Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Administrators

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 01-11-2008, 07:39 AM
Intermediate Member
 
Posts: 17
Default Restricting LDAP permissions

I want to enable people to use LDAP to access their contacts from mail clients.
I would prefer if this information were not made public though... so I want to require authentication.

But Zimbra seems to use LDAP internally without authentication, and adding "require authc" to slapd.conf seems to stop mail sending etc from working

LDAP Security ? suggests blocking access to LDAP with the firewall but then people can't use it externally at all

Is there any way to configure openldap to do this or should I be filing something in bugzilla?
Reply With Quote
  #2 (permalink)  
Old 01-11-2008, 11:32 PM
Zimbra Employee
 
Posts: 580
Default

A bug for this already exists:

Bug 15378 - Obviate the need for and disallow LDAP anonymous binds

It is not currently resolved. You can with 5.0.0 and up work on disabling anonymous access to most things by manually customizing the ACLs. I think what you are really trying to do is also tied in with:

Bug 16601 - Secure Access To LDAP

So you have secure connections without anonymous binds.
__________________
Quanah Gibson-Mount
Sr. Member of Technical Staff
Zimbra, Inc
A Division of VMware, Inc.
--------------------
Zimbra :: the leader in open source messaging and collaboration
Reply With Quote
  #3 (permalink)  
Old 02-06-2008, 11:26 PM
Intermediate Member
 
Posts: 17
Default Thanks

Yay, voted for the bugs and waiting for the switch to make it into the 5.0 series - will be much easier than trying to patch all the LDAP config myself. Thanks for the feedback...
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.