Results 1 to 6 of 6

Thread: Auto-povision accounts

  1. #1
    eng_ak is offline Junior Member
    Join Date
    May 2006
    Posts
    6
    Rep Power
    9

    Default Auto-provision accounts

    Hi,

    I just installed zimbra & integrated it with Fedora-Directory-Server (FDS). It works great. Only problem is, the part about having to provision an account *manually* after creating it in FDS!!
    I mean, the whole point of FDS is centralized management. I was wondering, why is it so difficult for Zimbra to 'auto-provision' an account if it authenticates successfuly over ldap! Other groupware suites has these features.
    Is there anyway (even if not staright-forward) to get this going?

    Thanks
    Last edited by eng_ak; 05-01-2006 at 08:56 AM.

  2. #2
    KevinH's Avatar
    KevinH is offline Expert Member
    Join Date
    Aug 2005
    Location
    San Mateo, CA
    Posts
    4,789
    Rep Power
    18

    Default

    What we've done with other LDAP deployments is just scripting a import from the other LDAP, then use a lastchanged or createdate and a cron job to auto-add new entries. zmprov command line tool makes this easy.

    The auto-provision is a good idea and is in bugzilla. You can vote for it here:

    http://bugzilla.zimbra.com/show_bug.cgi?id=7235
    Looking for new beta users -> Co-Founder of Acompli. Previously worked at Zimbra (and Yahoo! & VMware) since 2005.

  3. #3
    eng_ak is offline Junior Member
    Join Date
    May 2006
    Posts
    6
    Rep Power
    9

    Default Trying to script it

    Ok, thanks for the reply. I really wish this feature gets implemented.

    In the mean time, What would happen if I re-zmprov an account?? I'm just thinking about zmprov'ing all user accounts every 30 minutes (just to simplify my script, I have no idea what you mean about 'lastchanged' attributes)

    On the other hand, if you can post any sample cron-job script, it would be really helpful

    Thanks

  4. #4
    KevinH's Avatar
    KevinH is offline Expert Member
    Join Date
    Aug 2005
    Location
    San Mateo, CA
    Posts
    4,789
    Rep Power
    18

    Default

    I'd probably error. Almost all LDAP directories have the idea of last change or create date. So you can query with ldapsearch just for new accounts. Calling zmprov for accounts that already exists seems like a waste of resources.

    Don't have any scripts to post. They are written by our PS group for specfic Network customers. The basic idea is do an LDAP search for *new* accounts and zmprov them.
    Looking for new beta users -> Co-Founder of Acompli. Previously worked at Zimbra (and Yahoo! & VMware) since 2005.

  5. #5
    eng_ak is offline Junior Member
    Join Date
    May 2006
    Posts
    6
    Rep Power
    9

    Default Use FDS as primary directory?

    ok .. thanks for the prompt reply BTW You rock

    One last thing ... Would the cleanest solution be, to use my FDS as the main directory server for Zimbra as well?? (after I transfer all needed schemas ... etc)

    Would this work, and be recommended?

    Thanks again

  6. #6
    daniellawson is offline Intermediate Member
    Join Date
    Feb 2006
    Posts
    16
    Rep Power
    9

    Default

    One last thing ... Would the cleanest solution be, to use my FDS as the main directory server for Zimbra as well?? (after I transfer all needed schemas ... etc)

    Would this work, and be recommended?
    From what I've seen, this isn't the best way to do this. You can configure Zimbra to use an external GAL and external LDAP authentication, and point both of these at your FDS server.

    This is the cleanest approach, and works the best in terms of tying other systems in (eg, samba authentication via the same LDAP tree). Having tried it the other way, I wouldn't bother going ahead with it.

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. Multiple Mail Accounts, Folders
    By skwdenyer in forum Users
    Replies: 12
    Last Post: 12-01-2013, 08:52 PM
  2. Auto recieve pop accounts
    By mesbaba8 in forum Administrators
    Replies: 1
    Last Post: 06-07-2007, 08:53 AM
  3. zimbra 4.5RC2 pop accounts auto check???
    By nfear24 in forum Administrators
    Replies: 5
    Last Post: 01-30-2007, 01:25 PM
  4. Spam Accounts and Auto Training Error
    By Justin Rock in forum Administrators
    Replies: 2
    Last Post: 05-09-2006, 12:00 PM
  5. script auto create email accounts
    By raidip in forum Administrators
    Replies: 2
    Last Post: 09-29-2005, 11:46 AM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •