Topic Options
Rate This Topic
#109503 - 12/28/04 04:02 AM AREA LDAP w/ AD
lanners Offline
newbie

Registered: 03/09/05
Posts: 8
I'm having a problem with the bind with setting up the AREA LDAP
configuration with Active Directory.

The error in the arplugin.log file is this: Bind:
Invalid credentials (LDAPERR Code 49) 80090308: LdapErr: DSID-0C09030F,
comment: AcceptSecurityContext error, data 525, vece

I've seen conflicting methods of entering the Distinguishing Name in the
Config form. One way suggests domain\username another uid=username, ou=xxx,
o=zzz

I'm waiting to hear back from the AD people about the structure for the
second example, but I was wondering if anyone has had this problem, or could
validate the DN needed for the bind.

Thanks.

-Kevin Lanners


UNSUBSCRIBE or access ARSlist Archives at http://www.ARSLIST.org
(Support: mailto:support@arslist.org)


Top
#109504 - 12/28/04 05:59 AM Re: AREA LDAP w/ AD [Re: mdellertson]
jjmckenzie51464 Offline
enthusiast

Registered: 03/09/05
Posts: 334
Kevin:

Both should work according to the folks at Remedy. I think that the user should have the appropriate priveledges or you will get errors. Also, make sure the user can actually log into the AD domain appropriately, as passwords can and do get misread.

James McKenzie

-----Original Message-----
From: Kevin Lanners
Sent: Dec 28, 2004 9:02 AM
To: arslist@ARSLIST.ORG
Subject: [ARSLIST] AREA LDAP w/ AD

I'm having a problem with the bind with setting up the AREA LDAP
configuration with Active Directory.

The error in the arplugin.log file is this: Bind:
Invalid credentials (LDAPERR Code 49) 80090308: LdapErr: DSID-0C09030F,
comment: AcceptSecurityContext error, data 525, vece

I've seen conflicting methods of entering the Distinguishing Name in the
Config form. One way suggests domain\username another uid=username, ou=xxx,
o=zzz

I'm waiting to hear back from the AD people about the structure for the
second example, but I was wondering if anyone has had this problem, or could
validate the DN needed for the bind.

Thanks.

-Kevin Lanners


UNSUBSCRIBE or access ARSlist Archives at http://www.ARSLIST.org
(Support: mailto:support@arslist.org)


James McKenzie
A Proud User of Linux!


UNSUBSCRIBE or access ARSlist Archives at http://www.ARSLIST.org
(Support: mailto:support@arslist.org)


Top
#109505 - 12/28/04 06:31 AM Re: AREA LDAP w/ AD [Re: mdellertson]
tluebbe Offline
journeyman

Registered: 03/02/04
Posts: 58
A problem that I just had was that the "user" that I used to
authenticate was listed within the OU of NMR\Flordia\Users, but was also
listed in the NMR\Service Accounts OU. The latter is the one that I had
to use as my distinguished name.

Tom Luebbe
Nielsen Media Research
Oldsmar, FL

-----Original Message-----
From: Action Request System discussion list(ARSList)
[mailto:arslist@ARSLIST.ORG] On Behalf Of James Mckenzie
Sent: Tuesday, December 28, 2004 12:59 PM
To: arslist@ARSLIST.ORG
Subject: Re: [ARSLIST] AREA LDAP w/ AD

Kevin:

Both should work according to the folks at Remedy. I think that the
user should have the appropriate priveledges or you will get errors.
Also, make sure the user can actually log into the AD domain
appropriately, as passwords can and do get misread.

James McKenzie

-----Original Message-----
From: Kevin Lanners
Sent: Dec 28, 2004 9:02 AM
To: arslist@ARSLIST.ORG
Subject: [ARSLIST] AREA LDAP w/ AD

I'm having a problem with the bind with setting up the AREA LDAP
configuration with Active Directory.

