full admin rights work just fine. However User - Config - Deny Config Write does not work for active directory users.

      Right now the assigned privileges for the read-only group are "User - Config - Deny Config Write" and "WebCfg - All pages". I created a local user and assigned these same privileges and it worked as intended (the account could not save changes). However it just doesn't work for active directory accounts. I also verified that the account is a member of the read-only group. Does anyone have any ideas?

      1 Reply Last reply Reply Quote 0
      • jimp
        jimp Rebel Alliance Developer Netgate last edited by

        Are you certain the user is being put into the correct group?

        I can't think of any reason why that privilege wouldn't work from LDAP unless the user wasn't actually being detected as a member of the group that included the privilege.

        Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

        Need help fast? Netgate Global Support!

        Do not Chat/PM for help!

        1 Reply Last reply Reply Quote 0
        • First post
          Last post