This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

AD groups and membership

Hello,
i'm testing the asl proxy with AD SSO and AD user groups, the thing is that i'm running into problems as the asl box is not detecting group membership.
letme clarify the steps:
*) I created a group, selected backend membership and active directory as provider, but ASL does not shows anything else so how does this work?(if i don't check the limit checkbox, i can't define any groups or cn or anything, what good does that do?)
*) so i checked the limit checkbox and using the ldap browser selected the distribution group the user is member of, but the proxy afterwards does not detect it as valid and falls back.
*) If i select the user specifically in the filter assignment, then it works

any ideas.

asl is 7.502


This thread was automatically locked due to age.
Parents
  • I think this may be a known bug that I thought had been fixed.  In the Astaro User Group definition, when you drag the AD group name into the Astaro definition, you get "CN=Groupname,OU=Unitname,DC=Domain,DC=local" instead of just Groupname.  You manually have to delete everything but Groupname in the Group definiton.

    Was that it?

    Cheers - Bob
     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Reply
  • I think this may be a known bug that I thought had been fixed.  In the Astaro User Group definition, when you drag the AD group name into the Astaro definition, you get "CN=Groupname,OU=Unitname,DC=Domain,DC=local" instead of just Groupname.  You manually have to delete everything but Groupname in the Group definiton.

    Was that it?

    Cheers - Bob
     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Children
No Data