- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
11-08-2012 11:11 AM
Hi,
When we use to authenticate users through AD, we configure LDAP profile and in Authentication profile tab.
We write "sAMAccountname" for attribute at this window.We want to change this attribute and we want users not to log in with just username; We want them to log in with username@domain or domain\username so What attribute should we use ? I tried userPrincipalName but it did not work.Thanks
11-08-2012 11:16 AM
You got to keep sAMAccountname but if you have multiple domains, you will need to configure several LDAP servers (one for each domain) or use a Global one if you infrastructure allows it.
11-08-2012 11:21 AM
we have configured Ldap for each domain.We have 3 domains, 3Ldap profiles.But there are some people with the same name on different domains so
dc1 username: u1
dc2 username: u1
when u1 tries to log in , authentication sequence cannot understand which u1 is he/she user should log in with domain name credential but how ?
11-08-2012 11:23 AM
did you create an authentication Sequence with Profile 1, Profile 2 and Profile 3 ?
11-08-2012 11:26 AM
yes as you said we created.But when it looks the first match of username it doesn't look the other so it cannot understand the person is on 2nd or 3rd.(with that config it is impossible)
11-08-2012 11:29 AM
hmm I have a slighlty different experience : over here it tests my 4 authentication servers one after the other until it matches
11-08-2012 11:31 AM
I see the difference with your setup : I use Kerberos, not LDAP.
I use LDAP for Group extraction only. Authentication is done with Kerberos
11-08-2012 11:31 AM
you also have users with the same name because otherwise no problem occurs.
11-08-2012 11:32 AM
hmm.I see.maybe we should change auth method also
11-08-2012 11:34 AM
I do have users with same name, no problem so far. But there is a small probabilty that not all of them are using my captive portal ....
11-08-2012 11:55 AM
I understand.Thanks very much for help.I opened a case let me look what support will do and I'll write if there is any option to solve it.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!