Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Active Directory "No groups found for user"

I've set up a win2003 DC as a server object. 
I've went into signle-sign on under users - authentication and joined the Astaro box into the domain.
My BIND DN seems to work. When i click Test the "Test passed"

When i try to authenticate a user, I get this popup
User authentication:


LDAP call error


User is a member of the following groups:

No groups have been found for this user


When i go to the advanced tab and add a group for prefecth, i can brows the AD tree. So i add the Domain Users group and it says 0 users in group (which is wrong).
Here's the prefetch log:
2010:03:24-22:19:10 fw-oslo user_prefetch[6513]: Retrieving server configuration

2010:03:24-22:19:10 fw-oslo user_prefetch[6513]: -> using internal configuration from Confd
2010:03:24-22:19:10 fw-oslo user_prefetch[6513]: Using contexts from confd object
2010:03:24-22:19:10 fw-oslo user_prefetch[6513]: ldap server:
2010:03:24-22:19:10 fw-oslo user_prefetch[6513]: server: 192.168.1.3
2010:03:24-22:19:10 fw-oslo user_prefetch[6513]: port: 389
2010:03:24-22:19:10 fw-oslo user_prefetch[6513]: ssl: 0
2010:03:24-22:19:10 fw-oslo user_prefetch[6513]: bind_dn: CN=Administrator,CN=Users,DC=intelcom,DC=local
2010:03:24-22:19:10 fw-oslo user_prefetch[6513]: update: 0
2010:03:24-22:19:10 fw-oslo user_prefetch[6513]: contexts:
2010:03:24-22:19:10 fw-oslo user_prefetch[6513]: CN=Domain Users,CN=Users,DC=intelcom,DC=local
2010:03:24-22:19:10 fw-oslo user_prefetch[6513]: ------------------------------------------------------------
2010:03:24-22:19:10 fw-oslo user_prefetch[6513]: Starting synchronization for adirectory
2010:03:24-22:19:10 fw-oslo user_prefetch[6513]: ------------------------------------------------------------
2010:03:24-22:19:10 fw-oslo user_prefetch[6513]: ------------------------------------------------------------
2010:03:24-22:19:10 fw-oslo user_prefetch[6513]: Searching for users
2010:03:24-22:19:10 fw-oslo user_prefetch[6513]: ------------------------------------------------------------
2010:03:24-22:19:10 fw-oslo user_prefetch[6513]: Connecting to ldap server
2010:03:24-22:19:10 fw-oslo user_prefetch[6513]: ldap server: ldap://192.168.1.3:389
2010:03:24-22:19:11 fw-oslo user_prefetch[6513]: No group members found for group 'CN=Domain Users,CN=Users,DC=intelcom,DC=local'
2010:03:24-22:19:11 fw-oslo user_prefetch[6513]: ------------------------------------------------------------
2010:03:24-22:19:11 fw-oslo user_prefetch[6513]: Performing ldap search:
2010:03:24-22:19:11 fw-oslo user_prefetch[6513]: Ldap search returned 0 users
2010:03:24-22:19:11 fw-oslo user_prefetch[6513]: Search time: 0m 0s
2010:03:24-22:19:12 fw-oslo user_prefetch[6513]: ------------------------------------------------------------
2010:03:24-22:19:12 fw-oslo user_prefetch[6513]: Adding/updating users
2010:03:24-22:19:12 fw-oslo user_prefetch[6513]: ------------------------------------------------------------
2010:03:24-22:19:12 fw-oslo user_prefetch[6513]: 0 user objects were found:
2010:03:24-22:19:12 fw-oslo user_prefetch[6513]: 0 users were created
2010:03:24-22:19:12 fw-oslo user_prefetch[6513]: 0 users were updated
2010:03:24-22:19:12 fw-oslo user_prefetch[6513]: 0 users are authenticated locally.
2010:03:24-22:19:12 fw-oslo user_prefetch[6513]: Overall time: 0m 2s 


This thread was automatically locked due to age.
Parents
  • I'm not really thinking of using this for http proxy, but to import the domain users for SSL VPN authorization. I just don't want to add them manually (though it's not really a problem). 

    (Which is why this thread wasn't added in web security, but under the "Management" Term for this particular forum.
Reply
  • I'm not really thinking of using this for http proxy, but to import the domain users for SSL VPN authorization. I just don't want to add them manually (though it's not really a problem). 

    (Which is why this thread wasn't added in web security, but under the "Management" Term for this particular forum.
Children
No Data