The error in the arplugin.log file is this:
Bind:
Invalid credentials (LDAPERR Code 49) 80090308: LdapErr: DSID-0C09030F,
comment: AcceptSecurityContext error, data 525, vece

I've seen conflicting methods of entering the Distinguishing Name in the
Config form. One way suggests domain\username another uid=username,
ou=xxx, o=zzz

I'm waiting to hear back from the AD people about the structure for the
second example, but I was wondering if anyone has had this problem, or
could validate the DN needed for the bind.

Thanks.

-Kevin Lanners



UNSUBSCRIBE or access ARSlist Archives at http://www.ARSLIST.org
(Support: mailto:support@arslist.org)


James McKenzie
A Proud User of Linux!



UNSUBSCRIBE or access ARSlist Archives at http://www.ARSLIST.org
(Support: mailto:support@arslist.org)


UNSUBSCRIBE or access ARSlist Archives at http://www.ARSLIST.org
(Support: mailto:support@arslist.org)


Top
#109506 - 12/27/04 08:30 PM Re: AREA LDAP w/ AD [Re: mdellertson]
lanners Offline
newbie

Registered: 03/09/05
Posts: 8
Thanks everyone. I'm making progress. (I think)

The problem seems to be with AD. I don't know much about it but as you saw
in my original message the bind isn't working due to "invalid credentials"
I've tested the connection through the LDP utility and I get the same error.
I've verified the username and password so what permissions does that user
need to have. According to the documentation it just states they must have
"read permissions". I don't have access to the AD server... How does that
translate to what I need to tell the AD admin?

Thanks.

-Kevin



-----Original Message-----
From: Action Request System discussion list(ARSList)
[mailto:arslist@ARSLIST.ORG] On Behalf Of Luebbe, Tom
Sent: Tuesday, December 28, 2004 12:32 PM
To: arslist@ARSLIST.ORG
Subject: Re: AREA LDAP w/ AD


A problem that I just had was that the "user" that I used to
authenticate was listed within the OU of NMR\Flordia\Users, but was also
listed in the NMR\Service Accounts OU. The latter is the one that I had
to use as my distinguished name.

Tom Luebbe
Nielsen Media Research
Oldsmar, FL

-----Original Message-----
From: Action Request System discussion list(ARSList)
[mailto:arslist@ARSLIST.ORG] On Behalf Of James Mckenzie
Sent: Tuesday, December 28, 2004 12:59 PM
To: arslist@ARSLIST.ORG
Subject: Re: [ARSLIST] AREA LDAP w/ AD

Kevin:

Both should work according to the folks at Remedy. I think that the
user should have the appropriate priveledges or you will get errors.
Also, make sure the user can actually log into the AD domain
appropriately, as passwords can and do get misread.

James McKenzie

-----Original Message-----
From: Kevin Lanners
Sent: Dec 28, 2004 9:02 AM
To: arslist@ARSLIST.ORG
Subject: [ARSLIST] AREA LDAP w/ AD

I'm having a problem with the bind with setting up the AREA LDAP
configuration with Active Directory.

The error in the arplugin.log file is this:
Bind:
Invalid credentials (LDAPERR Code 49) 80090308: LdapErr: DSID-0C09030F,
comment: AcceptSecurityContext error, data 525, vece

I've seen conflicting methods of entering the Distinguishing Name in the
Config form. One way suggests domain\username another uid=username,
ou=xxx, o=zzz

I'm waiting to hear back from the AD people about the structure for the
second example, but I was wondering if anyone has had this problem, or
could validate the DN needed for the bind.

Thanks.

-Kevin Lanners



UNSUBSCRIBE or access ARSlist Archives at http://www.ARSLIST.org
(Support: mailto:support@arslist.org)


James McKenzie
A Proud User of Linux!



