Results 1 to 3 of 3

Thread: External authentication against Distribution List - possible?

  1. #1
    Join Date
    Jul 2007
    Posts
    10
    Rep Power
    8

    Default External authentication against Distribution List - possible?

    Hello, all.

    I have installed Zimbra 4.5 on a new, fully-updated, 32-bit CentOS 5 server with no apparent problems. I have checked that the basic collaborative features work as advertised. Nice product -- strong integration work! In fact, from an "truly open framework" perspective, there is only one serious feature I need that Zimbra seems to lack: the ability for external systems to authenticate users by group, which I guess means by Distribution List.

    As far as I can tell, the only way Zimbra aggregates users is into Distribution Lists (a confirmation of this would be appreciated). it seems that with the "User object", a generous amount of the data is kept in LDAP, mostly in standard schema objects, so that external software services can access it in a standard way. Any extra Zimbra-specific user information is stored in MySQL, I presume. Sadly, this entirely sensible model was not followed in the design of the "Group Object", which seems to be stored entirely in MySQL, despite the fact that the groupOfUniqueNames LDAP object type is now ubiquitous and well-supported.

    I have tried using the Zimbra-LDAP-Posix extensions to get some kind of group data into Zimbra-LDAP, but even when I create a SMB domain, some Posix groups, and try to group some users, I get two problems:

    1. In the Zimbra administration UI, there appears to be no way to assign a user to more than one Poisx group. Can this really be true? Can this limitation be overcome by editing the data store more directly?
    2. Even when I assign a Zimbra account to a (single) Posix group, I cannot find where this information is encoded in the LDAP database! Is it there? How does PAM get your POSIX group info solely from LDAP (query examples would be appreciated)?


    I need to secure lots of web-based content using apache, enough content that managing a separate user access for each resource is out of the question -- group-based access is required.
    So my question is this: is there any way to use Zimbra to model groups of users (as Distribution Lists, Posix groups, or anything else!) in the LDAP database alone?

    If yes, how? If not, how do veteran Zimbrans make apache authorize users against Zimbra?

    Thanks in advance for your advice.
    - benton

  2. #2
    Join Date
    Oct 2009
    Location
    australia
    Posts
    33
    Rep Power
    6

    Default

    Did you ever get this working?
    I am authenticating a wiki against zimbra, but its not seeing any groups or distrobution lists memberships.

  3. #3
    Join Date
    Mar 2007
    Location
    Plymouth, uk
    Posts
    93
    Rep Power
    8

    Default

    Groups are not stored at the user level in ldap, the group has member: userx though - I have set up apache with group auth but cant find any configs atm - though this should help Linux.com :: Apache authentication and authorization using LDAP, be careful with the "AuthLDAPGroupAttribute memberUid" - zimbra uses zimbraMailForwardingAddress as the group attribute.

    To see the ldap groups you have set up: ldapsearch -h yourzimbraserver -x objectClass=zimbraDistributionList should work

Similar Threads

  1. Distribution list in external GAL
    By strobhen in forum Administrators
    Replies: 5
    Last Post: 05-30-2007, 03:00 PM
  2. Authentication to external ldap stop working.
    By jahaj in forum Installation
    Replies: 3
    Last Post: 12-05-2006, 03:17 PM
  3. Reply To for Distribution List
    By alivebyscience in forum Administrators
    Replies: 3
    Last Post: 10-28-2006, 11:35 AM
  4. Orphaned alias for a distribution list
    By area in forum Administrators
    Replies: 0
    Last Post: 09-17-2006, 09:22 PM
  5. Distribution list problem
    By achow in forum Users
    Replies: 1
    Last Post: 05-15-2006, 09:45 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •