Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > ZCS Client Connectors > CalDAV / CardDAV / iSync

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 02-01-2012, 08:28 AM
lgp lgp is offline
New Member
 
Posts: 3
Default Apple Addressbook LDAP Setup in Lion (10.7)

I have been searching the forums and wiki and tried all suggestions but still no luck so here I go:

I have a Mac 10.7 Lion client and trying to use LDAP for accessing the GAL. I tried with ldapsearch on the same client and the result is success but no info is returned.

I have managed to configure Thunderbird on the same Mac.

I've also tried LDAP Admin on Windows and manage only to connect with the admin account.

My setup
Zimbra server address: zimbra.example.com
Domains:
zimbra.example.com
GAL is both internal and external
Authentication is internal

example.com
GAL is both internal and external
Authentication is external

External Authentication: LDAP
Server address: odm.example.com
LDAP Base: dc=od,dc=example,dc=com

Any tips, please?
Reply With Quote
  #2 (permalink)  
Old 02-02-2012, 01:52 AM
lgp lgp is offline
New Member
 
Posts: 3
Default More info

The external LDAP server is an Open Directory server with the address odm.example.com. LDAP Search Base: dc=od,dc=example,dc=com

The domain: zimbra.example.com
GAL mode: Both
Authentication: External LDAP
Both GAL and Authentication work fine in the Test stage of the configuration.


The domain: example.com
GAL mode: Both
Authentication: External LDAP
Both GAL and Authentication work fine in the Test stage of the configuration.


The user: guest3@example.com
User exists in external LDAP as: uid=guest3,cn=Users,dc=od,dc=example,dc=com
User exists in Zimbra in the domain example.com
What about the field "External LDAP account for Authentication"? Should there be a value in that field?

Client tests on Mac OS X 10.7/Lion client:
Apple Address Book:
Server: zimbra.example.com
Port: 389, no SSL
Search Base: dc=zimbra,dc=example.dc=com
Scope: Subtree
Authentication: Simple
User Name: uid=guest3,ou=people,dc=zimbra,dc=example,dc=com
Password: xxx

No success.

Thunderbird 10.0:
Hostname: zimbra.example.com
Base DN: dc=zimbra,dc=example,dc=com
Port Number: 389
Bind DN: uid=guest3,ou=people,dc=zimbra,dc=example,dc=com

No success.

I have tried different variations of the User Name/Bind DN without dc=zimbra and without the last domain parts, still np luck.

Terminal:
ldapsearch -x -h zimbra.example.com -b "ou=people,dc=zimbra,dc=example,dc=com" "uid=guest3"
# extended LDIF
#
# LDAPv3
# base <ou=people,dc=zimbra,dc=nersc,dc=no> with scope subtree
# filter: uid=guest3
# requesting: ALL
#

# search result
search: 2
result: 0 Success

# numResponses: 1

On the server I see after adjusting the debug level:
Feb 2 10:20:52 zimbra slapd[30747]: conn=1218 op=0 BIND dn="uid=guest3,ou=people,dc=zimbra,dc=example,dc=c om" method=128
Feb 2 10:20:52 zimbra slapd[30747]: conn=1218 op=0 RESULT tag=97 err=49 text=
Feb 2 10:20:52 zimbra slapd[30747]: conn=1218 op=1 UNBIND
Reply With Quote
  #3 (permalink)  
Old 02-06-2012, 10:54 AM
Moderator
 
Posts: 1,432
Default

I use the following, and it works, but note that since it depends on no authentication and no SSL, it's only suitable if you firewall off LDAP at your border firewall.

server: zimbra.company.com
port: 389 (no SSL)
Search Base: ou=people, o=my company (those are the literal values, which are just the greyed-out defaults that appear when you create an LDAP account in Address Book)
Scope: subtree
Authentication: none

See Bug 15378 &ndash; Obviate the need for and disallow LDAP anonymous binds for more info on turning on/off anonymous access.

I tried a while back to get authentication with SSL working (after turning off anonymous access at the server ). I don't recall if I was trying with Snow Leopard or Lion, but I couldn't get it to work.
__________________
Elliot Wilen
Berkeley, CA

Don't forget to enter your Zimbra version in your forum profile.
Reply With Quote
  #4 (permalink)  
Old 02-08-2012, 04:36 AM
lgp lgp is offline
New Member
 
Posts: 3
Default Anonymous LDAP works

I would just like to confirm that anonymous LDAP works in Apple Address Book and Thunderbird.

In Apple Address Book, my settings are:
Name: Zimbra
Server: zimbra.nersc.no
Port: 389, No SSL
Search Base: [blank]
Scope: Subtree
Authentication: None

In Thunderbird my settings are:
General:
Name: Zimbra
Hostname: zimbra.nersc.no
Base DN: [blank]
Port number: 389
Bind DN: [blank]
No SSL
Advanced:
Scope: Subtree
Search filter: (objectclass=*)
Login method: Simple

I am not so sure about only using anonymous LDAP though, I prefer authenticated with SSL.

Thank you very much for your tip!
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.