LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Newbie
User Name
Password
Linux - Newbie This Linux forum is for members that are new to Linux.
Just starting out and have a question? If it is not in the man pages or the how-to's this is the place!

Notices


Reply
  Search this Thread
Old 07-13-2016, 07:43 AM   #1
coolkid123
LQ Newbie
 
Registered: Jun 2016
Posts: 15

Rep: Reputation: Disabled
ldap authentication


Hi, we have an existing ldap server in America. And here in our office in Canada, we would like to authenticate clients in our local PC's. How can I connect the ldap server here in our office? We want to authenticate clients on the server. How to configure our ubuntu OS as an ldap client? Kindly help. Thanks.
 
Old 07-13-2016, 07:50 AM   #2
TB0ne
LQ Guru
 
Registered: Jul 2003
Location: Birmingham, Alabama
Distribution: SuSE, RedHat, Slack,CentOS
Posts: 26,685

Rep: Reputation: 7972Reputation: 7972Reputation: 7972Reputation: 7972Reputation: 7972Reputation: 7972Reputation: 7972Reputation: 7972Reputation: 7972Reputation: 7972Reputation: 7972
Quote:
Originally Posted by coolkid123 View Post
Hi, we have an existing ldap server in America. And here in our office in Canada, we would like to authenticate clients in our local PC's. How can I connect the ldap server here in our office? We want to authenticate clients on the server. How to configure our ubuntu OS as an ldap client? Kindly help. Thanks.
You mean HELP AGAIN???:
http://www.linuxquestions.org/questi...on-4175582740/
http://www.linuxquestions.org/questi...on-4175582412/

AGAIN, putting "how to set up ubuntu to authenticate to ldap server" pulls up:
https://help.ubuntu.com/community/LD...Authentication

Opening new threads with the same question (and under a different user ID), doesn't get you different results. AGAIN...it doesn't matter where the server is, as long as it's reachable over the network.
 
Old 07-13-2016, 07:57 AM   #3
coolkid123
LQ Newbie
 
Registered: Jun 2016
Posts: 15

Original Poster
Rep: Reputation: Disabled
The LDAP Server is on another network, or subnet from my local PC. How can I make my local PC and the LDAP Server meet? Or in the same network?
 
Old 07-13-2016, 07:59 AM   #4
pan64
LQ Addict
 
Registered: Mar 2012
Location: Hungary
Distribution: debian/ubuntu/suse ...
Posts: 21,930

Rep: Reputation: 7321Reputation: 7321Reputation: 7321Reputation: 7321Reputation: 7321Reputation: 7321Reputation: 7321Reputation: 7321Reputation: 7321Reputation: 7321Reputation: 7321
looks like you don't read the answers. Can you tell us what kind of response will be accepted?
For me it works - is this a good answer?
Follow the guideline: https://help.ubuntu.com/community/LD...Authentication was posted several times. What is the problem with it?
How can we help you?
 
1 members found this post helpful.
Old 07-13-2016, 08:03 AM   #5
TB0ne
LQ Guru
 
Registered: Jul 2003
Location: Birmingham, Alabama
Distribution: SuSE, RedHat, Slack,CentOS
Posts: 26,685

Rep: Reputation: 7972Reputation: 7972Reputation: 7972Reputation: 7972Reputation: 7972Reputation: 7972Reputation: 7972Reputation: 7972Reputation: 7972Reputation: 7972Reputation: 7972
Quote:
Originally Posted by coolkid123 View Post
The LDAP Server is on another network, or subnet from my local PC. How can I make my local PC and the LDAP Server meet? Or in the same network?
AGAIN, as you've been told in your OTHER threads, and under your other user ID, IT DOES NOT MATTER WHERE THE LDAP SERVER IS. As long as you can query it over the network, then set up your LDAP client as you would for any OTHER PC. You've been handed the documentation several times now, but it appears you're just not reading/understanding the answers.
 
Old 07-13-2016, 08:05 AM   #6
coolkid123
LQ Newbie
 
Registered: Jun 2016
Posts: 15

Original Poster
Rep: Reputation: Disabled
I already succeeded at authenticating my local PC with a local LDAP server. Now, i am trying to authenticate my local PC in our existing LDAP server which is not in the local/ same network. How can i do that? Our LDAP server is not accessed locally. It's in america.

