This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Active Directory "No groups found for user"

I've set up a win2003 DC as a server object. 
I've went into signle-sign on under users - authentication and joined the Astaro box into the domain.
My BIND DN seems to work. When i click Test the "Test passed"

When i try to authenticate a user, I get this popup
User authentication:


LDAP call error


User is a member of the following groups:

No groups have been found for this user


When i go to the advanced tab and add a group for prefecth, i can brows the AD tree. So i add the Domain Users group and it says 0 users in group (which is wrong).
Here's the prefetch log:
2010:03:24-22:19:10 fw-oslo user_prefetch[6513]: Retrieving server configuration

2010:03:24-22:19:10 fw-oslo user_prefetch[6513]: -> using internal configuration from Confd
2010:03:24-22:19:10 fw-oslo user_prefetch[6513]: Using contexts from confd object
2010:03:24-22:19:10 fw-oslo user_prefetch[6513]: ldap server:
2010:03:24-22:19:10 fw-oslo user_prefetch[6513]: server: 192.168.1.3
2010:03:24-22:19:10 fw-oslo user_prefetch[6513]: port: 389
2010:03:24-22:19:10 fw-oslo user_prefetch[6513]: ssl: 0
2010:03:24-22:19:10 fw-oslo user_prefetch[6513]: bind_dn: CN=Administrator,CN=Users,DC=intelcom,DC=local
2010:03:24-22:19:10 fw-oslo user_prefetch[6513]: update: 0
2010:03:24-22:19:10 fw-oslo user_prefetch[6513]: contexts:
2010:03:24-22:19:10 fw-oslo user_prefetch[6513]: CN=Domain Users,CN=Users,DC=intelcom,DC=local
2010:03:24-22:19:10 fw-oslo user_prefetch[6513]: ------------------------------------------------------------
2010:03:24-22:19:10 fw-oslo user_prefetch[6513]: Starting synchronization for adirectory
2010:03:24-22:19:10 fw-oslo user_prefetch[6513]: ------------------------------------------------------------
2010:03:24-22:19:10 fw-oslo user_prefetch[6513]: ------------------------------------------------------------
2010:03:24-22:19:10 fw-oslo user_prefetch[6513]: Searching for users
2010:03:24-22:19:10 fw-oslo user_prefetch[6513]: ------------------------------------------------------------
2010:03:24-22:19:10 fw-oslo user_prefetch[6513]: Connecting to ldap server
2010:03:24-22:19:10 fw-oslo user_prefetch[6513]: ldap server: ldap://192.168.1.3:389
2010:03:24-22:19:11 fw-oslo user_prefetch[6513]: No group members found for group 'CN=Domain Users,CN=Users,DC=intelcom,DC=local'
2010:03:24-22:19:11 fw-oslo user_prefetch[6513]: ------------------------------------------------------------
2010:03:24-22:19:11 fw-oslo user_prefetch[6513]: Performing ldap search:
2010:03:24-22:19:11 fw-oslo user_prefetch[6513]: Ldap search returned 0 users
2010:03:24-22:19:11 fw-oslo user_prefetch[6513]: Search time: 0m 0s
2010:03:24-22:19:12 fw-oslo user_prefetch[6513]: ------------------------------------------------------------
2010:03:24-22:19:12 fw-oslo user_prefetch[6513]: Adding/updating users
2010:03:24-22:19:12 fw-oslo user_prefetch[6513]: ------------------------------------------------------------
2010:03:24-22:19:12 fw-oslo user_prefetch[6513]: 0 user objects were found:
2010:03:24-22:19:12 fw-oslo user_prefetch[6513]: 0 users were created
2010:03:24-22:19:12 fw-oslo user_prefetch[6513]: 0 users were updated
2010:03:24-22:19:12 fw-oslo user_prefetch[6513]: 0 users are authenticated locally.
2010:03:24-22:19:12 fw-oslo user_prefetch[6513]: Overall time: 0m 2s 


This thread was automatically locked due to age.
Parents
  • it WILL auto populate users and de-populate users and you can have them created in openvpn section as well...AD SSO is for much more than only http AD SSO..it's truly integrated if you configure it properly.

    Owner:  Emmanuel Technology Consulting

    http://etc-md.com

    Former Sophos SG(Astaro) advocate/researcher/Silver Partner

    PfSense w/Suricata, ntopng, 

    Other addons to follow

Reply
  • it WILL auto populate users and de-populate users and you can have them created in openvpn section as well...AD SSO is for much more than only http AD SSO..it's truly integrated if you configure it properly.

    Owner:  Emmanuel Technology Consulting

    http://etc-md.com

    Former Sophos SG(Astaro) advocate/researcher/Silver Partner

    PfSense w/Suricata, ntopng, 

    Other addons to follow

Children
No Data