<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<style type="text/css" style="display:none;"><!-- P {margin-top:0;margin-bottom:0;} --></style>
</head>
<body dir="ltr">
<div id="divtagdefaultwrapper" style="font-size:12pt;color:#000000;background-color:#FFFFFF;font-family:Calibri,Arial,Helvetica,sans-serif;">
<p>Is baseDN=&quot;cn=Users,dc=bucknell,dc=edu&quot; actually correct, and all of your users are in cn=Users?</p>
<p><br>
</p>
<p><br>
</p>
<div style="color: rgb(33, 33, 33);">
<hr tabindex="-1" style="display:inline-block; width:98%">
<div id="divRplyFwdMsg" dir="ltr"><font style="font-size:11pt" face="Calibri, sans-serif" color="#000000"><b>From:</b> users-bounces@shibboleth.net &lt;users-bounces@shibboleth.net&gt; on behalf of Michael Dahlberg &lt;olgamirth@gmail.com&gt;<br>
<b>Sent:</b> Wednesday, March 04, 2015 12:23 PM<br>
<b>To:</b> Shib Users<br>
<b>Subject:</b> Re: Active Directory as Authentication Source</font>
<div>&nbsp;</div>
</div>
<div>
<div dir="ltr">
<div class="gmail_extra"><br>
<div class="gmail_quote">On Wed, Mar 4, 2015 at 1:02 PM, Rod Widdowson <span dir="ltr">
&lt;<a href="mailto:rdw@steadingsoftware.com" target="_blank">rdw@steadingsoftware.com</a>&gt;</span> wrote:<br>
<blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex; border-left-width:1px; border-left-color:rgb(204,204,204); border-left-style:solid; padding-left:1ex">
<span class="">&gt; (1) Any suggestions on why the authentication phase is not completed?<br>
<br>
<br>
</span>What are you setting &quot;base&quot; to in login.config? As I recall it needs to be something like<br>
<br>
nase=&quot;CN=Users, DC=toplevel, DC=edu&quot;<br>
<br>
For a domain called <a href="http://toplevel.edu" target="_blank">toplevel.edu</a><br>
<br>
</blockquote>
<div><br>
</div>
<div>This is my BaseDN line:</div>
<div><br>
</div>
<div>baseDN=&quot;cn=Users,dc=bucknell,dc=edu&quot;<br>
</div>
<div><br>
</div>
<div><br>
</div>
<div>&nbsp;</div>
<blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex; border-left-width:1px; border-left-color:rgb(204,204,204); border-left-style:solid; padding-left:1ex">
If you haven't found it already <a href="https://wiki.shibboleth.net/confluence/display/SHIB2/LdapServerIssues" target="_blank">
https://wiki.shibboleth.net/confluence/display/SHIB2/LdapServerIssues</a> has a wealth of useful info.<br>
<span class=""><font color="#888888"><br>
<br>
</font></span></blockquote>
<div><br>
</div>
<div>Yes, I found that page.&nbsp; Completely disabled encryption and tried both types of BindDN as listed in this article.&nbsp; Also, I tried using the Global Catalog port, but our Windows Admins keep that port closed.&nbsp; And because we've always distributed attributes
 from the AD server, the referrals have always been set to follow. &nbsp;(Not sure about the objectSid and objectGUID params).</div>
<div><br>
</div>
<div>Also, a final note: I've tried using ldapsearch with the given BaseDN and the BindDN as &quot;<a href="mailto:serviceuser@bucknell.edu">serviceuser@bucknell.edu</a>&quot; and am able to successfully query the AD database.</div>
<div><br>
</div>
<div>I might give Kerberos a try anyway, since I've hit a wall with LDAP.</div>
<div><br>
</div>
<div>Thanks,</div>
<div>Mike</div>
</div>
<br>
</div>
</div>
</div>
</div>
</div>
</body>
</html>