Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Administrators

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Closed Thread
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 02-18-2007, 11:48 AM
Loyal Member
 
Posts: 81
Default disable anonymous LDAP access

How to DISABLE anonymous bind/access to LDAP ? I've tried a few things in slapd.conf but it doesn't work .
  #2 (permalink)  
Old 02-18-2007, 09:32 PM
Former Zimbran
 
Posts: 5,606
Default

You can use ipchains to restrict/firewall on the zimbra box.
It's open for browsing email address book.
  #3 (permalink)  
Old 02-18-2007, 09:36 PM
Loyal Member
 
Posts: 81
Default

Thanks . Unfortunately this is not an option because we want external AUTHORIZED NON-ANONYMOUS bind to still be available .
  #4 (permalink)  
Old 02-18-2007, 09:40 PM
Loyal Member
 
Posts: 81
Default

That is , we can't use the firewall ... is there not a way to change the config in slapd.conf or ldap.conf ? It appears no-one has figured this out yet which is kind of odd .
  #5 (permalink)  
Old 02-19-2007, 01:02 AM
Intermediate Member
 
Posts: 21
Default

Well, I also had this issue for a long time. I resorted to use a firewall to block outside access and pass internal IPs. I first wanted to assign another internal IP to the server so that local users can access and and block outsiders based on that. But OpenLDAP only listens on one IP and I couldn't figure out how to make it listen on other IPs as well. So I ended up doing a special routing for local IPs on the router plus the firewall to prevent connections from Internet. Kind of messy, but works.
  #6 (permalink)  
Old 02-19-2007, 06:27 AM
Loyal Member
 
Posts: 81
Default

Kibo , I am sorry but I just said that firewall is not an option for me . I need external access ( but authenticated access ) . If anyone has figured out how to modify the config files for ldap , please let me know .
  #7 (permalink)  
Old 02-19-2007, 06:34 AM
Zimbra Consultant & Moderator
 
Posts: 19,653
Default

As far as I know it's anonymous bind only at the moment. I'd suggest you search bugzilla for any relevant feature requests, if there isn't one then file an entry and vote on it.
__________________
Regards


Bill
  #8 (permalink)  
Old 02-19-2007, 11:59 AM
Loyal Member
 
Posts: 81
Default

OK , but does anyone have an explanation why and how this is the case ? I mean OpenLDAP should be separate from zimbra itself and the config file should be modifiable ( although I have had no luck ) .
  #9 (permalink)  
Old 02-19-2007, 12:11 PM
Zimbra Consultant & Moderator
 
Posts: 19,653
Default

No, it's not seperate from Zimbra - it's part of the package that is Zimbra. It's there and anonymous so we can get at the details that Zimbra stores in it.

Did you vote for the bug in bugzilla? You can also add your comments to it as well.
__________________
Regards


Bill
  #10 (permalink)  
Old 02-19-2007, 02:49 PM
Loyal Member
 
Posts: 81
Default

OK , so you locked in anonymous LDAP somehow ... some trick . I will get to bugzilla eventually this week but I think it is pretty obvious that anonymous LDAP should be allowed to be disabled .

In your zimbra code , you are asking for data anonymously instead of binding with username and password ... that's just lazy code and has nothing to do with necessity .

And I have searched this forum and everybody's questions on this issue HAVE NOT BEEN ANSWERED OR EXPLAINED . And this has been going for who knows how many years . Finally we get to hear from someone that it is simply NOT POSSIBLE . The reason is still not divulged however except that it doesn't take a genius that it is LAZY CODE .
Closed Thread


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.