RFE: Better Active Directory integration
Bug #2015772 reported by
Mark Cunningham
This bug affects 1 person
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
Landscape Server |
New
|
Undecided
|
Unassigned |
Bug Description
Request for enhancements from client:
* There really, really needs to be better Active Directory integration.
* Apparently, you can either have AD auth OR landscape accounts, but not both. And using AD apparently requires messing with PAM - albeit the instructions seems straightforward.
* My issue is, with no "local" admin account, what happens if AD is unavailable?
* And AD integration should be a gui-fied process, not a CLI/Manual/PAM process.
* It'd be nice to allow AD groups as administrators, for instance, instead of individual accounts.
* In our enterprise, these features are nearly essential.
information type: | Proprietary → Public |
To post a comment you must log in.
We implemented AD authentication in CODENERIX long time ago, and we could log in indistinctly as usual users or through AD. Could we be facing a permission problem?
CODENERIX's authentication backend is here (it has been written for work on Django's authentication backend): /github. com/codenerix/ django- codenerix/ blob/master/ codenerix/ authbackend. py#L866
https:/