Results 1 to 10 of 10

Thread: External LDAP - auto Account creation

  1. #1
    nepenthe is offline New Member
    Join Date
    Jan 2006
    Posts
    3
    Rep Power
    9

    Default External LDAP - auto Account creation

    Hi Guys,

    I've just set up the GA release on a FC4 and everything is running fine.

    It's looking really great! However.. ..

    I have authentication via External LDAP to our site-wide LDAP servers.

    Whilst the external ldap authentication works fine, it requires me to add each account to Zimbra by hand. Is this correct functionality?

    e.g. We have ~1200 users in our LDAP, do I need to add each of these accounts one at a time? Ideally Zimbra would read off our internal LDAP servers dynamically, i.e. if we add a new account to our internal LDAP servers, the user will automatically get a mail account in Zimbra. I have seen the batch-provisioning command (zmprov) which uses a text file of usernames, but this would only work at the initial setup stage. After that, we would still need to keep our internal LDAP servers and the Zimbra accounts in sync manually.

    Am i going about this the wrong way?

    At this point I haven't added the Zimbra LDAP schema to our site-wide schema, but can do so if that is required.

    Any instruction on how to make this setup work would be great. I've looked thru the doco and forums but can't find anything relevant.

    Cheers

    J

  2. #2
    marcmac is offline Expert Member
    Join Date
    Sep 2005
    Posts
    2,103
    Rep Power
    13

    Default

    we don't currently support provisioning of the type you've described. If you want to avoid creating all the accounts by hand via the UI, you can write a simple script to dump your account db and use zmprov to create the accounts in zimbra.

  3. #3
    croffler is offline Member
    Join Date
    Oct 2006
    Posts
    12
    Rep Power
    8

    Default

    I have the same issue ! Are there any plans to suppor this auto creation of users ?

    Chris

  4. #4
    fmodola is offline Special Member
    Join Date
    Feb 2006
    Location
    France (Haute-Savoie)
    Posts
    123
    Rep Power
    9

    Default

    I'm not developer, but I think that a Perl script (that finds out informations about accounts in a branch of the LDAP tree source) can do the trick.

    The input arguments would be the source DN, and the most useful would be that the script runs every day in order to sync the modifications on the source LDAP tree (if your accounts' source is an LDAP tree).

    I think it would be great too if this script could search through any LDAP tree (MS Active Directory, Novell eDirectory, OpenLDAP, etc ...).

    Is there a developer ready to write that script ???

  5. #5
    croffler is offline Member
    Join Date
    Oct 2006
    Posts
    12
    Rep Power
    8

    Default

    It would be nice if this could run in an automated mode. For example, the authentication is done via LDAP, if the user exists in LDAP, zimbra checks if the user exist in Zimbra, if not it will automatically create the user in Zimbra.

    I am using OTRS www.otrs.org, they do exactly that. It is writen in perl and you can map all attributes in ldap to there internal attributes.

    Chris

  6. #6
    phoenix is online now Zimbra Consultant & Moderator
    Join Date
    Sep 2005
    Location
    Vannes, France
    Posts
    23,499
    Rep Power
    56

    Default

    Quote Originally Posted by spacegoose View Post
    I'm using external LDAP auth, and would like it if Zimbra auto-created the zimbra mailbox if the external LDAP auth is successful and the acct doesn't already exist in zimbra.
    There's already a request in bugzilla for this feature, search and vote.

    Quote Originally Posted by spacegoose View Post
    Would also like a script that would auto-create the accounts from a dump of my external LDAP - but this would be less ideal than the above automatic solution.
    Check in bugzilla if there's already an RFE, if not file one and vote on it.
    Last edited by phoenix; 08-12-2008 at 12:25 PM.
    Regards


    Bill


    Acompli: A new adventure for Co-Founder KevinH.

  7. #7
    spacegoose is offline Member
    Join Date
    Feb 2008
    Posts
    14
    Rep Power
    7

    Thumbs up I would like this too!

    I'm using external LDAP auth, and would like it if Zimbra auto-created the zimbra mailbox if the external LDAP auth is successful and the acct doesn't already exist in zimbra.

    Would also like a script that would auto-create the accounts from a dump of my external LDAP - but this would be less ideal than the above automatic solution.

    Thanks,
    s g

  8. #8
    r0b0t is offline Starter Member
    Join Date
    Jul 2008
    Posts
    2
    Rep Power
    7

    Default

    We need to the same thing plus more. Our organization environment is dynamic and users will get different COS depending on certain attributes. This is not just during account creation but is ongoing. to make matters worst it doesn't look like openLdap has any kind of changelog to figure out what changed/created/deleted.

  9. #9
    bdial's Avatar
    bdial is offline Moderator
    Join Date
    Jul 2007
    Location
    Baltimore
    Posts
    1,649
    Rep Power
    11

    Default

    You'd want something like Novell's Identity Manager.

  10. #10
    aporto is offline Starter Member
    Join Date
    Aug 2008
    Posts
    1
    Rep Power
    6

    Default OpenLDAP + Samba + Zimbra

    Hi,
    I have an environment with Samba and OpenLDAP and would like to integrate to Zimbra.
    Now I'm searching docs or script that make that. Use script with cron for temporary solution is ok, but with exist inside Zimbra should be better.

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. Zimbra Install Problem - getDirectContext
    By bsimzer in forum Installation
    Replies: 27
    Last Post: 07-19-2007, 10:12 AM
  2. 3 testing: LDAP: 389 Failed when restore zimbra
    By victorLeong in forum Administrators
    Replies: 15
    Last Post: 05-24-2007, 06:45 AM
  3. External LDAP Problem
    By facerw in forum Installation
    Replies: 7
    Last Post: 05-08-2007, 04:29 AM
  4. Authentication to external ldap stop working.
    By jahaj in forum Installation
    Replies: 3
    Last Post: 12-05-2006, 03:17 PM
  5. LDAP External Auth Fedora Directory Services
    By prpatrol in forum Administrators
    Replies: 3
    Last Post: 08-14-2006, 06:00 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •