Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Installation

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 04-13-2006, 11:52 PM
Intermediate Member
 
Posts: 15
Default External LDAP: Admin says it works, but users can't login

Have my system running on CentOS 4.x, everything updated via yum. Got zimbra to start and it appears happy, then I went to the domain part of the admin console (webapp), and went to "configure authentication" and set up the LDAP filter (uid=%u) and search base: ou=People,dc=blah,dc=blahblah, and when I went to test it, it worked: I tried different user accounts, and gave correct and incorrect passwords, and the test succeeded in authenticating when the password was correct only.

If only that were the case for the rest of the application. When I try to login as a regular user, it says wrong password, whether I append the domain or not. I'm quite sure that the password being given is correct, and frankly it returns failure much too quickly - I suspect I've missed a step here. I've tried with and without the DN/password set.

zmcontrol status shows everything running.
ldapwhoami returns the following:
Quote:
[zimbra@mail ~]$ ldapwhoami
SASL/OTP authentication started
ldap_sasl_interactive_bind_s: Internal (implementation specific) error (80)
additional info: SASL(-13): user not found: no OTP secret in database
Same thing with ldapsearch. D'oh! What'd I miss?
Reply With Quote
  #2 (permalink)  
Old 04-14-2006, 01:37 AM
Zimbra Employee
 
Posts: 4,792
Default

Are you pointing to an external LDAP or zimbra itself. Can you run a local LDAP search against your LDAP dir?
__________________
Bugzilla - Wiki - Downloads - Offline Client
Reply With Quote
  #3 (permalink)  
Old 04-14-2006, 07:53 AM
Intermediate Member
 
Posts: 15
Default

How would I be able to find out the answers to these questions?
Reply With Quote
  #4 (permalink)  
Old 04-14-2006, 08:23 AM
Zimbra Employee
 
Posts: 4,792
Default

Is the ldap host you configured the same as the zimbra host?
__________________
Bugzilla - Wiki - Downloads - Offline Client
Reply With Quote
  #5 (permalink)  
Old 04-14-2006, 09:06 AM
Intermediate Member
 
Posts: 15
Default

As far as I can tell, there are two places where LDAP configuration is an issue. The first place is in the CLI during the operation of zmsetup.pl, and for that part I left things default (LDAP happens on the zimbra host) per the phone support person at zimbra. The second place I configured LDAP is in the zimbra admin console, and in that location, I've configured zimbra to look at an external LDAP server - the one we use to authenticate all our users.

Hope that makes things slightly more clear than mud...
Reply With Quote
  #6 (permalink)  
Old 04-14-2006, 09:10 AM
Zimbra Employee
 
Posts: 4,792
Default

Quote:
Originally Posted by rrsd
As far as I can tell, there are two places where LDAP configuration is an issue. The first place is in the CLI during the operation of zmsetup.pl, and for that part I left things default (LDAP happens on the zimbra host) per the phone support person at zimbra. The second place I configured LDAP is in the zimbra admin console, and in that location, I've configured zimbra to look at an external LDAP server - the one we use to authenticate all our users.

Hope that makes things slightly more clear than mud...
Do you have a support case for this? If so please finish there. It's a waste of our time to try to solve the same problem in two places. If not we can keep working on it here.

Can you use ldasearch to run a test search against your external LDAP server? Just do a simple search for like an email address.
__________________
Bugzilla - Wiki - Downloads - Offline Client
Reply With Quote
  #7 (permalink)  
Old 04-14-2006, 09:15 AM
Intermediate Member
 
Posts: 15
Default

There is not currently a support case open on this issue.

ldapsearch throws the same error as given above. So I'm pretty much at a loss.

Last edited by rrsd; 04-14-2006 at 10:05 AM..
Reply With Quote
  #8 (permalink)  
Old 04-14-2006, 01:12 PM
Intermediate Member
 
Posts: 15
Default

Argh, ok. Turns out that I have to also create the account in zimbraAdmin. Then everything goes swimmingly.
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.