Active Directory/LDAP binding

56 views
Skip to first unread message

Joseph Rafferty

unread,
Sep 7, 2016, 11:00:19 AM9/7/16
to Search Guard

I've successfully gotten Search Guard 2 to authenticate to one of our Active Directory DCs with a dedicated binding account. My ultimate goal, however, is to use a different Active Directory domain that won't have a dedicated account for binding. Is it possible to use the username and password provided by the client to perform the bind?

This cluster is used in an academic setting, higher ed.

Thanks!

SG

unread,
Sep 19, 2016, 3:36:59 PM9/19/16
to search...@googlegroups.com
if the username is a DN then its possible (although we need to implement it).
A direct bind is only possible if the username is the DN, ist that true in your case?
> --
> You received this message because you are subscribed to the Google Groups "Search Guard" group.
> To unsubscribe from this group and stop receiving emails from it, send an email to search-guard...@googlegroups.com.
> To post to this group, send email to search...@googlegroups.com.
> To view this discussion on the web visit https://groups.google.com/d/msgid/search-guard/80e8b610-e9e8-48df-9234-8ee5b2fafb8f%40googlegroups.com.
> For more options, visit https://groups.google.com/d/optout.

Joseph Rafferty

unread,
Sep 19, 2016, 3:56:12 PM9/19/16
to search...@googlegroups.com
No, but the DNs will all be identical except for the CN. I don't know if this will always be the case, however, and probably won't be common for other institutions.

For now I am using a lightweight authentication proxy that leverages our SAML infrastructure. If you think this is an edge case, I am happy using the proxy.

Thanks!
You received this message because you are subscribed to a topic in the Google Groups "Search Guard" group.
To unsubscribe from this topic, visit https://groups.google.com/d/topic/search-guard/YJaBBtjaih4/unsubscribe.
To unsubscribe from this group and all its topics, send an email to search-guard...@googlegroups.com.

To post to this group, send email to search...@googlegroups.com.
Reply all
Reply to author
Forward
0 new messages