Alternative to sAMAccountname ,when using Ldap for Authentication

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Alternative to sAMAccountname ,when using Ldap for Authentication

L6 Presenter

Hi,

When we use to authenticate users through AD, we configure LDAP profile and in Authentication profile tab.

We write "sAMAccountname" for attribute at this window.We want to change this attribute and we want users not to log in with just username; We want them to log in with username@domain  or  domain\username so What attribute should we use ? I tried userPrincipalName but it did not work.Thanks

10 REPLIES 10

L4 Transporter

You got to keep sAMAccountname but if you have multiple domains, you will need to configure several LDAP servers (one for each domain) or use a Global one if you infrastructure allows it.

we have configured Ldap for each domain.We have 3 domains, 3Ldap profiles.But there are some people with the same name on different domains so

dc1  username: u1

dc2  username: u1

when u1 tries to log in , authentication sequence cannot understand which u1 is he/she user should log in with domain name credential but how ?

did you create an authentication Sequence with Profile 1, Profile 2 and Profile 3 ?

yes as you said we created.But when it looks the first match of username it doesn't look the other so it cannot understand the person is on 2nd or 3rd.(with that config it is impossible)

hmm I have a slighlty different experience : over here it tests my 4 authentication servers one after the other until it matches

I see the difference with your setup : I use Kerberos, not LDAP.

I use LDAP for Group extraction only. Authentication is done with Kerberos

you also have users with the same name because otherwise no problem occurs.

hmm.I see.maybe we should change auth method also

I do have users with same name, no problem so far. But there is a small probabilty that not all of them are using my captive portal ....

I understand.Thanks very much for help.I opened a case let me look what support will do and I'll write if there is any option to solve it.

  • 5792 Views
  • 10 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!