| From: | srijith s <udbdoctor(at)gmail(dot)com> |
|---|---|
| To: | pgsql-admin(at)lists(dot)postgresql(dot)org |
| Subject: | Postgers AD authentication on windows server |
| Date: | 2021-03-04 18:14:15 |
| Message-ID: | CACReZzyhDOnUYpcieSvXkbi0YnRWjEJdvmfGSv6OnuwJYsJ13Q@mail.gmail.com |
| Views: | Whole Thread | Raw Message | Download mbox | Resend email |
| Thread: | |
| Lists: | pgsql-admin |
Dear Admin's,
I am not a postgres expert and struggling with postgres AD authentication
on my windows server. Any help will be highly appreciated.
My users spread across different AD Organization Units
If I put pg_hba entry like below , it will search for all users in the *first
container* and stop the search there.All users in the first container will
be authenticated and can access the db.
I think that the expected behavior since i put "all" for users
host all all all ldap ldapserver=adserver1.mycomp.com ldapprefix="cn="
ldapsuffix="*,OU=appusers,DC=mycomp,DC=com"*
host all all all ldap ldapserver=adserver1.mycomp.com ldapprefix="cn="
ldapsuffix=",OU=dbusers,OU=Users,OU=mycomp,DC=mycomp,DC=com"
host all all all ldap ldapserver=adserver1.mycomp.com ldapprefix="cn="
ldapsuffix=",OU=testers,OU=mycomp,DC=mycomp,DC=com"
If i put it like below it will search in all OU's and the
authentication works fine for all users in all OU's, but i have to find the
users under each OU and *create separate files with those user names in it.*
host all *(at)LDAP(dot)OU(dot)APPUSERScontainerallusr(dot)txt* all ldap ldapserver=
adserver1.mycomp.com ldapprefix="cn="
ldapsuffix=",OU=appusers,DC=mycomp,DC=com"
host all *(at)LDAP(dot)OU(dot)DBUSERScontainerallusr(dot)txt* all ldap ldapserver=
adserver1.mycomp.com ldapprefix="cn="
ldapsuffix=",OU=dbusers,OU=Users,OU=mycomp,DC=mycomp,DC=com"
host all *(at)LDAP(dot)OU(dot)TESTERScontainerallusr(dot)txt * all ldap ldapserver=
adserver1.mycomp.com ldapprefix="cn="
ldapsuffix=",OU=testers,OU=mycomp,DC=mycomp,DC=com"
I think it's the similar issue mentioned in the Link, is there a way that
all users can be authenticated by just putting the last part of the suffix
or something ?
https://www.postgresql.org/message-id/4D64E4E1.7000107@compulab.co.il
Thanks in Advance
Sri
| From | Date | Subject | |
|---|---|---|---|
| Next Message | RAJAMOHAN | 2021-03-05 07:03:48 | could not load library "$libdir/plpython2" while upgrading from postgresql-10 to 12 |
| Previous Message | Tom Lane | 2021-03-04 15:29:33 | Re: Different encodings and locales on one machine |