LDAP Problems

JohnKyrle

New Member
Mar 5, 2007
14
0
1
I am trying to setup ldap intergration but have run into a small problem.

If I try to add a base DN for groups I get an error which I do not understand.

Error: ldap group search error: 000020D6: SvcDrr: DSID-031006CC, problem 5012 (DIR_ERROR), data 0

All I have added to get this error is:

cn=students

into the following field:

Base DN for Groups (optional)

Now what I want to do is to create an ldap group for each or our user sets i.e. students, staff, senior management etc.....

Any ideas??

Regards,

Ozan Pakyuz, MCSE
John Kyrle High School
 
You need to add the full path, for example:

OU=Your Groups,DC=example,DC=com

Then Proxmox only considers groups inside that directory.

Whithout "Base DN for Groups" you can use all groups for filtering.

So why do you want to add such restriction at all? Simply Create the Groups you want, then you can use them with our LDAP Group object inside the rule system.

The number of LDAP Groups found ist displayed when you create a new profile.

What version of AD do you use?

- Dietmar
 
You need to add the full path, for example:

OU=Your Groups,DC=example,DC=com

Then Proxmox only considers groups inside that directory.

Whithout "Base DN for Groups" you can use all groups for filtering.

So why do you want to add such restriction at all? Simply Create the Groups you want, then you can use them with our LDAP Group object inside the rule system.

The number of LDAP Groups found ist displayed when you create a new profile.

What version of AD do you use?

- Dietmar
We use a 2003 AD.

So if I understand you correctly:

1 - Add an LDAP rule at the top level covering all our AD groups
2 - Using the Rules system add rules based on LDAP group there?

Is this correct?
 
Yes, you can configure an LDAP profile covering all groups. Then you can create 'who'-objects using the 'LDAP Group' filter (where you can select the the Profile/Groups).

- Dietmar
 
Yes, you can configure an LDAP profile covering all groups. Then you can create 'who'-objects using the 'LDAP Group' filter (where you can select the the Profile/Groups).

- Dietmar
I now see when editing the rules if you select "LDAP GROUP" you then get a list of group there that you can apply filtering to, nice ;-)

Many thanks for your help
 

About

The Proxmox community has been around for many years and offers help and support for Proxmox VE, Proxmox Backup Server, and Proxmox Mail Gateway.
We think our community is one of the best thanks to people like you!

Get your subscription!

The Proxmox team works very hard to make sure you are running the best software and getting stable updates and security enhancements, as well as quick enterprise support. Tens of thousands of happy customers have a Proxmox subscription. Get yours easily in our online shop.

Buy now!