Solved

Configuration of Apache with LDAP on Widows 2003

Posted on 2008-06-18
6
641 Views
Last Modified: 2008-06-22
Hi,

   I want to configure the Apache 2.2.8 with MS LDAP and then will configure Subvesion 1.4.6 on Windows 2003 Platform.
I read the documention over the web but most of it is for Unix/Linux platform.  

Can you please provide the detailed configuration of Apache with LDAP. I have installed the Apache 2.2.8 on Windows 2003 and following actions are done.

Following are the entries in httpd.conf file for Apache.
1.LoadModule authnz_ldap_module modules/mod_authnz_ldap.so
2. LoadModule ldap_module modules/mod_ldap.so
3. Add the following

<Directory "C:\Program Files\Apache Software Foundation\Apache2.2\htdocs">
AuthType Basic
AuthName Internal
AuthBasicAuthoritative off
AuthBasicProvider ldap
AuthzLDAPAuthoritative off
AuthLDAPURL "ldap://ldap.domain.com:389/ou=LDAP Users & Groups,dc=domain,dc=com"
Require valid-user
AuthLDAPBindDN "ou=LDAP Users & Groups,dc=domain,dc=com"            
</Directory>

When I try to login to the Apache Server I am not getting authenticated by the LDAP Server and I found the following errors in the Apache Server's log file.

[Wed Jun 18 00:13:19 2008] [warn] [client localhost] [3588] auth_ldap authenticate: user myname authentication failed; URI / [ldap_search_ext_s() for user failed][Operations Error]

Where as the user 'myname' exists in the LDAP.
0
Comment
Question by:Naveed27c
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 3
6 Comments
 
LVL 57

Expert Comment

by:giltjr
ID: 21816660
Typically you must use a authorized ID to connect to the LDAP server to even validate a user.  I don't think that AD allows for anonymous LDAP queries to validate user.

Which means you will need to specify a valid user-id and password on the "AuthLDAPBindDN" statement.
0
 

Author Comment

by:Naveed27c
ID: 21819505
Hi giltjr,  

   Thanks for your comments. I hope you can help me on this issue. There is some entry which I am not entering correctly.  I need you help to put the entried for all the required parameters for LDAP configurations.

     The user in LDAP is 'tester' and his password is 'a1234'. This user is created under a orgnizationalunit OU called 'Users'.    DC=domain,DC=com .  In LDAP the objectClass entries for usre 'tester' are 'top' and 'person'.  I have already defined all the configuration in my post. Now in Apache httpd.conf file I have enter the following entries, Please correct me on this and also if you need any more info let me know. I really need this to work and stuck on this for whole one week. Also let me know if any permission issues are there.

This is on Windows.

<Directory "C:\Program Files\Apache Software Foundation\Apache2.2\htdocs">
AuthType Basic
AuthName Internal
AuthBasicAuthoritative off
AuthBasicProvider ldap
AuthzLDAPAuthoritative off
AuthLDAPURL "ldap://192.168.1.101:389/ou=Users,dc=domain,dc=com"
Require valid-user
AuthLDAPBindDN "cn='tester',ou=Users,dc=domain,dc=com"            
</Directory>

But still getting same error. I dont know how to specify a valid user-id and password on the "AuthLDAPBindDN" statement.

Can you please send me a example configuration which is working and their corresponding entries in LDAP server so I can follow the same steps to setup this.

Thanks Guru
Naveed
0
 
LVL 57

Accepted Solution

by:
giltjr earned 500 total points
ID: 21820985
Here is a guide to help you.  Basically you need something like:


AuthLDAPURL "ldap://192.168.1.101:389/ou=Users,dc=domain,dc=com?sAMAccountName?sub?(objectClass=*)"
AuthLDAPBindDN "cn=tester,cn=Users,dc=domain,dc=com"  
AuthLDAPBindPassword a1234
0
NFR key for Veeam Backup for Microsoft Office 365

Veeam is happy to provide a free NFR license (for 1 year, up to 10 users). This license allows for the non‑production use of Veeam Backup for Microsoft Office 365 in your home lab without any feature limitations.

 

Author Comment

by:Naveed27c
ID: 21828854
Thanks giltjr it worked for user tester after binding the password.

Now if there are 300 users in LDAP in OU 'Users' then how do I authenticate them. I mean to say that now how  a common user part of my domain 'domain' get authenticated.

Thanks
Naveed


0
 

Author Comment

by:Naveed27c
ID: 21833745
Thanks again giltjr, every thing is working now. Great help.

Best Regards
Naveed
0
 
LVL 57

Expert Comment

by:giltjr
ID: 21841752
Glad to see you have it working.  I was out of town and did not have access to the Internet.  To give a basic explanation of why it is working.

The way things normally use LDAP for authentication is they connect to the LDAP server either anonymously or with a "common" user-id.  Then they do a "look-up" for the user you are attempting to verify.  If that user-id exists, then they verify the password.

This is why once you got the correct user-id/password to connect to the LDAP server, everything worked.  If you had users in a OU other than Users, then it gets a bit more complicated.
0

Featured Post

Free Tool: IP Lookup

Get more info about an IP address or domain name, such as organization, abuse contacts and geolocation.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article outlines the process to identify and resolve account lockout in an Active Directory environment.
Lease-to-own eliminates the expenditure of hardware replacement and allows you to pay off the server over time. Usually, this is much cheaper than leasing servers. Think of lease-to-own as credit without interest.
Attackers love to prey on accounts that have privileges. Reducing privileged accounts and protecting privileged accounts therefore is paramount. Users, groups, and service accounts need to be protected to help protect the entire Active Directory …
Are you ready to implement Active Directory best practices without reading 300+ pages? You're in luck. In this webinar hosted by Skyport Systems, you gain insight into Microsoft's latest comprehensive guide, with tips on the best and easiest way…

734 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question