Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×
  • entries
    60
  • comments
    63
  • views
    837

extreme brain strain


it's just one thing after another!

 

installed wordpress on xampp on server 2003.

Found a good plugin for active directory authentication. (2nd one i tried)

WordPress › Active Directory Integration « WordPress Plugins

 

figured out I needed to use .htaccess to limit site to teachers only.

found out about ad authentication & htaccess.

been fiddling with for hours; fixed some problems.

 

# Authentication realm and method:
AuthType Basic
AuthName "LDAP Auth"
AuthBasicProvider ldap
AuthUserFile /dev/null 
AuthBasicAuthoritative Off 

# DN of Active Directory server
AuthLDAPUrl ldap://x.xxxxxxx.lancs.sch.uk:389/DC=xxxxx,DC=lancs,DC=sch,DC=uk??base?(objectClass=*)

# An account in the AD that has enough permissions to perform an LDAP search
#AuthLDAPBindDN "CN=xxx,OU=pupils,OU=other accounts,DC=xxxx,DC=lancs,DC=sch,DC=uk"
AuthLDAPBindDN [email protected]
AuthLDAPBindPassword xxxxx

# The following would also be valid, although not truly LDAP compliant
#AuthLDAPBindDN ADS\\yrodrigu
#AuthLDAPBindDN [email protected]

# When checking for group membership, use the DN of the user, not the HTTP entry
AuthLDAPGroupAttributeIsDN on

# Require groups, specifying the DN of the security group
require ldap-group CN=teachers,OU=Staff,DC=xxxx,DC=lancs,DC=sch,DC=uk
require ldap-group CN=Domain Admins,OU=Admins,DC=xxxxx,DC=lancs,DC=sch,DC=uk

 

stuck with the errors

[Thu Jul 01 09:36:52 2010] [warn] [client 192.168.x.x] [6848] auth_ldap authenticate: user xxxx authentication failed; URI /wordpress [ldap_search_ext_s() for user failed][Operations Error]

[Thu Jul 01 09:36:52 2010] [error] [client 192.168.x.x] access to /wordpress failed, reason: verification of user id 'xxx' not configured

 

using wireshark to try and find some more information about what's not working

realised I need to filter out remote desktop traffic (TPKT)

 

currently: trying to work out what capture filter syntax to use.....

3 Comments


Recommended Comments

browolf

Posted (edited)

capture filter: tcp port 389

 

after fixing the error of not being able to find the AuthLDAPBindDN user

 

now it appears to be searching for

"cn=configuration, dc=domain,dc=lancs,dc=sch,dc=uk"

 

that isnt in active directory with view advanced features turned on.

 

and then having an operations error

LdapErr: DSID-0C090627, comment: In order to perform this operation a successful bind must be completed on the connection., data 0, vece

Edited by browolf
browolf

Posted

its also searching for "cn=domaindnszones, dc=domain,dc=lancs,dc=sch,dc=uk"

which causes the same error...

 

domaindnszones and configuration are present and working in softerra ldap browser tho...

browolf

Posted

it's definitely binding successfully, it only fails when it searches for domaindnszones and configuration

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...