Link to home
Start Free TrialLog in
Avatar of hostarica

asked on

Troubleshoot mediawiki <-> ActiveDirectory authentication


I'm trying to configure a fresh install of Mediawiki 1.26  to authenticate users from an Active Directory server but it simply refuses to allow this software to work properly. I know the AD server works fine as I also configured an instance of Racktables against it with no problems.
Below is the current configs added to /var/www/html/LocalSettings.php:

require_once( "$IP/extensions/LdapAuthentication/LdapAuthentication.php" );
$wgAuth = new LdapAuthenticationPlugin();
$wgLDAPDomainNames = array( "domain.local" );
$wgLDAPServerNames = array( "domain.local" => "dcmaster.domain.local" );

$wgLDAPSearchStrings = array( "domain.local" => "domain.local\\USER-NAME" );
#$wgLDAPEncryptionType = array( "domain.local" => "tls" );
$wgLDAPUseSSL = false;
$wgLDAPUseTLS = false;
$wgLDAPUseLocal = false;
$wgMinimalPasswordLength = 1;

$wgLDAPBaseDNs = array( "domain.local" => "dc=domain,dc=local" );
# Example: If your domain is then you want to put in "dc=mydomain,dc=internet,dc=ca".

$wgLDAPSearchAttributes = array( "domain.local" => "sAMAccountName" );
$wgLDAPRetrievePrefs = array( "domain.local" => "true" );

$wgLDAPPreferences = array('domain.local' => array( 'email' => 'mail','realname' => 'displayname'));
# This will automatically map the users e-mail address and full name from Active Directory to their account in MediaWiki

Open in new window

However, Access is not granted and I can't seem to find any logfiles either on the mediawiki server or on the AD server.
While trying to sniff the connection packets I found the following info:

[root@wiki ~]# tshark  -ni any '(host'
<deleted lines>
5 0.001356667 -> LDAP 199 extendedResp(1) (00000000: LdapErr: DSID-0C090FAA, comment: [b]Error initializing SSL/TLS, data 0, v2580) LDAP_START_TLS_OID[/b]

Open in new window

As far as I know SSL/TLS should be disabled, however it still shows as if trying to authenticate.
I have reached a wall with this since my google-fu skills seem to show nothing similar.
Has anyone had any experience on this?
Avatar of Brian Murphy
Brian Murphy
Flag of United States of America image

Link to home
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial