RE: [External] Issues with LDAP Configuration
Daniel McCarty <[email protected]> Tue, 15 Feb 2022 19:19:32 +0000
| Newsgroups | gmane.comp.mozilla.devel.webtools |
|---|---|
| Message-ID | <[email protected]> |
AD is a bit of voodoo to me but I recommend Emmanual's suggestion as well. We ended up creating a domain service account "xxxxxxxxconnector" just for this. Be careful with security here as this account is a domain super account (again I'm not an expert on AD by any means) and a potential attack vector. We were able to bind with userPrincipalName (user: "[email protected]"), but things were easier once we switched to sAMAccountName (user: "username"). Hope this helps, Dan Daniel McCarty Director of Engineering W. H. Leary Co. P. +1 708.444.4900 E. [email protected] | W. whleary.com<http://www.whleary.com> -----Original Message----- From: support-list <[email protected]> On Behalf Of Emmanuel Seyman Sent: Tuesday, February 15, 2022 12:44 PM To: [email protected] Subject: Re: [External] Issues with LDAP Configuration * Agi Joseph [15/02/2022 18:06] : > > Can I know what is the least access required for the user to bind the > LDAP from bugzilla. We cannot configure the administrator account on > bugzilla portal, so required a least permitted user supposed to use > for the binding Note that the DN/password combo you use to bind to the LDAP server does not need to be that of a valid bugzilla user. I recommand you create a dedicated account in your AD to use as the bind account in your Bugzilla config. Emmanuel _______________________________________________ support-list mailing list [email protected] https://urldefense.proofpoint.com/v2/url?u=https-3A__lists.bugzilla.org_listinfo_support-2Dlist&d=DwICAg&c=euGZstcaTDllvimEN8b7jXrwqOf-v5A_CdpgnVfiiMM&r=KfJK_i8bAAiKEOAyAm9y9vt5kSwc8dkKCDiCjPA9mhw&m=g-ZdcS0CauG1eVsHSGKIxfbr5olIkx9uRM4zvxaHE-c&s=aKUf25ydaBVSjpDDXZkiNWIIk50KnyeB331Rdo3-NQ8&e= _______________________________________________ support-list mailing list [email protected] https://lists.bugzilla.org/listinfo/support-list