Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
 
Go Back   Zimbra - Forums > Zimbra Collaboration Suite > Administrators

Welcome to the Zimbra - Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 05-16-2007, 02:48 PM
New Member
 
Posts: 4
Question Disable local authentication with an external ldap

I recently installed the latest version of Zimbra. I created users with a default known password to facilitate syncing of emails from the old server to Zimbra. Once the ldapsync was finished Zimbra was reconfigured to authenticate with our external ldap server.
However users can now log in with both the password on the external ldap and the password configured locally on Zimbra
Is there a way to prevent users from authenticating locally when an external ldap is selected?
Reply With Quote
  #2 (permalink)  
Old 05-16-2007, 11:37 PM
Zimbra-Yahoo Consultant
 
Posts: 5,608
Default

In the administration console, you probably have authentication set to "BOTH". Change that.
Reply With Quote
  #3 (permalink)  
Old 05-17-2007, 01:32 AM
New Member
 
Posts: 4
Default

Thanks for the reply,
Could you be more specific? I cant see anywhere where authentication can be set to 'BOTH'

From the graphical interface:
In the domain, authentication is set to: 'Authentication mechanism: External LDAP'

And from the command line it shows just the external ldap

Code:
[zimbra@mail root]$ zmprov gd mydomain.com | grep Auth
zimbraAuthLdapSearchBase: dc=mydomain,dc=com
zimbraAuthLdapSearchBindDn: cn=Manager,dc=mydomain,dc=com
zimbraAuthLdapSearchBindPassword: xXxXx
zimbraAuthLdapSearchFilter: (uid=%u)
zimbraAuthLdapURL: ldap://myldapserver:389
zimbraAuthMech: ldap
Reply With Quote
  #4 (permalink)  
Old 05-17-2007, 02:34 AM
Zimbra Consultant & Moderator
 
Posts: 11,505
Default

There is no current option to fix the problem of having two password. However, what you are asking for will give rise to the user being unable to get email if external LDAP goes down. To get round tha you might want to set the following:
Code:
zmprov md <domain> zimbraAuthFallbackToLocal TRUE
which will fallback to the zimbra ldap for authentication. If you consider the current set-up a problem then vote on this bug.
__________________
Regards


Bill
Reply With Quote
  #5 (permalink)  
Old 05-17-2007, 03:13 AM
New Member
 
Posts: 4
Default

Thanks for the reply,
I can solve my issue by setting zimbraAuthFallbackToLocal to FALSE.
Cheers
Reply With Quote
Reply


Thread Tools
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

Zimbrablog.com




 

Search Engine Optimization by vBSEO 3.1.0