UNSUBSCRIBE or access ARSlist Archives at http://www.ARSLIST.org
(Support: mailto:support@arslist.org)



UNSUBSCRIBE or access ARSlist Archives at http://www.ARSLIST.org
(Support: mailto:support@arslist.org)


UNSUBSCRIBE or access ARSlist Archives at http://www.ARSLIST.org
(Support: mailto:support@arslist.org)


Top
#109507 - 12/27/04 08:46 PM Re: AREA LDAP w/ AD [Re: mdellertson]
Jarl Groneng Offline
enthusiast

Registered: 03/10/05
Posts: 2371
Have you tried to connect to the LDAP server with a LDAP client?

Here is a ldap browser:
http://www-unix.mcs.anl.gov/~gawor/ldap/index.html

--
Jarl


> -----Original Message-----
> From: Action Request System discussion list(ARSList)
> [mailto:arslist@ARSLIST.ORG]On Behalf Of Kevin Lanners
> Sent: 28. desember 2004 21:30
> To: arslist@ARSLIST.ORG
> Subject: Re: AREA LDAP w/ AD
>
>
> Thanks everyone. I'm making progress. (I think)
>
> The problem seems to be with AD. I don't know much about it
> but as you saw
> in my original message the bind isn't working due to "invalid
> credentials"
> I've tested the connection through the LDP utility and I get
> the same error.
> I've verified the username and password so what permissions
> does that user
> need to have. According to the documentation it just states
> they must have
> "read permissions". I don't have access to the AD server...
> How does that
> translate to what I need to tell the AD admin?
>
> Thanks.
>
> -Kevin
>
>
>
> -----Original Message-----
> From: Action Request System discussion list(ARSList)
> [mailto:arslist@ARSLIST.ORG] On Behalf Of Luebbe, Tom
> Sent: Tuesday, December 28, 2004 12:32 PM
> To: arslist@ARSLIST.ORG
> Subject: Re: AREA LDAP w/ AD
>
>
> A problem that I just had was that the "user" that I used to
> authenticate was listed within the OU of NMR\Flordia\Users,
> but was also
> listed in the NMR\Service Accounts OU. The latter is the one
> that I had
> to use as my distinguished name.
>
> Tom Luebbe
> Nielsen Media Research
> Oldsmar, FL
>
> -----Original Message-----
> From: Action Request System discussion list(ARSList)
> [mailto:arslist@ARSLIST.ORG] On Behalf Of James Mckenzie
> Sent: Tuesday, December 28, 2004 12:59 PM
> To: arslist@ARSLIST.ORG
> Subject: Re: [ARSLIST] AREA LDAP w/ AD
>
> Kevin:
>
> Both should work according to the folks at Remedy. I think that the
> user should have the appropriate priveledges or you will get errors.
> Also, make sure the user can actually log into the AD domain
> appropriately, as passwords can and do get misread.
>
> James McKenzie
>
> -----Original Message-----
> From: Kevin Lanners
> Sent: Dec 28, 2004 9:02 AM
> To: arslist@ARSLIST.ORG
> Subject: [ARSLIST] AREA LDAP w/ AD
>
> I'm having a problem with the bind with setting up the AREA LDAP
> configuration with Active Directory.
>
> The error in the arplugin.log file is this:
> Bind:
> Invalid credentials (LDAPERR Code 49) 80090308: LdapErr:
> DSID-0C09030F,
> comment: AcceptSecurityContext error, data 525, vece
>
> I've seen conflicting methods of entering the Distinguishing
> Name in the
> Config form. One way suggests domain\username another uid=username,
> ou=xxx, o=zzz
>
> I'm waiting to hear back from the AD people about the
> structure for the
> second example, but I was wondering if anyone has had this problem, or
> could validate the DN needed for the bind.
>
> Thanks.
>
> -Kevin Lanners
>
>
>
>
> UNSUBSCRIBE or access ARSlist Archives at http://www.ARSLIST.org
> (Support: mailto:support@arslist.org)
>
>
> James McKenzie
> A Proud User of Linux!
>
>
>
>
> UNSUBSCRIBE or access ARSlist Archives at http://www.ARSLIST.org
> (Support: mailto:support@arslist.org)
>
>
>
>
> UNSUBSCRIBE or access ARSlist Archives at http://www.ARSLIST.org
> (Support: mailto:support@arslist.org)
>
>
>
> UNSUBSCRIBE or access ARSlist Archives at http://www.ARSLIST.org
> (Support: mailto:support@arslist.org)
>


