LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Server
User Name
Password
Linux - Server This forum is for the discussion of Linux Software used in a server related context.

Notices


Reply
  Search this Thread
Old 08-15-2012, 06:29 PM   #1
Felipe
Member
 
Registered: Oct 2006
Posts: 302

Rep: Reputation: 32
Chaining Openldap to Active Directory


Hello:

I'm using Openldap. But I want to chain some searches to Active Directory.
Example:
Quote:
- domain.com --> Entities stored in Openldap.
- ad.red -- > Entities stored in Active Directory.
What I try is to use openldap as a front-end that solves queries of domain.com an ad.red (chaining).
- Can any tell me how can be configured openldap for this (don't need secure connections with ldaps).
And a second question:
- Can any tell me how to pass authentication from opemldap to Active Directory using users/password and/or kerberos?

Thanks
 
Old 08-15-2012, 07:21 PM   #2
ferricoxide
LQ Newbie
 
Registered: Nov 2010
Posts: 12

Rep: Reputation: 0
Quote:
Originally Posted by Felipe View Post
Hello:

I'm using Openldap. But I want to chain some searches to Active Directory.
Example:


What I try is to use openldap as a front-end that solves queries of domain.com an ad.red (chaining).
- Can any tell me how can be configured openldap for this (don't need secure connections with ldaps).
And a second question:
- Can any tell me how to pass authentication from opemldap to Active Directory using users/password and/or kerberos?

Thanks
Not exactly sure what you're referring to by "chaining".

At any rate, Active Directory is an LDAP system (granted, it's also Kerberos extensions to it, but still...). As such, you can query AD with the standard LDAP tools so long as you have an account in the directory to proxy your requests with. So, treat it like any other LDAP source - use the normal extensions to OpenLDAP that you would for any multi-source query system.

You'd probably want to look at OpenLDAP's "meta" backend for linking multiple LDAP sources into a common query-space.
 
Old 08-16-2012, 04:44 PM   #3
Felipe
Member
 
Registered: Oct 2006
Posts: 302

Original Poster
Rep: Reputation: 32
Thanks for reply:

When I talk about chaining is about: http://www.openldap.org/doc/admin24/....html#Chaining.

But there it talks about configuring slave ldap and I think that it can be done configuring them master to send requests to slaves (I can't modify Active Directory configuration).
I try to configure openldap to work as a proxy for different ldaps, including Active Directory. All requests are received by openldap which has the data or knows where the data is stored and asks for it and sends it to the client.

I've found different pages talking about it, but I've not been able to make it work. So I'd like to know if someone has been able to do it and how.

Thanks again
 
  


Reply

Tags
active directory, openldap



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
OpenLDAP and Active Directory Integration verve13 Linux - Server 18 09-22-2011 03:25 PM
OpenLDAP query Active Directory noir911 Linux - Server 0 04-30-2008 06:18 AM
OpenLDAP and Active Directory custangro Linux - Enterprise 1 01-05-2008 01:55 AM
Active Directory vs. OpenLDAP msteiner Linux - Software 1 10-30-2007 12:09 PM
openldap and active directory akismax Linux - Enterprise 1 07-21-2006 05:50 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Server

All times are GMT -5. The time now is 01:30 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration