Closed Ianooch closed 2 years ago
Users in this group cannot be authenticated using NTLM, so it doesn't seem to be likely to work with the standard LDAP authentication.
I believe there needs to be additional configuration with Apache for Kerberos authentication to work, and then configure the "Other authentication sent in the HTTP request" authentication options (Setup > Authentication > Other authentication methods). There are posts on the GLPI forum about this if you need some assistance. I don't know this part at all.
There has been no activity on this issue for some time and therefore it is considered stale and will be closed automatically in 10 days.
If this issue is related to a bug, please try to reproduce on latest release. If the problem persist, feel free to add a comment to revive this issue. If it is related to a new feature, please open a topic to discuss with community about this enhancement on suggestion website.
You may also consider taking a subscription to get professionnal support or contact GLPI editor team directly.
Code of Conduct
Is there an existing issue for this?
Version
10.0.1
Bug description
Hello,
I've setup an LDAP integration that works fine to retrieve users. When i import a standard user, i can log in to GLPI using this account.
When the Active Directory user is member of "Protected Users" group, i can import the user but the log in will fail. Message is "Identifiant ou mot de passe incorrect" (wrong identifier or password)
Relevant log output
Page URL
No response
Steps To reproduce
Create an AD standard user Import it in GLPI, activate it Try to login -> OK Ad "Protected Users" group to the AD object membership Try to login -> KO
Your GLPI setup information
Information about system installation & configuration
Server
GLPI constants
Libraries
LDAP directories
SQL replicas
Notifications
Plugins list
Anything else?
Info on protected user : https://docs.microsoft.com/en-us/windows-server/security/credentials-protection-and-management/protected-users-security-group