UNSUBSCRIBE or access ARSlist Archives at http://www.ARSLIST.org
(Support: mailto:support@arslist.org)


Top
#109508 - 12/27/04 09:09 PM Re: AREA LDAP w/ AD [Re: mdellertson]
lanners Offline
newbie

Registered: 03/09/05
Posts: 8
Yes. I used the Windows LDP client. I still get the ldap 49 error on the
bind.

-----Original Message-----
From: Action Request System discussion list(ARSList)
[mailto:arslist@ARSLIST.ORG] On Behalf Of Jarl Groneng
Sent: Tuesday, December 28, 2004 2:46 PM
To: arslist@ARSLIST.ORG
Subject: Re: AREA LDAP w/ AD


Have you tried to connect to the LDAP server with a LDAP client?

Here is a ldap browser:
http://www-unix.mcs.anl.gov/~gawor/ldap/index.html

--
Jarl


> -----Original Message-----
> From: Action Request System discussion list(ARSList)
> [mailto:arslist@ARSLIST.ORG]On Behalf Of Kevin Lanners
> Sent: 28. desember 2004 21:30
> To: arslist@ARSLIST.ORG
> Subject: Re: AREA LDAP w/ AD
>
>
> Thanks everyone. I'm making progress. (I think)
>
> The problem seems to be with AD. I don't know much about it
> but as you saw
> in my original message the bind isn't working due to "invalid
> credentials"
> I've tested the connection through the LDP utility and I get
> the same error.
> I've verified the username and password so what permissions
> does that user
> need to have. According to the documentation it just states
> they must have
> "read permissions". I don't have access to the AD server...
> How does that
> translate to what I need to tell the AD admin?
>
> Thanks.
>
> -Kevin
>
>
>
> -----Original Message-----
> From: Action Request System discussion list(ARSList)
> [mailto:arslist@ARSLIST.ORG] On Behalf Of Luebbe, Tom
> Sent: Tuesday, December 28, 2004 12:32 PM
> To: arslist@ARSLIST.ORG
> Subject: Re: AREA LDAP w/ AD
>
>
> A problem that I just had was that the "user" that I used to
> authenticate was listed within the OU of NMR\Flordia\Users,
> but was also
> listed in the NMR\Service Accounts OU. The latter is the one
> that I had
> to use as my distinguished name.
>
> Tom Luebbe
> Nielsen Media Research
> Oldsmar, FL
>
> -----Original Message-----
> From: Action Request System discussion list(ARSList)
> [mailto:arslist@ARSLIST.ORG] On Behalf Of James Mckenzie
> Sent: Tuesday, December 28, 2004 12:59 PM
> To: arslist@ARSLIST.ORG
> Subject: Re: [ARSLIST] AREA LDAP w/ AD
>
> Kevin:
>
> Both should work according to the folks at Remedy. I think that the
> user should have the appropriate priveledges or you will get errors.
> Also, make sure the user can actually log into the AD domain
> appropriately, as passwords can and do get misread.
>
> James McKenzie
>
> -----Original Message-----
> From: Kevin Lanners
> Sent: Dec 28, 2004 9:02 AM
> To: arslist@ARSLIST.ORG
> Subject: [ARSLIST] AREA LDAP w/ AD
>
> I'm having a problem with the bind with setting up the AREA LDAP
> configuration with Active Directory.
>
> The error in the arplugin.log file is this:
> Bind:
> Invalid credentials (LDAPERR Code 49) 80090308: LdapErr:
> DSID-0C09030F,
> comment: AcceptSecurityContext error, data 525, vece
>
> I've seen conflicting methods of entering the Distinguishing
> Name in the
> Config form. One way suggests domain\username another uid=username,
> ou=xxx, o=zzz
>
> I'm waiting to hear back from the AD people about the
> structure for the
> second example, but I was wondering if anyone has had this problem, or
> could validate the DN needed for the bind.
>
> Thanks.
>
> -Kevin Lanners
>
>
>
>
> UNSUBSCRIBE or access ARSlist Archives at http://www.ARSLIST.org
> (Support: mailto:support@arslist.org)
>
>
> James McKenzie
> A Proud User of Linux!
>
>
>
>
> UNSUBSCRIBE or access ARSlist Archives at http://www.ARSLIST.org
> (Support: mailto:support@arslist.org)
>
>
>
>
> UNSUBSCRIBE or access ARSlist Archives at http://www.ARSLIST.org
> (Support: mailto:support@arslist.org)
>
>
>
> UNSUBSCRIBE or access ARSlist Archives at http://www.ARSLIST.org
> (Support: mailto:support@arslist.org)
>



