Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Administrators

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 03-31-2009, 02:32 AM
Member
 
Posts: 10
Default Zimbra internal and external LDAP authorization

Hi folks!
This is my first thread about zimbra.
My situation: I created Samba + OpenLDAP domain - everything works! Log in domain works, can change password from windows and all the usual NT4 domain features works. Than there is one more samba file server, that authorizes to this External LDAP! Everything's cool, but! My pain is Zimbra server (on DMZ port) that authorizes internally. Right now i would like to change this Zimbra authorization to this External LDAP and there is an option to configure it in admin console, so no problem, but... will Zimbra work on selected domain using External LDAP and internal authorization at the same time? I ask this thing because i have to migrate ~50 users from local authorization to domain and it is going to take more than a couple of hours, but people need their e-mail an stuff. Maybe I'm thinking wrong and someone has other ideas how to manage this trick?
Sorry for my poor English!
Regards,
Martins
P.S.Zimbra Version 5.0.11_GA_2695.SLES10_64.FOSS Nov 17, 2008
Reply With Quote
  #2 (permalink)  
Old 03-31-2009, 03:57 AM
Zimbra Consultant & Moderator
 
Posts: 19,655
Default

Welcome to the forums.

Normally Zimbra will only use one server for authentication unless you have the following set:

Code:
su - zimbra
zmprov md domain.com zimbraAuthFallbackToLocal TRUE
That will allow you to migrate users to your external LDAP as you need. Do note that currently there is no synchronisation between external and internal authentication mechanisms (there is an RFE in bugzilla for it for passwords. It will also mean that if your external LDAP is unavailable your users will still be able to login to their email.
__________________
Regards


Bill

Last edited by phoenix; 10-06-2009 at 07:47 AM..
Reply With Quote
  #3 (permalink)  
Old 03-31-2009, 04:17 AM
Member
 
Posts: 10
Default

Thanks for quick response!
One more missunderstanding i have: as far as i understand this option u mentioned will allow to login into e-mail accounts using both - LDAP and internal authozitation methods at the same time, right? If i migrate authorization to external LDAP to users, than how i gonna be able to link that user1@mydomain.com authorized internally right now is the same user1@mydomain.com with same IMAP box, but right now authorized to external LDAP?!
Sorry, if it is too stupid question , but i didn't find this information in none of the topics and i really need to be sure about all the topics i'm interested in before i start to migrate.
Reply With Quote
  #4 (permalink)  
Old 03-31-2009, 04:33 AM
Zimbra Consultant & Moderator
 
Posts: 19,655
Default

No, that's not quite how the authentication works. You can only authenticate against the internal LDAP or an external LDAP, the option I've given you will allow you to use an external LDAP and if the user doesn't exist there (or the external becomes unavailable for some reason) then it will 'fallback' to using the internal LDAP for authentication. If you want to migrate your users to an external LDAP then you will have to create the user in that LDAP, is that what you were asking and have I understood your question correctly?
__________________
Regards


Bill
Reply With Quote
  #5 (permalink)  
Old 03-31-2009, 04:46 AM
Member
 
Posts: 10
Default

Ok, about an option (zmprov md domain.com zimbraAuthFallbackToLocal TRUE) u mentioned i understood.
About migration - i have made all users in my external LDAP and i have zimbra internal LDAP. On the supposition that i added zimbra to external LDAP, how can i tell zimbra that user1@mydomain.com in internal LDAP with all mailbox is the same as user user1@mydomain.com in external LDAP? How will it recognise users with their mailboxes?
Reply With Quote
  #6 (permalink)  
Old 03-31-2009, 05:00 AM
Zimbra Consultant & Moderator
 
Posts: 19,655
Default

If you create user1@mydomain.com with a password and point the Zimbra Authentication (in the Admin UI) at that external LDAP server they will be able to access their email - the user will also need to be provisioned in Zimbra as user1@mydomain.com. Does that answer your question?
__________________
Regards


Bill
Reply With Quote
  #7 (permalink)  
Old 03-31-2009, 07:25 AM
Member
 
Posts: 10
Default

Quote:
Originally Posted by phoenix View Post
If you create user1@mydomain.com with a password and point the Zimbra Authentication (in the Admin UI) at that external LDAP server they will be able to access their email - the user will also need to be provisioned in Zimbra as user1@mydomain.com. Does that answer your question?
Actually it doesnt (or i just don't understand)! I will try to explain what i need:
External LDAP - already works, domain users created as well! Domain username is just surname (Domain\Surname).
Internal Zimbra LDAP - e-mail users, created as name.surname@mydomain.lv (picture in attachment)
If i point authorization to External LDAP, should i make External LDAP user (Domain\name.surname) the same as zimbra internal LDAP (name.surname)?
Attached Images
File Type: png scsh_2009-03-31_15-34-54.png (1.7 KB, 251 views)
Reply With Quote
  #8 (permalink)  
Old 03-31-2009, 07:37 AM
Zimbra Consultant & Moderator
 
Posts: 19,655
Default

Quote:
Originally Posted by snpz View Post
If i point authorization to External LDAP, should i make External LDAP user (Domain\name.surname) the same as zimbra internal LDAP (name.surname)?
Yes, you should. I thought that's what I had said in my previous reply - the username & domain name for logging in must be the same in your external LDAP and your internal LDAP.
__________________
Regards


Bill

Last edited by phoenix; 03-31-2009 at 09:25 AM..
Reply With Quote
  #9 (permalink)  
Old 03-31-2009, 07:56 AM
Member
 
Posts: 10
Default

Hehehe! My misunderstanding than! Sorry!
Ok, tomorrow I will modify some test users, make some FW rules and try to add zimbra to this External LDAP. I will report about success
Thanks for your advice and patience
Reply With Quote
  #10 (permalink)  
Old 10-06-2009, 07:45 AM
Intermediate Member
 
Posts: 15
Default

Sorry

How to synchronize External Ldap with Internal Ldap ?
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.