TEM 8.2, LDAP authentication against a huge Active Directory

(imported topic written by RolfWilhelm)

Hello everybody,

I am trying to establish LDAP operators instead of TEM own operators, but I am failing in production.

It works against a small AD (test environment), but not against the production AD. It’s not a DNS issue and the test while creating the LDAP Directory definition is fine. It’s displaying a time out error while searching for/create new operator:

LDAP Search Failed

Search files on “”: Fail to search to the directory:

Time Limit Exceeded (error HTTP 503 in method /data/ad-list-data-search)

It would be also nice to limit the LDAP directory entry to specific OU only, didn’t found a working way to do this as the “Base DN” field seems to accept only the domain description but no additional OU parameters.

Thanks,

Rolf.

(imported comment written by SystemAdmin)

I have mine set up for a specific OU. My Base DN looks like: OU=GulfSoft Users,DC=gulfsoft,DC=local

The domain is: gulfsoft.local

The OU is: Gulfsoft Users

The OU is at the root level, if it were buried in a couple sublevels down, I would have to include those in the base DN also.

HTH.

Martin Carnegie

Gulf Breeze Software Partners

http://www.gulfsoft.com

(imported comment written by RolfWilhelm)

Hi Martin,

thank you very much.

I was sure that I tried it as you wrote, but it looks I made something wrong.

Now it works. I have specified the OU from which my TEM Admins will come from and as this is only a very small subset of the whole domain, there is also no time out any more.

Works as expected!

Thanks,

Rolf.

(imported comment written by Bhushan Chirmade)

We have faced similar issue and it got resolved by following 2 things:

  1. Set the LDAP directory as global catalog

  2. Search the user with option “Starts with” instead of “Contains”

We specifically asked to add this enhancement so speed up the user search process.

Regards,

Bhushan

(imported comment written by RolfWilhelm)

Bushan,

thank you very much for the feedback, it was me not giving any further updates.

  1. All my LDAP servers (domain controllers) are global catalog servers

  2. I reduced the amount of stuff to search through by specifying an OU (OU=xyz, DC=…)

  3. good point with “start with”. In fact, I am using this now and is as fast as expected. Need to check if this would also resolve the whole directory. Yes, having this as “default” would be good.

Regards,

Rolf.