Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Guest - Sponsorship - Multiple LDAP Server

This thread has been viewed 3 times
  • 1.  Guest - Sponsorship - Multiple LDAP Server

    Posted Jan 27, 2017 08:09 AM

    Hello,

    For self-registration portal, I need to lookup in 2 LDAP servers (during AD migration).

     

    I succeeded in configuring the portal to have the sponsor_lookup search in one of the 2 LDAP servers (using LDAP server priorities or Select2 ajax.args.server parameters) but didn't find a way to perform the search in both simultaneously.

     

    Is it possible? If yes, how and if not, which other option can I use?

     

    Thanks,



  • 2.  RE: Guest - Sponsorship - Multiple LDAP Server

    Posted Jan 30, 2017 04:24 AM

    I had this issue too and couldn't find a way to query both.



  • 3.  RE: Guest - Sponsorship - Multiple LDAP Server

    Posted Jan 30, 2017 04:54 AM

    Hello James,

     

    thanks for the answer, not a good perspective :)

    I tried using a second sponsor_lookup (duplicate field) which works for the lookup but the e-mail used is the guest's one => maybe I have something wrong but can't find what.

     



  • 4.  RE: Guest - Sponsorship - Multiple LDAP Server

    Posted Jan 30, 2017 05:08 AM
    Sounds like that should work. Wasn't an option for me at the time. :(

    I'll try to have a look on my lab.

    Does the 2nd sponsor lookup work if you remove the first one?


  • 5.  RE: Guest - Sponsorship - Multiple LDAP Server

    Posted Jan 30, 2017 08:02 AM

    I tried disabling the first sponsor_lookup but it is still the same.

    EDIT: Little correction: the guest's email is used for the sponsor_name and the sponsor_email is not filled.

     

    The solution is not very nice but it is a workaround.  As title for the field, I use: "If you don't find your host, search in the second directory:"



  • 6.  RE: Guest - Sponsorship - Multiple LDAP Server
    Best Answer

    Posted Jan 30, 2017 08:57 AM

    It is working now...

    I didn't do anything related to this but:

    - I edited the LDAP servers to check the mapping (was working before, so didn't should have an impact)

    - I created a second copy of the sponsor_lookup field and after checking parameters, deleted it

     

    So, currently my configuration is:

    - Duplicate sponsor_lookup field and change its name to sponsor_lookup2

    - Added the sponsor_lookup2 in my form right after the existing sponsor_lookup field

    - Edit both sponsor_lookup field in my form and define the LDAP server to use in the Select2 Option / ajax.args.server

    - Change the label of sponsor_lookup2 to instruct the guest to search in this field if he don't find him in the first

     

    Not a nice solution but it's working.

     

    Maybe an improvement to do for Aruba :)