Loading...
 
LDAP / Active directory

LDAP / Active directory


Tiki and LDAP authentication

Hi,

I installed the "Tiki and PEAR::Auth" authentication method for my Tikiwiki 1.9.8. It's running very well with the authentication LDAP against AD but the users directly registered on the Tiki can't login.

Is it possible to have the both methods, Tiki and LDAP, coexisting?

Thanks in advance,
venap

United States

> Hi,
>
> I installed the "Tiki and PEAR::Auth" authentication method for my Tikiwiki 1.9.8. It's running very well with the authentication LDAP against AD but the users directly registered on the Tiki can't login.
>
> Is it possible to have the both methods, Tiki and LDAP, coexisting?
>
> Thanks in advance,
> venap

Hi venap,
i don't have an answer to your your question, but as far as I can see you are the only one succeeded to make authentication LDAP against AD working. I can't make it working and so the other, as far as I can tell from other posts. Would you mind to share what exactly changes/settings you made, would appreciate any comment.

edabxv

United States

> > Hi,
> >
> > I installed the "Tiki and PEAR::Auth" authentication method for my Tikiwiki 1.9.8. It's running very well with the authentication LDAP against AD but the users directly registered on the Tiki can't login.
> >
> > Is it possible to have the both methods, Tiki and LDAP, coexisting?
> >
> > Thanks in advance,
> > venap
>
> Hi venap,
> i don't have an answer to your your question, but as far as I can see you are the only one succeeded to make authentication LDAP against AD working. I can't make it working and so the other, as far as I can tell from other posts. Would you mind to share what exactly changes/settings you made, would appreciate any comment.
>
> edabxv

venap: this is an eaither/or setup. LDAP or Tiki, not a mix of both. The admin is a special case if you tic the "just use Tiki auth for admin" which I highly recommend.

edabxv:
What version of Tiki are you running? 1.10 has the native AD options 'built in'

\\Greg


I have LDAP working fine. and Registered user works fine to!
The problem I see is this:
User Registers, using LDAP user ID, but a different password.
All is ok, but when they log in, it uses the typed in password but not th eLdap password. and in the Admin, there is no way to change this, it says, authentication is passed to LDAP, that is fine too, but what I would expect is,
A user Registers, selects the group they are in, if LDAP is Enabled, then no need to ask password, and let the other options take presendence, such as administrator approval etc.
If the user does not register, and logs straight in, this works as expected, but assigned to the default group, it would be nice to allow a user who logs i for the first time, to be presented with a group selection to fit them to a group, and then the Admin can do the usual approval. Also in this case, no Email is sent to admin, so the trigger for administrative control is not there.
My company has took my recomendation to use Tiki to replace all the Sharepoint, and internal collaboration site. and it is the largest Retail company in Asia.
Any solution to the Above conundrum? all I can think of it to turn of the Registration option. but all users can only enter the system as a lowly user, and the admin will not know what team this user is from, were as the registration option asks the user to select the group, and this can be the trigger for admin to obtain approval from that team, BUT, not matched against AD (LDAP) EEK.