Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Administrators

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 10-15-2008, 12:04 PM
Junior Member
 
Posts: 6
Default [SOLVED] External LDAP Authentication failover

I am using Zimbra 5.0.10 on Ubuntu 8.04 on Xen 3.2. I have External LDAP Authentication setup against another server in my domain and that is all working fine.

However, I would like to create some mailboxes (support, info, etc) that are shared mailboxes between multiple users. As a result, I would like to avoid creating these mailboxes as "users" in my LDAP store. I believe, from various sources and specifically from the LDAP Auth wiki page (LDAP Authentication - Zimbra :: Wiki towards the bottom), that I should be able to create the account in Zimbra and *assign* a password (for normal users I do not assign a password so that they are forced to use the LDAP password) and avoid the user creation in LDAP.

Problem is, I get authentication errors when I try to log in as the user. Upon review of the LDAP logs, I can clearly see that Zimbra is attempting to look up the user in LDAP which is, obviously, failing. Is there a way to convince Zimbra that users auth'ing against just Zimbra are legit?
Reply With Quote
  #2 (permalink)  
Old 10-15-2008, 12:31 PM
Moderator
 
Posts: 6,237
Default

Welcome to the forums,

su - zimbra
zmprov md domain.com zimbraAuthFallbackToLocal TRUE

Global & domain admin accounts automatically have fallback auth 'set' (both admin console and web-client) in-case your external LDAP/AD auth is unavailable or configured improperly.

If you have any accounts with passwords besides '' (null) & your external ldap auth is down they can use that password - you may want to set:
zmprov mc COSname zimbraFeatureChangePasswordEnabled FALSE
Reply With Quote
  #3 (permalink)  
Old 10-15-2008, 12:51 PM
Junior Member
 
Posts: 6
Default

Looks like I made a good guess on the name of the thread . Worked like a charm.

On the other aspect, I already do have "change pass" disabled, I am looking forward to seeing the write-through on passwords as are others elsewhere on the forums
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.