Solved

AD LDAP Authentication Question

Posted on 2010-11-24
4
862 Views
Last Modified: 2015-01-05
We are trying to set up a 3rd party device to authenicate AD user accounts via LDAP.

The device is a Mitel Applications Suite and is asking for the following fields in the LDAP Configuation settings...

1) LDAP Server Name:

We are using: 10.21.0.25  (The IP address of the AD server)

2) LDAP Port Number

We are using:  389

3) LDAP Search Base

We Are using:   CN=Staff,DC=OurDomainName,DC=local  (our user objects are in the Staff container)

4) LDAP Admin ID

We are using:  CN=Test,CN=Staff,DC=OurDomainName,DC=local  
(user account  "test" is a domain admin in the staff container)

5) LDAP Admin ID Password

We are using: user account "Tests" AD password

6) LDAP UID Field

We are using the string:  sAMAccountName

7) Email domain

We are using:   ourdomainname.com


We are trying to use the preceeding values but are unsucessful.

We are not seeing anything appear in the AD server's event log when we try to authenticate either.


Can anyone be of assistance
0
Comment
Question by:miteldatanet
  • 2
4 Comments
 
LVL 5

Expert Comment

by:sgdought
ID: 34207573
Try downloading the softerra ldap browser and see if you can connect with that.   Then see if you can use the browser to help you trouble shhoot your application connectivity issue.
0
 
LVL 35

Expert Comment

by:Joseph Daly
ID: 34207595
Replace this
We Are using:   CN=Staff,DC=OurDomainName,DC=local  (our user objects are in the Staff container)

with this

OU=Staff,DC=OurDomainName,DC=local  


You have CN set for an object that should be using OU.

0
 
LVL 35

Accepted Solution

by:
Joseph Daly earned 500 total points
ID: 34207608
Also you will need to change your test id.

4) LDAP Admin ID
We are using:  CN=Test,OU=Staff,DC=OurDomainName,DC=local  
(user account  "test" is a domain admin in the staff container)

And if all else fails download AD explorer. This will give you a gui interface where you can copy the distinguished name of any AD object.

http://technet.microsoft.com/en-us/sysinternals/bb963907.aspx
0
 
LVL 3

Expert Comment

by:davdjevans
ID: 34216357
For 6) sAMAccount name should be changed for the older style NT4 User account name, something like:
test

And for 7) the domain name needs to be the same as the one used in the ldap distinguished names(DN):
ourdomain.local

ps, If the domain name is company.com, then the ldap DN is: dc=company,dc=com
0

Featured Post

Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Super Scope, DHCP 5 53
Need to set users home page in Microsoft Edge via a GPO 13 31
AD lockouts-AdAudit Plus 7 30
Using cipher to decrypt files. 4 29
Is your Office 365 signature not working the way you want it to? Are signature updates taking up too much of your time? Let's run through the most common problems that an IT administrator can encounter when dealing with Office 365 email signatures.
This article shows how to deploy dynamic backgrounds to computers depending on the aspect ratio of display
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …

895 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

14 Experts available now in Live!

Get 1:1 Help Now