Active Directory as Authentication Source

Douglas E Engert deengert at gmail.com
Sat Mar 7 20:58:21 EST 2015



On 3/5/2015 5:34 PM, Cantor, Scott wrote:
> On 3/5/15, 5:09 PM, "David Gersic" <dgersic at niu.edu> wrote:
>
>> Hm. Ok, a couple of things that are worth a look:
>>
>>
>> 1. In login.config I don't think you want to have binddn or
>> usercredentials.
>
> That depends on the LDAP requirements, but if you use a userFilter and
> thus need to search to find the DN to bind, you generally do unless the
> LDAP server is running open to searches.
>
>> 2. In attribute-resolver.xml, you probably need to specify a DN for
>> "principal", not a UPN. And same as above, I don't think you want the
>> trailing slash, so:
>
> With an AD, I've found the bare syntax of a principal name works better
> than figuring out what DN it wants, but that may just be the broken
> nightmare of an AD I have to use.

  This spells it out:

  https://msdn.microsoft.com/en-us/library/cc223499.aspx

>
> LDAP is just highly situational.
>
> -- Scott
>
>

-- 

  Douglas E. Engert  <DEEngert at gmail.com>



More information about the users mailing list