Problem with active directory authentication

asked 2014-03-12 13:50:55 -0600

sam gravatar image

updated 2014-03-12 17:13:07 -0600

Stefan gravatar image

Problem with active directory authentication. Enabling active directory authentication overrides local authentication. (i.e I am unable to log in with my local credentials). Is there a reason for this? I edited the code below with my information and replaced objectClass = person with bbjectClass= user. If anyone has another way of doing this please advice.

  - class: CASServer::Authenticators::ActiveDirectoryLDAP
      port: 389
      base: dc=example,dc=net
      filter: (objectClass=person)
      auth_user: authenticator
      auth_password: itsasecret
can you please clarify about what product you are talking about? Is this some application you deploy with puppet, or a puppet application itself (like puppet dashboard or puppet console)

Stefan ( 2014-03-12 14:27:17 -0600 )

I am setting up active directory authentication on a test environment for PE 3.2 where all the components like db, console and master are installed on the same box.

sam ( 2014-03-12 15:30:37 -0600 )

I have been following the steps to configure active directory based on the documentation provided on the website. But the moment I uncomment the AD section in config.yml my ...(more)

sam ( 2014-03-12 15:32:25 -0600 )

I guess you are referring to Have you replaced the CASServer::Authenticators::SQLEncrypted section (like your pasted configuration suggest) or merely ...(more)

Stefan ( 2014-03-12 17:16:03 -0600 )

I did not replace CASServer::Authenticators::SQLEncrypted section, I just added the authentication section for the active directory below it. Which is why I don't understand why it bypasses ...(more)

sam ( 2014-03-12 18:15:39 -0600 )

answered 2014-03-17 17:17:25 -0600

chsnell gravatar image

updated 2014-03-17 17:34:30 -0600

Stefan gravatar image

You need to make the authenticator piece an array in the rubycas-server/config.yml file. Make sure the local authentication section is not commented out, then uncomment your AD section, but leave the "authenticator:" line commented, and that should work for you. You'll probably want the local authentication database before the AD section.

Asked: 2014-03-12 13:50:55 -0600

Seen: 540 times

Last updated: Mar 17 '14