Different BaseDN for User/Group Objects in rlm_ldap

2013-01-09 Thread Rudolph Bott
Hi List, we are currently using rlm_ldap to check against a LDAP backend, which works fine so far. rlm_ldap is configured to use a BaseDN of ou=poeple,dc=example,dc=org. We have also specified a group membership filter and are trying to enforce group memberships via the combination of

Re: Different BaseDN for User/Group Objects in rlm_ldap

2013-01-09 Thread Michael Schwartzkopff
Am Mittwoch, 9. Januar 2013, 09:29:48 schrieb Rudolph Bott: Hi List, we are currently using rlm_ldap to check against a LDAP backend, which works fine so far. rlm_ldap is configured to use a BaseDN of ou=poeple,dc=example,dc=org. We have also specified a group membership filter and are

Re: Different BaseDN for User/Group Objects in rlm_ldap

2013-01-09 Thread Rudolph Bott
Hi, thanks for the fast reply. Am 2013-01-09 09:43, schrieb Michael Schwartzkopff: Am Mittwoch, 9. Januar 2013, 09:29:48 schrieb Rudolph Bott: Hi List, we are currently using rlm_ldap to check against a LDAP backend, which works fine so far. rlm_ldap is configured to use a BaseDN of

Re: Different BaseDN for User/Group Objects in rlm_ldap

2013-01-09 Thread Tobias Hachmer
On Wednesday 09 January 2013 09:29:48 Rudolph Bott wrote: Is there is possibility to set a different basedn for group lookups OR another feasable solution (e.g. modify the filter...?). Filter and groupmembership_filter are currently set to: Create a new ldap module called e.g. ldap2 (just copy

Re: Different BaseDN for User/Group Objects in rlm_ldap

2013-01-09 Thread Rudolph Bott
Am 2013-01-09 10:27, schrieb Tobias Hachmer: On Wednesday 09 January 2013 09:29:48 Rudolph Bott wrote: Is there is possibility to set a different basedn for group lookups OR another feasable solution (e.g. modify the filter...?). Filter and groupmembership_filter are currently set to: Create

Re: Different BaseDN for User/Group Objects in rlm_ldap

2013-01-09 Thread Tobias Hachmer
On Wednesday 09 January 2013 10:48:16 Rudolph Bott wrote: Am 2013-01-09 10:27, schrieb Tobias Hachmer: On Wednesday 09 January 2013 09:29:48 Rudolph Bott wrote: Is there is possibility to set a different basedn for group lookups OR another feasable solution (e.g. modify the filter...?).

Re: Different BaseDN for User/Group Objects in rlm_ldap

2013-01-09 Thread Phil Mayers
On 01/09/2013 08:29 AM, Rudolph Bott wrote: However, our groups are stored underneath ou=groups,dc=example,dc=org - so rlm_ldap is not able to find them with the basedn shown above. We Unsolicited advice: that's not a great schema, and you should look to move away from it. are also not

Re: Different BaseDN for User/Group Objects in rlm_ldap

2013-01-09 Thread Rudolph Bott
Hi Phil, we fixed the problem by using the radiusGroupName attribute in the user's object instead of posixGroup-Objects. Thanks for your help anyone! Am 2013-01-09 12:38, schrieb Phil Mayers: On 01/09/2013 08:29 AM, Rudolph Bott wrote: However, our groups are stored underneath