asommer 04-13-2007 02:46 PM

Apache LDAP Group

I've configured Apache to use LDAP to authenticate users, and it works great. What I want to do is restrict access to users in a specific group. I've added the directives that I believe will do that, but everything I've tried still lets any user login.

I've followed the info here:

I'm using a Gentoo 2006.1 system with Apache 2.0.58 and an OpenLDAP 2.2.13 server.

This is my config:


<IfDefine SVN>
  <IfModule !mod_dav_svn.c>
    LoadModule dav_svn_module  modules/
  <Location /svn>
    DAV svn
    SVNPath /var/svn/
    AuthType Basic
    Options Indexes FollowSymLinks
    AllowOverride None
    order allow,deny
    allow from all
    AuthName "Authorize Me"
    AuthLDAPURL ldaps://,dc=edu?uid?sub?(objectClass=posixAccount)
    AuthLDAPBindDN "cn=Manager,dc=salem,dc=edu"
    AuthLDAPBindPassword password
    Require valid-user
    SVNIndexXSLT "/svnindex.xsl"
  #AuthLDAPGroupAttribute uniqueMember
    AuthLDAPGroupAttributeIsDN on
    Require group cn=SVNGroup,ou=Groups


Any ideas and/or links to other documentation is greatly appreciated.

