Active Directory as Authentication Source

Cantor, Scott cantor.2 at osu.edu
Thu Mar 5 18:34:33 EST 2015


On 3/5/15, 5:09 PM, "David Gersic" <dgersic at niu.edu> wrote:

>Hm. Ok, a couple of things that are worth a look:
>
>
>1. In login.config I don't think you want to have binddn or 
>usercredentials.

That depends on the LDAP requirements, but if you use a userFilter and 
thus need to search to find the DN to bind, you generally do unless the 
LDAP server is running open to searches.

>2. In attribute-resolver.xml, you probably need to specify a DN for 
>"principal", not a UPN. And same as above, I don't think you want the 
>trailing slash, so:

With an AD, I've found the bare syntax of a principal name works better 
than figuring out what DN it wants, but that may just be the broken 
nightmare of an AD I have to use.

LDAP is just highly situational.

-- Scott




More information about the users mailing list