UNSUBSCRIBE or access ARSlist Archives at http://www.ARSLIST.org
(Support: mailto:support@arslist.org)


UNSUBSCRIBE or access ARSlist Archives at http://www.ARSLIST.org
(Support: mailto:support@arslist.org)


Top
#109509 - 12/29/04 02:16 AM Re: AREA LDAP w/ AD [Re: mdellertson]
JD_Hood Offline
journeyman

Registered: 12/20/04
Posts: 125
Loc: Georgia, USA
I'm no AD expert, but presuming you can log-in to the/an AD domain, you may
want to try just giving it your own network login name and password. You
don't necessarily need to be an AD admin and your own network login
credentials may have all the access permissions you need to read the
directory. At my site, the login name I use for the Remedy ldap integration
is my full email address and network password (though I initially expected
just my login name).

With AD, I actually needed to provide a login to read the directory. Prior
to our migration to AD, I could get to the ldap directory with a blank
login and password (no login at all), so try different combinations of
login name, email, , etc. Just beware of any lock-out policy due to
repeated failed logon attempts...

-JD-

On Tue, 28 Dec 2004 15:09:54 -0600, Kevin Lanners
wrote:

>Yes. I used the Windows LDP client. I still get the ldap 49 error on the
>bind.
>
>-----Original Message-----
>From: Action Request System discussion list(ARSList)
>[mailto:arslist@ARSLIST.ORG] On Behalf Of Jarl Groneng
>Sent: Tuesday, December 28, 2004 2:46 PM
>To: arslist@ARSLIST.ORG
>Subject: Re: AREA LDAP w/ AD
>
>
>Have you tried to connect to the LDAP server with a LDAP client?
>
>Here is a ldap browser:
>http://www-unix.mcs.anl.gov/~gawor/ldap/index.html
>
>--
>Jarl
>
>
>> -----Original Message-----
>> From: Action Request System discussion list(ARSList)
>> [mailto:arslist@ARSLIST.ORG]On Behalf Of Kevin Lanners
>> Sent: 28. desember 2004 21:30
>> To: arslist@ARSLIST.ORG
>> Subject: Re: AREA LDAP w/ AD
>>
>>
>> Thanks everyone. I'm making progress. (I think)
>>
>> The problem seems to be with AD. I don't know much about it
>> but as you saw
>> in my original message the bind isn't working due to "invalid
>> credentials"
>> I've tested the connection through the LDP utility and I get
>> the same error.
>> I've verified the username and password so what permissions
>> does that user
>> need to have. According to the documentation it just states
>> they must have
>> "read permissions". I don't have access to the AD server...
>> How does that
>> translate to what I need to tell the AD admin?
>>
>> Thanks.
>>
>> -Kevin
>>
>>
>>
>> -----Original Message-----
>> From: Action Request System discussion list(ARSList)
>> [mailto:arslist@ARSLIST.ORG] On Behalf Of Luebbe, Tom
>> Sent: Tuesday, December 28, 2004 12:32 PM
>> To: arslist@ARSLIST.ORG
>> Subject: Re: AREA LDAP w/ AD
>>
>>
>> A problem that I just had was that the "user" that I used to
>> authenticate was listed within the OU of NMR\Flordia\Users,
>> but was also
