Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Administrators

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #11 (permalink)  
Old 07-16-2011, 10:58 PM
Member
 
Posts: 14
Default

Quote:
Originally Posted by PhD View Post
a working line in my audit log shows:
2011-07-17 14:59:32,345 INFO [btpool0-2457://localhost/service/soap/AuthRequest] [name=username@domain.com;oip=10.0.0.10;ua=zclient/7.1.1_GA_3213;] security - cmd=Auth; account=username@domain.com; protocol=soap;

it looks like it might failing at finding a "valid" zimbra account?

whats the output of

zmprov ga csoviero | grep -e ^uid: -e ^mail:
ERROR: account.NO_SUCH_ACCOUNT (no such account: csoviero)

I may have found the problem...

I did a tcpdump while doing the following, and opened it up in Wireshark:
  • Doing the test (that works)
  • Actually logging in (which doesn't work)

When doing the first, I see a dozen or so packets flying back and forth with LDAP auth info...

However, when I actually try to login, there is no connection attempted between the LDAP server and Zimbra AT ALL!?

Huh!?

Edit: I also did a packet capture while running your command, and again no communication between the two servers... I am so confused.
Reply With Quote
  #12 (permalink)  
Old 07-16-2011, 11:05 PM
Member
 
Posts: 14
Default

Quote:
Originally Posted by PhD View Post
did you "actually" create a zimbra account called csoviero for the domain you have configured?

You still need to actually create users in zimbra, and their username must match the uid in ldap (or if it doesnt, then there is a field to map the user in zimbra to a user in ldap called "External LDAP account for Authentication:") - then you can log in using the username (or alias of the username) and the password in ldap.
Huh? You have to create the user in both Zimbra and the LDAP server to authenticate against the LDAP server? Doesn't that defeat the purpose?
Reply With Quote
  #13 (permalink)  
Old 07-16-2011, 11:06 PM
PhD PhD is offline
Senior Member
 
Posts: 62
Default

Yes that right... as zimbra uses its own internal ldap system for user accounts and system settings...
external ldap auth is just that... used for password authentication - but it still requires a valid user account in zimbra to authenticate with
Reply With Quote
  #14 (permalink)  
Old 07-16-2011, 11:10 PM
Member
 
Posts: 14
Default

Quote:
Originally Posted by PhD View Post
Yes that right... as zimbra uses its own internal ldap system for user accounts and system settings...
external ldap auth is just that... used for password authentication - but it still requires a valid user account in zimbra to authenticate with
Whatever man,

Thank you for all your help though!
Reply With Quote
  #15 (permalink)  
Old 07-16-2011, 11:26 PM
PhD PhD is offline
Senior Member
 
Posts: 62
Default

you can use the provisioning tool to import all the user accounts from your external ldap source - as a quick way to import them... (i think the OSS version has that option...) -

LDAP Authentication - Zimbra :: Wiki - this might give some more info for ldap auth..

and this Use external LDAP and MySQL mentions about something similar to what you were hoping to achive..


Good luck with it.. zimbra really is a good product
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.