Last edited by coolkid123; 07-13-2016 at 08:07 AM.
 
Old 07-13-2016, 08:12 AM   #7
coolkid123
LQ Newbie
 
Registered: Jun 2016
Posts: 15

Original Poster
Rep: Reputation: Disabled
I still cannot querry it, locally.
 
Old 07-13-2016, 08:12 AM   #8
TB0ne
LQ Guru
 
Registered: Jul 2003
Location: Birmingham, Alabama
Distribution: SuSE, RedHat, Slack,CentOS
Posts: 26,685

Rep: Reputation: 7972Reputation: 7972Reputation: 7972Reputation: 7972Reputation: 7972Reputation: 7972Reputation: 7972Reputation: 7972Reputation: 7972Reputation: 7972Reputation: 7972
Quote:
Originally Posted by coolkid123 View Post
I already succeeded at authenticating my local PC with a local LDAP server. Now, i am trying to authenticate my local PC in our existing LDAP server which is not in the local/ same network. How can i do that? Our LDAP server is not accessed locally. It's in america.
AGAIN.....IT DOES NOT MATTER WHERE IT IS LOCATED!!!!!!!

What part of that is not clear? AGAIN, as you've been asked several times now, in this and your OTHER threads for the exact same question...are you able to query the remote LDAP server from your location? If so...then set it up to use that server, the EXACT SAME WAY you set it up to use the LOCAL server, except change the name/address/port as needed. If you are NOT able to run an LDAP query against the remote server, then (as said before), talk with your network admins and GET ACCESS to it.

EDIT: Then talk to your network admins. You're asking us to provide you with details about your internal network.
 
Old 07-13-2016, 08:26 AM   #9
pan64
LQ Addict
 
Registered: Mar 2012
Location: Hungary
Distribution: debian/ubuntu/suse ...
Posts: 21,930

Rep: Reputation: 7321Reputation: 7321Reputation: 7321Reputation: 7321Reputation: 7321Reputation: 7321Reputation: 7321Reputation: 7321Reputation: 7321Reputation: 7321Reputation: 7321
Quote:
Originally Posted by coolkid123 View Post
I still cannot querry it, locally.
you mentioned you set up a tunnel. Is that right? Does it work properly (or as expected)?

I have no idea how can I connect to an ldap server in america.... without information about how it is configured, how can I reach it ....
 
1 members found this post helpful.
Old 07-13-2016, 07:48 PM   #10
coolkid123
LQ Newbie
 
Registered: Jun 2016
Posts: 15

Original Poster
Rep: Reputation: Disabled
How can i set up a tunnel correctly?? Please help.. The netadmins here said that i should use port forwarding, ldap server uses port 389.
 
Old 07-13-2016, 08:24 PM   #11
coolkid123
LQ Newbie
 
Registered: Jun 2016
Posts: 15

Original Poster
Rep: Reputation: Disabled
My main problem is i cannot connect my local machine to our ldap server. I cannot authenticate it.
 
Old 07-14-2016, 12:45 AM   #12
pan64
LQ Addict
 
Registered: Mar 2012
Location: Hungary
Distribution: debian/ubuntu/suse ...
Posts: 21,930

Rep: Reputation: 7321Reputation: 7321Reputation: 7321Reputation: 7321Reputation: 7321Reputation: 7321Reputation: 7321Reputation: 7321Reputation: 7321Reputation: 7321Reputation: 7321
just googling this is the first hit:
http://inside.mines.edu/fs_home/gmur.../sshNotes.html
Read that page carefully and try to follow the process (also you can try another page). Post if you stuck somewhere, but please post what have you tried too!
Quote:
I cannot authenticate it
and similar answers will not help YOU to go further.
 