>> listed in the NMR\Service Accounts OU. The latter is the one
>> that I had
>> to use as my distinguished name.
>>
>> Tom Luebbe
>> Nielsen Media Research
>> Oldsmar, FL
>>
>> -----Original Message-----
>> From: Action Request System discussion list(ARSList)
>> [mailto:arslist@ARSLIST.ORG] On Behalf Of James Mckenzie
>> Sent: Tuesday, December 28, 2004 12:59 PM
>> To: arslist@ARSLIST.ORG
>> Subject: Re: [ARSLIST] AREA LDAP w/ AD
>>
>> Kevin:
>>
>> Both should work according to the folks at Remedy. I think that the
>> user should have the appropriate priveledges or you will get errors.
>> Also, make sure the user can actually log into the AD domain
>> appropriately, as passwords can and do get misread.
>>
>> James McKenzie
>>
>> -----Original Message-----
>> From: Kevin Lanners
>> Sent: Dec 28, 2004 9:02 AM
>> To: arslist@ARSLIST.ORG
>> Subject: [ARSLIST] AREA LDAP w/ AD
>>
>> I'm having a problem with the bind with setting up the AREA LDAP
>> configuration with Active Directory.
>>
>> The error in the arplugin.log file is this:
>> Bind:
>> Invalid credentials (LDAPERR Code 49) 80090308: LdapErr:
>> DSID-0C09030F,
>> comment: AcceptSecurityContext error, data 525, vece
>>
>> I've seen conflicting methods of entering the Distinguishing
>> Name in the
>> Config form. One way suggests domain\username another uid=username,
>> ou=xxx, o=zzz
>>
>> I'm waiting to hear back from the AD people about the
>> structure for the
>> second example, but I was wondering if anyone has had this problem, or
>> could validate the DN needed for the bind.
>>
>> Thanks.
>>
>> -Kevin Lanners
>>
>>
>>
>>
>> UNSUBSCRIBE or access ARSlist Archives at http://www.ARSLIST.org
>> (Support: mailto:support@arslist.org)
>>
>>
>> James McKenzie
>> A Proud User of Linux!
>>
>>
>>
>>
>> UNSUBSCRIBE or access ARSlist Archives at http://www.ARSLIST.org
>> (Support: mailto:support@arslist.org)
>>
>>
>>
>>
>> UNSUBSCRIBE or access ARSlist Archives at http://www.ARSLIST.org
>> (Support: mailto:support@arslist.org)
>>
>>
>>
>> UNSUBSCRIBE or access ARSlist Archives at http://www.ARSLIST.org
>> (Support: mailto:support@arslist.org)
>>
>
>

>
>UNSUBSCRIBE or access ARSlist Archives at http://www.ARSLIST.org
>(Support: mailto:support@arslist.org)
>
>

>UNSUBSCRIBE or access ARSlist Archives at http://www.ARSLIST.org
>(Support: mailto:support@arslist.org)

Presuming you can log-in to the AD domain, then your very own network login
credentials may have all the access permissions you need to read LDAP.

Try giving it your network login name and password (you don't necessarily
need to be an AD admin). At my site, the login name I use for the Remedy
ldap integration is my email address and network password, so try different
combinations of login name, email, etc. You might just get lucky!

-JD-


UNSUBSCRIBE or access ARSlist Archives at http://www.ARSLIST.org
(Support: mailto:support@arslist.org)


Top


Moderator:  Matt Reinfeldt