I've been able to get it to work with
DOT7 mode but have't tried with 8. MS AD 2003R2 or above supports
RFC2307bis attributes (although you can use other values for them,
like I am using sAMAccountName instead of UID below).
Some of the required option are not shown by default which is odd
but this works for me, I am using port 3268 because I have
multiple domains, to support that you need to make sure your
required attributes (UID,GID etc) are replicated to Global
Catalogs (not all are by default) and have "ldap.site.company.com"
resolve to a Global Catalog.
ldap.ADdomain
company.com
ldap.base dc=company,dc=com
ldap.base.group dc=company,dc=com
ldap.base.netgroup
ldap.base.passwd dc=company,dc=com
ldap.enable on
ldap.minimum_bind_level simple
ldap.name
cn=ldap-auth-svc,ou=ldap,ou=services,dc=site,dc=company,dc=com
ldap.nssmap.attribute.gecos gecos
ldap.nssmap.attribute.gidNumber gidNumber
ldap.nssmap.attribute.groupname cn
ldap.nssmap.attribute.homeDirectory UnixHomeDirectory
ldap.nssmap.attribute.loginShell loginShell
ldap.nssmap.attribute.memberNisNetgroup
memberNisNetgroup
ldap.nssmap.attribute.memberUid memberUid
ldap.nssmap.attribute.netgroupname cn
ldap.nssmap.attribute.nisNetgroupTriple
nisNetgroupTriple
ldap.nssmap.attribute.uid sAMAccountName
ldap.nssmap.attribute.uidNumber uidNumber
ldap.nssmap.attribute.uniqueMember member
ldap.nssmap.attribute.userPassword unixUserPassword
ldap.nssmap.objectClass.groupOfUniqueNames group
ldap.nssmap.objectClass.nisNetgroup nisNetgroup
ldap.nssmap.objectClass.posixAccount user
ldap.nssmap.objectClass.posixGroup group
ldap.passwd ******
ldap.port 3268
ldap.rfc2307bis.enable on
ldap.servers ldap.site.company.com
ldap.servers.preferred
ldap.skip_cn_unescape.enable on
ldap.ssl.enable off
ldap.timeout 20
ldap.usermap.attribute.unixaccount sAMAccountName
ldap.usermap.attribute.windowsaccount sAMAccountName
ldap.usermap.base
ldap.usermap.enable on
Jeremy Page |
Senior Technical Architect | Gilbarco Veeder-Root, A
Danaher Company
Office:336-547-5399 | Cell:336-601-7274 | 24x7
Emergency:336-430-8151
On 04/10/2014 12:51 PM, Michael Bergman wrote: