Super Contributor.. Chuck Perilli Super Contributor..
Super Contributor..
819 views

Issue with LDAP authentication to central

We have configured LDAP (using eDirectory) to control access to HPOO Central (10.22).  This works fine with static groups but not with dynamic groups.  Has anyone else had an issue with dynamic groups?  Thanks.

Labels (2)
Tags (1)
0 Likes
6 Replies
AndreiTruta Outstanding Contributor.
Outstanding Contributor.

Re: Issue with LDAP authentication to central

Can you provide more details, including screenshots of your configuration and errors from the logs?

Andrei Vasile Truta
0 Likes
Super Contributor.. Chuck Perilli Super Contributor..
Super Contributor..

Re: Issue with LDAP authentication to central

Hi Andrei,

Please see attached screenshots and logs.  Thanks.

p1.jpgp2.jpgp3.jpgp4.jpgp5.jpg

0 Likes
AndreiTruta Outstanding Contributor.
Outstanding Contributor.

Re: Issue with LDAP authentication to central

Detailed information - I like it. The group filter. can you show it fully? I see you have an & there. I wonder what it continunes with.

I wonder if you tried to do an OR like give: (groupoOfNames) OR (groupOfNames AND dynamicGroup) - that is on the objectClass of course.

Andrei Vasile Truta
0 Likes
Super Contributor.. Chuck Perilli Super Contributor..
Super Contributor..

Re: Issue with LDAP authentication to central

Here is teh the whole filter:

(&(objectclass=groupOfNames)(Member={0})(!(objectclass=dynamicGroup)))

0 Likes
AndreiTruta Outstanding Contributor.
Outstanding Contributor.

Re: Issue with LDAP authentication to central

This filter seems to be the reason why the dynamicGroup is filtered out. the negation on objectclass=dynamicGroup is making sure those are excluded.

Something like below might work. not sure it will provide the optimal search in ldap. cannot test it right now.

(&(||(objectclass=groupOfNames)(&(objectclass=groupOfNames)(objectclass=dynamicGroup)))(Member={0}))

Andrei Vasile Truta
0 Likes
Super Contributor.. Chuck Perilli Super Contributor..
Super Contributor..

Re: Issue with LDAP authentication to central

We'll give it a try.  Thanks!

0 Likes
The opinions expressed above are the personal opinions of the authors, not of Micro Focus. By using this site, you accept the Terms of Use and Rules of Participation. Certain versions of content ("Material") accessible here may contain branding from Hewlett-Packard Company (now HP Inc.) and Hewlett Packard Enterprise Company. As of September 1, 2017, the Material is now offered by Micro Focus, a separately owned and operated company. Any reference to the HP and Hewlett Packard Enterprise/HPE marks is historical in nature, and the HP and Hewlett Packard Enterprise/HPE marks are the property of their respective owners.