Welcome, Guest. Please login or register.
Did you miss your activation email?
May 26, 2012, 08:36:57 PM

Login with username, password and session length
Search:     Advanced search
Wollen Sie dem WebsiteBaker Team beitreten?
Nähere Informationen finden Sie unter hier und auf unserer neuen Webseite.
155552 Posts in 21715 Topics by 7737 Members
Latest Member: gx-world
* Home Help Search Login Register
Pages: [1]   Go Down
Print
Author Topic: [MODULE] Ldap-Login  (Read 270 times)
pcwacht
AddOn Development
*
Offline Offline

Posts: 2859



WWW
« on: September 28, 2011, 08:00:07 AM »

With this module one could sync users between LDAP (Windows AD) and WB.
I wrote it since I need it Wink

This module needs wb282, it won't work with wb281 or less!!


Module is type page and shows loginform, user enters data, data is validated against WB users.
If user is validated:
- user is new for wb, wb user record is created
- use exists, wb user record is updated
Then user data is handed over to WB - authenticate

In backend following must be entered:
LDAP Serveraddress -> could be IP or DNS for one of the DC's, it must ofcourse be found from webserver
LDAP DN -> Distinguised Name, could contain OU or CN
LDAP Userlogon extention -> The @server.domain.com
LDAP Port -> Should be 389 in most cases
USER email addition -> the @server.com part of the email address will be appended to the username entered
Redirect to -> If login succeed, redirect to...

Next to these there is an option to enter 3 groups:
LDAP Usergroup to WB Usergroup -> if user exists in ldapgroup, the wbgroup will be set.

Have fun,
John

« Last Edit: September 28, 2011, 08:10:05 AM by pcwacht » Logged

http://www.ictwacht.nl = Dutch ICT info
http://www.pcwacht.nl = My first
both still work in progress, since years.....
pcwacht
AddOn Development
*
Offline Offline

Posts: 2859



WWW
« Reply #1 on: September 28, 2011, 08:08:53 AM »

For those who like pictures Wink
Logged

http://www.ictwacht.nl = Dutch ICT info
http://www.pcwacht.nl = My first
both still work in progress, since years.....
Ruud
WebsiteBaker Org e.V.

Offline Offline

Posts: 2297



WWW
« Reply #2 on: September 28, 2011, 09:15:00 AM »

Don't need it, but it sounds great..

Are local users deleted if they are not validated through LDAP? (Personnel leaving the company)
Logged

Professional WebsiteBaker Solutions
pcwacht
AddOn Development
*
Offline Offline

Posts: 2859



WWW
« Reply #3 on: September 28, 2011, 09:33:48 AM »

Nope. There is no synchronization between AD and WB, but
you need to be validated through AD before you can get into WB, unless you login through WB self.

If you need it, one can write a droplet wich deletes or set all users inactive who hasn't logged in for a time.
Thus removing the option of logging in through WB.

John
Logged

http://www.ictwacht.nl = Dutch ICT info
http://www.pcwacht.nl = My first
both still work in progress, since years.....
Ruud
WebsiteBaker Org e.V.

Offline Offline

Posts: 2297



WWW
« Reply #4 on: September 28, 2011, 09:57:33 AM »

Don't need it, but it sounds great..

I was just wondering.
Logged

Professional WebsiteBaker Solutions
Pages: [1]   Go Up
Print
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.16 | SMF © 2011, Simple Machines Valid XHTML 1.0! Valid CSS!