Configure the Gerrit to use Windows Domain Account to authenticate

1,191 views
Skip to first unread message

johnny

unread,
Aug 15, 2012, 5:32:55 AM8/15/12
to repo-d...@googlegroups.com
Hi,

I know Gerrit supports LDAP. However, is there anyone here who ever configured the Gerrit to use Windows Domain Account? If so, can please share a BKM on it.

Our company uses the Windows Domain, so using the domain account will be easy for users. They needn't to remember the other password.

Regards,
Johnny

Richard Bywater

unread,
Aug 15, 2012, 5:42:13 AM8/15/12
to johnny, repo-d...@googlegroups.com
Are you referring to Active Directory or some other form of Windows
domain authentication?

If you are talking about Active Directory then its a "simple" matter
of just pointing the LDAP settings at the domain controller and then
ensuring that the various settings reflect the setup of your AD.
(Unfortunately I have done it before but only with an older version of
Gerrit plus can't find my config at the moment :) )

Cheers
Richard.
> --
> To unsubscribe, email repo-discuss...@googlegroups.com
> More info at http://groups.google.com/group/repo-discuss?hl=en

Remy Bohmer

unread,
Aug 15, 2012, 1:27:00 PM8/15/12
to johnny, repo-d...@googlegroups.com

Robin Rosenberg

unread,
Aug 15, 2012, 5:34:20 PM8/15/12
to repo-d...@googlegroups.com
I got that to work. Is there any way Gerrit could use SSO (kerberos) for authenticating
the server to AD instead of using a password?

-- robin

Magnus Bäck

unread,
Aug 15, 2012, 6:02:22 PM8/15/12
to repo-d...@googlegroups.com
On Wednesday, August 15, 2012 at 17:34 EDT,
Robin Rosenberg <robin.rose...@dewire.com> wrote:

> I got that to work. Is there any way Gerrit could use SSO (kerberos)
> for authenticating the server to AD instead of using a password?

Yes, but that's mainly a web server configuration problem. Apache with
mod_auth_kerb can accept Kerberos tickets and pass on the name of the
authenticated user to Gerrit. You need to set Gerrit's auth.type to
HTTP_LDAP (or HTTP, but presumably you want to pick up group membership
etc from Active Directory).

--
Magnus Bäck
ba...@google.com
Reply all
Reply to author
Forward
0 new messages