Old 07-14-2016, 07:19 AM   #13
TB0ne
LQ Guru
 
Registered: Jul 2003
Location: Birmingham, Alabama
Distribution: SuSE, RedHat, Slack,CentOS
Posts: 26,685

Rep: Reputation: 7972Reputation: 7972Reputation: 7972Reputation: 7972Reputation: 7972Reputation: 7972Reputation: 7972Reputation: 7972Reputation: 7972Reputation: 7972Reputation: 7972
Quote:
Originally Posted by coolkid123 View Post
How can i set up a tunnel correctly?? Please help.. The netadmins here said that i should use port forwarding, ldap server uses port 389.
So why AREN'T YOU DOING IT??? 389 is the unsecured port, and 636 is the secure port. Since you STILL (after two threads as this user, and one as your OTHER user), don't tell us version/distro of Linux you're using, or what kind of firewall/router/switch/whatever is between you and the other server, what do you think we'll be able to tell you? The VERY FIRST HIT in Google for "port forwarding iptables" is:
https://www.digitalocean.com/communi...-with-iptables

...complete with examples. If you're the administrator at your site, this should be something easy for you to do. If you're NOT, then ask your network admins to help you.
Quote:
Originally Posted by coolkid123
My main problem is i cannot connect my local machine to our ldap server. I cannot authenticate it.
Right...which is the same thing you've posted in three threads now. Re-stating it doesn't tell us anything new.
 
Old 07-15-2016, 07:47 AM   #14
sundialsvcs
LQ Guru
 
Registered: Feb 2004
Location: SE Tennessee, USA
Distribution: Gentoo, LFS
Posts: 10,671
Blog Entries: 4

Rep: Reputation: 3945Reputation: 3945Reputation: 3945Reputation: 3945Reputation: 3945Reputation: 3945Reputation: 3945Reputation: 3945Reputation: 3945Reputation: 3945Reputation: 3945
Gentlebeings, for all we know, this exceptionally-unmotivated person could be a bot. Shouting at him won't turn his head(-lights) on.

There are basically only three possibilities to consider here:
  1. The IP-address of the LDAP server might, in fact, be incorrect.
  2. A firewall anywhere along the route could be blocking LDAP traffic, or refusing to accept such traffic from this "unexpected by it" IP address. (This is a wise precaution to take ...)
    • If a VPN is being used, then it, too, has traffic-filtering capability.
    • If the firewall rule is to DROP the packet rather than to REJECT it, "the packet simply disappears."
    • If the server is also programmed not to respond to "pings," its very presence on the network is difficult to detect.
  3. The server is, in fact, being contacted, but it is not responding as the OP expects, and the OP either does not know how to diagnose the problem or has not yet bothered to do so.

Network services find no reason to "be helpful" to someone or something that they consider might be an intruder or an attacker. If the managers of the LDAP configuration in America have done their homework, it certainly won't be.

Of course, what the OP should do is to contact his colleagues in America for assistance, not to keep asking questions here.

Last edited by sundialsvcs; 07-15-2016 at 07:49 AM.
 
Old 07-15-2016, 11:40 AM   #15
crazy-yiuf
Member
 
Registered: Nov 2015
Distribution: Debian Sid
Posts: 119

Rep: Reputation: 51
Quote:
389 is the unsecured port, and 636 is the secure port.
According to the documentation I've been reading lately this is deprecated, kind of like implicit FTPS. So it depends on the setup. /nitpick
 
  


Reply

Tags
authentication, client, ldap



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
[LDAP] -Setup Ldap for user authentication based on time trung1490 Linux - Server 1 02-23-2016 12:53 PM
[SOLVED] LDAP authentication error [Can't contact LDAP server] from apache httpd jonathan_w_brown Linux - Server 6 12-28-2011 05:30 PM
What are my options to enable LDAP authentication for certain LDAP users? ghost_dancer999 Linux - Security 1 10-18-2011 01:41 AM
Authentication Failure in LDAP after the Modification of ldap to ldaps url vijith.pa@gmail.com Linux - Newbie 3 06-03-2011 05:30 AM
[SOLVED] Apache authentication: allow LDAP group OR user named guest, but not all LDAP users AlucardZero Linux - Server 1 05-25-2011 03:21 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Newbie

All times are GMT -5. The time now is 06:43 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration