Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Migration

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 12-06-2011, 05:42 AM
Junior Member
 
Posts: 5
Default Zimbra to AD

Hi, just wondering if anyone has ever gone from Zimbra LDAP and successfully migrated current internal Zimbra users to authenticate from AD.

We've had Zimbra for a few years and now need to look at implementing AD for further user authentication, has anyone ever done this?

Cheers,

Craig
Reply With Quote
  #2 (permalink)  
Old 12-06-2011, 08:41 AM
Zimbra Consultant & Moderator
 
Posts: 20,319
Default

Quote:
Originally Posted by albanwr View Post
Hi, just wondering if anyone has ever gone from Zimbra LDAP and successfully migrated current internal Zimbra users to authenticate from AD.
Yes, plenty of people use AD for authentication.

Quote:
Originally Posted by albanwr View Post
We've had Zimbra for a few years and now need to look at implementing AD for further user authentication, has anyone ever done this?
Same answer as above, just follow the Authentication Wizard in the Admin and read the Admin Guido for details.
__________________
Regards


Bill
Reply With Quote
  #3 (permalink)  
Old 12-06-2011, 09:39 AM
Junior Member
 
Posts: 5
Default

Hi Bill, thanks for your reply. I'm aware that you can use AD as an authentication source, this knowledge was referenced in the original post if you read it correctly.

What I'm trying to achieve is to have our existing 2000 users which are authenticated internally via the zimbra LDAP, to authenticate externally via AD. What I really need to know is the implications and wether its a simple process. What happens to the user passwords?

Thanks.
Reply With Quote
  #4 (permalink)  
Old 12-06-2011, 09:48 AM
Zimbra Consultant & Moderator
 
Posts: 20,319
Default

Quote:
Originally Posted by albanwr View Post
What I'm trying to achieve is to have our existing 2000 users which are authenticated internally via the zimbra LDAP, to authenticate externally via AD. What I really need to know is the implications and wether its a simple process.
I thought I'd already answered this? Just follow the wizard in the Admin UI to use an external authentication source.

Quote:
Originally Posted by albanwr View Post
What happens to the user passwords?
I don't really understand what you mean by that question. Obviously the users will need to exist in AD and that would include their passwords.
__________________
Regards


Bill
Reply With Quote
  #5 (permalink)  
Old 12-06-2011, 09:57 AM
Junior Member
 
Posts: 5
Default

Ok, so we recreate the users in AD, then point the domain to the AD using the wizard.

Is it safe to assume that if the current user also exists in the AD the account will just continue to work after the switch and the user just can log in? Is it really that easy?

Thanks.
Reply With Quote
  #6 (permalink)  
Old 12-06-2011, 10:10 AM
Zimbra Consultant & Moderator
 
Posts: 20,319
Default

Quote:
Originally Posted by albanwr View Post
Is it really that easy?
Yes, it really is.
__________________
Regards


Bill
Reply With Quote
  #7 (permalink)  
Old 12-06-2011, 10:13 AM
Junior Member
 
Posts: 5
Default

Thanks again Bill.

Sorry I suppose that I always assumed that it would be hard...
Reply With Quote
  #8 (permalink)  
Old 12-06-2011, 11:00 AM
Zimbra Consultant & Moderator
 
Posts: 20,319
Default

Quote:
Originally Posted by albanwr View Post
Thanks again Bill.

Sorry I suppose that I always assumed that it would be hard...
If you want to verify the procedure works then create a test domain on your Zimbra server and a couple of users then create them in AD and change the authentication to AD for that domain.

You could also do it for the domain you currently have with local authentication and use this: Disable local authentication with an external ldap to allow users to authenticate even if they don't exist in AD. Once the user is created in AD they get their authentication from that and if AD becomes available they will still be able to login with their original Zimbra password. If you the same passwowrd in AD & Zimbra you'll have to sync the AD password with Zimbra (it isn't done automatically yet), IIRC there's a script in the forums to do that if you'd care to search.
__________________
Regards


Bill
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.