Re: [External] LDAP authentication failed

From: Pierre Ochsenbein <pierreochsenbein(at)gmail(dot)com>
To: Vijaykumar Jain <vjain(at)opentable(dot)com>
Cc: pgsql-admin <pgsql-admin(at)postgresql(dot)org>
Subject: Re: [External] LDAP authentication failed
Date: 2019-05-09 09:10:37
Message-ID: CABG8FoO9JM8EEK_-_KqSERU2Sd8TpjtTiWv=diEJ+u1UCuy9pA@mail.gmail.com
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-admin

Sorry I have just adapt the IP Adresse in the email. The IP looks fine.

Le jeu. 9 mai 2019 à 11:11, Vijaykumar Jain <vjain(at)opentable(dot)com> a écrit :

> 10.1.1.18/32 would only allow one host ip ( 10.1.1.18 ) to connect from.
> "10.1.1.181" will fail i think.
>
>
>
> Regards,
> Vijay
>
> On Thu, May 9, 2019 at 1:53 PM Pierre Ochsenbein
> <pierreochsenbein(at)gmail(dot)com> wrote:
> >
> > Hello
> >
> > I'm running on PostgreSQL 10.6 and would like to connect with LDAP users.
> > I have sync all users from my group in my database.
> > I can connect when I use auth "trust" in pg_hba but I would like to
> connect remotely with AD password and I have this error:
> > SSL is ON in postgresql.conf
> >
> > FATAL: LDAP authentication failed for user "userA" FATAL: no pg_hba.conf
> entry for host "10.1.1.181", user "userA", database "DB01", SSL off
> >
> > pg_hba.conf:
> >
> > hostssl all all 10.1.1.18/32 ldap
> ldapurl="ldap://ldap.local/OU=ASA,OU=Forest%20Admin%20Accounts%20%26%20Roles,DC=ASATL,DC=NET?sAMAccountName?sub"
> ldaptls=1 ldapbinddn="CN=POSTGRES,OU=Service Accounts,OU=Global,OU=Member
> Servers,DC=PMINTL,DC=NET" ldapbindpasswd='password001'
> >
> >
> > I need to put the Group AD in ldap query line in pg_hba file?
> >
> >
> > Thanks
> >
>

--
Cordialement,

*Pierre Ochsenbein*
Mobile: +33668295394
pierreochsenbein(at)gmail(dot)com

In response to

Browse pgsql-admin by date

  From Date Subject
Next Message Laurenz Albe 2019-05-09 11:42:06 Re: LDAP authentication failed
Previous Message Vijaykumar Jain 2019-05-09 09:10:33 Re: [External] LDAP authentication failed