Discussions
Categories
Groups
Community Home
Categories
INTERNAL ENABLEMENT
POPULAR
PUBLIC CLOUD
PRIVATE CLOUD
Quick Links
MY LINKS
HELPFUL TIPS
Back to website
Home
Web CMS (TeamSite)
LDAP protocol incorrect ?
nipper
This was an ugly one. All of a sudden no users could authenicate through TS.
Our LDAP manager had changed the config not to allow multiple binds per connection
(which is consistant with V2 of the LDAP RFC). V3 of the LDAP spec allows
this (which is also rather new).
This change was due to another issue, of course it brought 300 contributors to their
knees.
We have TS 552 SP4 with Solaris 2.8 and SunOne 5.2 LDAP.
Any LDAP experts out there know any details ?
Andy
Find more posts tagged with
Comments
Migrateduser
TeamSite goes through a real simple connect/bind/search sequence for each ldap query it makes. It does not do multiple binds per connection. In order to ensure compatibility with a wide variety of LDAP servers, most TeamSite servers will bind using LDAPv2. Most LDAPv3 servers allow both v2 and v3 binds by default. If your LDAP server has been configured to disallow v2 connections, you may see problems with TeamSite.
In any event, you should see enough information to diagnose the problem in your Sun One LDAP access logs. TeamSite binds are either done anonymously, or, if it is specified in iw.cfg, using the DN given by 'ldap_account' in the 'authentication' section. Assuming that you're using LDAp as a naming service for Solaris, you'll see a lot of LDAP queries from Solaris in your LDAP logs along with those made by TeamSite. Solaris binds typically use a bind account called 'proxyagent', so you can usually distinguish queries made by the OS from those made by TeamSite by looking at the account name on each connection.
Al Borr
Interwoven Engineering
Migrateduser
I checked TS5.5.2SP4. It's new enough that it does an LDAPv3 bind by default, so the v2 vs v3 thing I mentioned
in my earlkier post shouldn't be an issue for you.
Al Borr
Interwoven Engineering
nipper
>I checked TS5.5.2SP4. It's new enough that it does an LDAPv3 bind by default, so the v2 vs v3 thing I mentioned
>in my earlkier post shouldn't be an issue for you.
Well V3 allows the multiple binds (which is what my LDAP guy said happened) but we are on V2
which doesn't.
So I guess this makes sense. have to bounce it back to the LDAP guy, he cannot disallow that like he wanted to.
Andy