Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Administrators

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 07-11-2010, 06:45 AM
Member
 
Posts: 13
Default invalid credentials

Hello,
Small problem occurred while trying to authenticate users via Zimbra’s ldap server. I have 15 thinclient workstations which are used by students. I would like to configure those machines to authenticate students through their zimbra accounts.

On my ltsp-ubuntu 10.4 server I installed libpam-ldap and configured it like this:

Ldap.conf:
base dc=student,dc=my,dc=domain,dc=com
uri ldap://192.168.10.15/
ldap_version 3
binddn cn=config
bindpw cnPasswd
rootbinddn uid=zimbra,cn=admins,cn=zimbra
#ldap.secret file contains password
bind_policy soft
pam_password md5
nss_initgroups_ignoreusers avahi,avahi-autoipd,backup,bin,couchdb,daemon,dhcpd,games,gdm, gnats,haldaemon,hplip,irc,kernoops,libuuid,list,lp ,mail,man,messagebus,nbd,news,proxy,pulse,root,rtk it,saned,speech-dispatcher,sshd,sync,sys,syslog,tftp,usbmux,uucp,w ww-data

common-acount:
account [success=2 new_authtok_reqd=done default=ignore] pam_unix.so
account [success=1 default=ignore] pam_ldap.so
account requisite pam_deny.so
account required pam_permit.so

common-auth:
auth [success=2 default=ignore] pam_unix.so nullok_secure
auth [success=1 default=ignore] pam_ldap.so use_first_pass
auth requisite pam_deny.so
auth required pam_permit.so

common-password:
password [success=2 default=ignore] pam_unix.so obscure sha512
password [success=1 user_unknown=ignore default=die] pam_ldap.so use_authtok try_first_pass
password requisite pam_deny.so
password required pam_permit.so

common-session:
session [default=1] pam_permit.so
session requisite pam_deny.so
session sufficient pam_unix.so
session optional pam_ck_connector.so nox11

nsswitch.conf
passwd: files ldap
group: files ldap
shadow: compat
hosts: files mdns4_minimal [NOTFOUND=return] dns mdns4
networks: files
protocols: db files
services: db files
ethers: db files
rpc: db files
netgroup: nis

When I try to login with credentials which are stored in ldap server (student01 / studentspass) I got a response saying permission denied, wrong password.

thinserver's auth.log:
pam_ldap: error trying to bind as user “uid=student01, ou=people, dc=student,dc=my,dc=domain,dc=com” (invalid credentials)

On zimbra side, I included nis.schema in slapd.conf file but didn't add posix Admin extension, nor posix account.

Any suggestions? I can't figure out this one... Thanx
Kostres
Reply With Quote
  #2 (permalink)  
Old 09-01-2010, 01:53 PM
Junior Member
 
Posts: 6
Default

I have the same problem, did you ever solve this issue? I constantly get invalidCredentials no matter what. Even if i set the userPassword field blank and login in with a blank password.
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.