01-30-2020 01:58 AM
Hi everybody,
we do have a lot of local administrators configured to manage our appliances, is it possibile to have a LDAP configuration towards our internal LDAP of admins, to use it instead of local auth? Or is it mandatory to use local auth for esa administrative management?
Thanks everybody!
Regards
01-30-2020 03:57 AM
The next ESA software Release 13.x will support SAML authentication for ESA and SMA.
This should help with your question, ETA late Q1 2020.
01-30-2020 04:04 AM - edited 01-30-2020 07:08 AM
Yes.
On the page you create admin users, there should be a section for "External Authentication"
It relies on having an External Authentication query configured in your LDAP profile...
01-30-2020 11:25 PM
Done and everything works fine!
Thanks!
01-30-2020 11:58 PM
i have only a doubt, is it possible to login via cli with LDAP configured? Or still i need a local user?
Thanks
01-31-2020 03:33 AM
02-02-2020 11:50 PM
Hi all,
weird thing today, we got two ESA in a cluster.
I cannot understand why ldap is working on a unit and not on other.
Just to be clear, should i configure LDAP in a "cluster mode"? or per machine?
Thanks
02-03-2020 03:58 AM
Per definition you should try to configure in cluster mode when ever possible to make it easier on you.
There are areas where a cluster configuration might break things, as an example in LDAP . Check system admin / ldap and make sure the name of the Certificate used for LDAPs in named the same and exists on both ESA with that name.
Also test the LDAP settings in both ESA in machine mode and cluster mode to see if there is a mismatch.
I hope that helps
-Marc
02-03-2020 05:40 AM
Hi Marc,
the certificate is the same, and the tests are all fine on both, with machine and with cluster, i cannot understand why on one i got ldap auth and not on the other one.
I've noticed, dunno if it is right, one of the two esas has an inbound listener, machine mode, the other one has not configured a listener machine mode but only cluster mode. Dunno if this helps.
Thanks
Regards
Salvatore
02-03-2020 06:29 AM
Hi Salvatore,
can only speculate as I dont have access to your ESA. In our enviroment all ESA have the IP interfaces in machine mode and the listeners in cluster mode. The LDAP port binds to the listener. Does LDAP work on the ESA with the machine mode listener or the other one ? This would give me hints in which way the configuration needs to be "copied".
-Marc
02-03-2020 11:23 PM
Hi,
yes, the ldap is working on the machine with the listener present, should i configure the same listener on the other one?
Thanks
02-04-2020 12:04 AM
hi all, just configured the listener on the other machine, but no way, the ldap is working only on one machine of the cluster, dunno why!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide