Feature #863


add ability to restrict ldap authentication to a security group

Added by Corey Osman about 13 years ago. Updated almost 11 years ago.

Target version:
Fixed in Releases:
Found in Releases:


I would like to be able to specify ldap authentication to only do name lookups by a specific group:


can I restrict by group like this : cn=foremanadmins, ou=Security Groups, dc=MYDOMAIN,dc=CORP

I currently have this enabled with my subversion setup so I was hoping I could do it on foreman as well.

Related issues 1 (0 open1 closed)

Related to Foreman - Feature #813: Support AD group membership for authorization and authenticationClosedDaniel Lobato Garcia03/31/2011Actions
Actions #1

Updated by Benjamin Papillon over 12 years ago

And also important, affect role based on LDAP group.
If it's possible to create a LDAP Group type,(auto create user option enabled) then when the user from a group connect for the first time, the good role is automatically assigned.

Actions #2

Updated by monte olvera over 12 years ago

I would also like to have ldap auth restricted to members of an ldap group.

Actions #3

Updated by Karl Vollmer about 11 years ago

I need this for work, so I put $100 down for anyone who will complete this functionality.

Actions #4

Updated by Mikael Fridh about 11 years ago

just a bit of a pseudo-code version of doing it (untested):

The actual search method code was tested against Active Directory before I hackishly put this example in the Foreman code though as I recently built some puppet functions to get canonical user and group information from Active Directory with net-ldap.

Perhaps it can inspire someone to clean it up, make it work and add it as a configuration setting?

Actions #6

Updated by Dominic Cleal almost 11 years ago

  • Description updated (diff)
  • Category set to Authentication
  • Status changed from New to Ready For Testing
Actions #7

Updated by Dominic Cleal almost 11 years ago

  • Target version set to 1.3.0
Actions #8

Updated by Anonymous almost 11 years ago

  • Status changed from Ready For Testing to Closed
  • % Done changed from 0 to 100

Also available in: Atom PDF