[External] Issues with LDAP Configuration

Agi Joseph agi.joseph at gans.aero
Wed Feb 16 04:26:01 UTC 2022


Dear Emmanuel,

Can I know the least level permission to required to establish the LDAP bind account, because I tried with a normal AD account but didn’t work getting below error,

" Failed to bind to the LDAP server. The error message was: 80090308: LdapErr: DSID-0C090439, comment: AcceptSecurityContext error, data 52e, v4563"

It seems its required some sort of additional permissions rather than a normal AD account.

Thanks,



Best Regards,

Agi Joseph
Systems & Network Administrator
Global Air Navigation Services LLC
Tel:+971 2 5565233 * 2583
Mob:+971 50 2383530
Email:agi.joseph at gans.aero
Web:www.gans.aero


-----Original Message-----
From: support-list <support-list-bounces at bugzilla.org> On Behalf Of Emmanuel Seyman
Sent: Wednesday, February 16, 2022 3:05 AM
To: support-list at bugzilla.org
Subject: Re: [External] Issues with LDAP Configuration

* Daniel McCarty [15/02/2022 19:19] :
>
> Be careful with security here as this account is a domain super
> account (again I'm not an expert on AD by any means) and a potential
> attack vector.

Making the account an AD super admin seems unneccesary. If this account is dedicated to letting Bugzilla talk to the directory, you really only need bind and search permissions.

Emmanuel
_______________________________________________
support-list mailing list
support-list at bugzilla.org
https://lists.bugzilla.org/listinfo/support-list


More information about the support-list mailing list