External Active Directory Authentication

Discuss your pilot or production implementation with other Zimbra admins or our engineers.
Post Reply
markb
Posts: 8
Joined: Thu Jul 14, 2016 8:48 am

External Active Directory Authentication

Post by markb »

Hi,
I have configured external AD authentication, it is working fine but because I am migrating from an existing MS Exchange, i found some limitations.
I Exchange i can have email address different from active directory user name, now I have to be able to replicate this condition.
For example
AD User: rossim
Exchange mail: rossi.mario@mail.com

Now in zimbra if i create the mail "mario.rossi@mail.com" i can't of course authenticate because mario.rossi is not the AD username.
User avatar
AndreasB
Posts: 5
Joined: Wed Jul 13, 2016 12:06 pm
Location: Germany

Re: External Active Directory Authentication

Post by AndreasB »

I having more or less the same issue. I do authenticate by external LDAP and switched Auto Provisioning on Zimbra side.
The Users on the external LDAP are usually like

LDAP DN
uid=uid1,ou=People,o=domain.tld,o=isp
mail=First.Last@domain.tld

Unfortunately the auto provisioning create a zimbra user but the mail on zimbra is uid1@domain.tld
Furthermore I observed you can not do an Attribute Map by the auto provisioning as zimbra always
tell me 'immutable'

What is the best practice here? I believe this is a common LDAP setup.
markb
Posts: 8
Joined: Thu Jul 14, 2016 8:48 am

Re: External Active Directory Authentication

Post by markb »

Take a look here ( https://wiki.zimbra.com/wiki/External_L ... ExternalDn ), it seem to do in my case.
I will try it tomorrow and i will give a feedback.
Post Reply