Sample Header Ad - 728x90

Authenticate Mac users by LDAP

3 votes
1 answer
12232 views
I connected to the LDAP server with a special account and searching password using the Directory Utility. When I set the LDAPv3 Service to RFC2307 LDAP Mappings, with SSL checked, I can move to Directory Editor and authenticate using the username and password for the LDAP directory. I cannot login to the computer however. I did this: 1. Checked the box in Users & Groups - Allow network users to login .... 1. Clicked Options 1. Chose Only these network users 1. Clicked + and searched for my LDAP username 1. Selected the user name so it appears in the list. When I try to login, the box only shakes and these log error messages arrive in the system.log. Aug 31 10:35:58 MacBook-Pro SecurityAgent: User info context values set for userid Aug 31 10:35:58 MacBook-Pro authorizationhost: Failed to authenticate user (error: 13). Some guides on the web indicate error 13 to be so: Indicates that the session is not protected by a protocol such as Transport Layer Security (TLS), which provides session confidentiality and the request will not be handled without confidentiality enabled. But I chose SSL and do not find a box or method to change this to TLS in the Mac Directory Utility. When I click Security in the setup section (where I put the "use authentication when connecting" information) the Security Policy options are unavailable with the message "Server capabilities and requirements determine the availability of options." So, I cannot choose to sign all packets or to Encrypt all packets... When I choose other connection schemes, like Open Directory or Custom, I was unable to even authenticate in the Directory Editor window. (Error 500, 2100) The "authentication when connecting" information is the same that I use for web applications that provide access by LDAP so it surely works in the field. Just not apparently from the Mac when trying to login. Have any advice to allow users to authenticate on this mac by LDAP to access share folders?
Asked by ndasusers (557 rep)
Aug 31, 2016, 03:21 PM
Last activity: Oct 7, 2018, 02:00 PM