XCP-ng
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    LDAP Groups are Empty

    Scheduled Pinned Locked Moved Xen Orchestra
    3 Posts 2 Posters 1.0k Views 1 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • K Offline
      Kajetan321
      last edited by

      Hello, I set up my auth-ldap (v0.10.4) plugin as follows:

      ldaps://ad_serv.something.company.com
      Certificate authentication item: /etc/ssl/certs/company_root.pem
      check cert = OFF
      Use StartTLS = OFF
      
      base= DC=something,DC=company,DC=com
      Credentials:
      dn = admin@something.company.com
      password = xxxxx
      user filter=(userPrincipalName={{name}})
      ID Attribute= dn
      

      and I’m able to log onto XOA with AD domain credentials. The next challenge is to get LDAP groups working. I used the settings from this post:
      https://xcp-ng.org/forum/topic/3760/ldap-plugin-syncing-groups-from-windows-ad-server-2016-help/3

      Base			DC=something,DC=company,DC=com
      Filter			objectClass=group
      ID Attribute		cn
      Display name attribute	cn
      
      Members mapping
      
      Group attribute		member
      User attribute		dn
      
      

      After rebooting XOA I got the domain groups to show up under Settings > Groups. The problem is each of the groups is empty (no users in group).

      My knowledge of LDAP is very limited. Would anyone know how to modify the configurations so users will populate, I’m assuming that’s what you would want. I would like different AD groups to have different abilities in XO

      Cheers.

      DarkbeldinD 1 Reply Last reply Reply Quote 0
      • DarkbeldinD Offline
        Darkbeldin Vates 🪐 Pro Support Team @Kajetan321
        last edited by

        @Kajetan321 Hi,

        Users are only populating groups when they try to login so that "normal" that you have no user in the groups at start

        K 1 Reply Last reply Reply Quote 0
        • K Offline
          Kajetan321 @Darkbeldin
          last edited by

          @Darkbeldin Got ya, thanks!

          1 Reply Last reply Reply Quote 0

          Hello! It looks like you're interested in this conversation, but you don't have an account yet.

          Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.

          With your input, this post could be even better 💗

          Register Login
          • First post
            Last post