Mrpower Posted October 11, 2022 Posted October 11, 2022 I have been trying to setup communication between our Smoothwall S4 box and our OpenLDAP server ( Mac Server). According to the Status all is connected but when I check the status by clicking on the diagnostics check, the results keep telling me that the "Group List can be retrieved" but the status is red and it tells me that " this might be due to permissions being wrong or the provided group search root is invalid". Yet all the details are correct and I have tried different combinations of "cn=mygroups,dc=Server,dc=local" "ou=mygroups,dc=server,dc=local," all to no success. Anyone know what the problem might be?
ibpalle Posted October 11, 2022 Posted October 11, 2022 What is the domain name? server.local? You could try just adding dc=local and see if it catches everything below that and work down from there. There are limited authentication options though - I think we are down to just being able to use the login page with that type of directory.
Mrpower Posted October 11, 2022 Author Posted October 11, 2022 I am in the in services, directories, and this is the diagnostics information I receive. I have successfully added google g-suite as a directory but it would be useful to have the local authentication as well.
Mrpower Posted October 12, 2022 Author Posted October 12, 2022 (edited) Not sure what's changed but its now recognising the LDAP accounts and logging in. My next question would be. Anyone know how to set up synchronised login on the device with login on the smoothwall proxy, with a mdm server? Edited October 12, 2022 by Mrpower
ibpalle Posted October 13, 2022 Posted October 13, 2022 It may be possible to create a Kerberos keytab file for the domain and upload that to the Smoothwall in Services » Authentication » Kerberos keytabs - the help contains a lot of info for this page. Once done, use the Kerberos script you can download from https://download.smoothwall.net/support/. How to go about creating a keytab for the OpenLDAP domain and make sure DNS and domain names are resolved correctly will likely be an adventure though.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now