Hi,
I'm setting UP OTRS 3.1.3 for a bunch of different customer.
I have been able to setup the LDAP Integration with AD for the customer1, and using local db for agents.
In the future I will have to extend the customer integration with another ldap, I have already the guide to follow and I'm quite confident to have a few minor problems
BUT
what happens if I have the same login in both the customer repositories ?
I am using the smaccountname as login for authentication, and there can be situations where two different AD, belonging to different companies, use the same smaccountname.
Will OTRS try the combination smaccountname+password provided against each of the AD o will it stop at first "password error" ?
Have anyone tried to autenticate using UID=mail ?
I'm against the usage of mail because not every customer may have exchange, with the AD extensions installed or simply with the record populated.
Should it work to use the
CustomerUserSearchPrefix => '',
CustomerUserSearchSuffix => '*',
for example to search for MYDOMAIN1\userX or MYDOMAIN2\userX ?
But OTRS, in that case, should cascade the authentication tests.
I was not able to find a proper documentation regarding this.
Thanks,
Massimo
[SOLVED] same customer login in multiple AD domain
Moderator: crythias
-
- Znuny newbie
- Posts: 67
- Joined: 02 Apr 2012, 12:18
- Znuny Version: 3.1.14
- Real Name: Massimo Bianchi
- Company: NPO Sistemi S.p.A.
- Contact:
[SOLVED] same customer login in multiple AD domain
Last edited by massimobianchi on 18 Apr 2012, 16:29, edited 1 time in total.
Massimo Bianchi
skype: massimo.bianchi
OTRS:3.1.14, ITSM:3.1.8, httpd, mysql, Centos 6.3 on X86_64
skype: massimo.bianchi
OTRS:3.1.14, ITSM:3.1.8, httpd, mysql, Centos 6.3 on X86_64
Re: same customer login in multiple AD domain
We have had this problem - 2 different LDAP directories with identical samaccountname.
The problem is that OTRS takes the first valid login and populates some fields like the mail-adress with wrong values.
I only found as work-around to create a unique local user account instead of using the ldap account.
For example I had 2 user wagner.s - if the first logged in he got an email adress mail@ldap1, if the second logged in, he got mail@ldap2
Maybe there is another way around this - I didn't find it.
The problem is that OTRS takes the first valid login and populates some fields like the mail-adress with wrong values.
I only found as work-around to create a unique local user account instead of using the ldap account.
For example I had 2 user wagner.s - if the first logged in he got an email adress mail@ldap1, if the second logged in, he got mail@ldap2
Maybe there is another way around this - I didn't find it.
Produktivsystem: OpenSuSE 11.2, Apache/2.2.13, MySQL 5.0.51, OTRS 2.4.9
Testsystem: OpenSuSE 11.4, OTRS 3.0.9
Testsystem: OpenSuSE 11.4, OTRS 3.0.9
-
- Znuny newbie
- Posts: 67
- Joined: 02 Apr 2012, 12:18
- Znuny Version: 3.1.14
- Real Name: Massimo Bianchi
- Company: NPO Sistemi S.p.A.
- Contact:
Re: same customer login in multiple AD domain
Hi,thank you for your suggestion, I will use it in case of identical identifier.
In the meantime, I have an idea but don't have the tech skill to implement it.
I was thinking of creating a set of custom skin, one "standard" and many for the different customer.
I can differenziate the skin based upon connecting address via sysconfig parameter.
And in this skin hack the code to force a determined domain to authenticate against...
Maybe googling will help me
regards,
Massimo
In the meantime, I have an idea but don't have the tech skill to implement it.
I was thinking of creating a set of custom skin, one "standard" and many for the different customer.
I can differenziate the skin based upon connecting address via sysconfig parameter.
And in this skin hack the code to force a determined domain to authenticate against...
Maybe googling will help me

regards,
Massimo
Massimo Bianchi
skype: massimo.bianchi
OTRS:3.1.14, ITSM:3.1.8, httpd, mysql, Centos 6.3 on X86_64
skype: massimo.bianchi
OTRS:3.1.14, ITSM:3.1.8, httpd, mysql, Centos 6.3 on X86_64
-
- Znuny newbie
- Posts: 6
- Joined: 16 Apr 2012, 15:48
- Znuny Version: 3.1.3
- Real Name: Kevin Lawry
- Company: National Friendly
Re: same customer login in multiple AD domain
have you considered userPrincipalName rather than sAMAccountName?
That should be unique, avoids problems with users who have multiple e-mail addresses, and should be recognisable to users as relating to their account
That should be unique, avoids problems with users who have multiple e-mail addresses, and should be recognisable to users as relating to their account
-
- Znuny newbie
- Posts: 67
- Joined: 02 Apr 2012, 12:18
- Znuny Version: 3.1.14
- Real Name: Massimo Bianchi
- Company: NPO Sistemi S.p.A.
- Contact:
Re: same customer login in multiple AD domain
Hi,
looks VERY promising.
Do you know if I can use it also for authentication, as a user, instead of sAMAccountName ?
Kind regards,
Massimo
looks VERY promising.
Do you know if I can use it also for authentication, as a user, instead of sAMAccountName ?
Kind regards,
Massimo
Massimo Bianchi
skype: massimo.bianchi
OTRS:3.1.14, ITSM:3.1.8, httpd, mysql, Centos 6.3 on X86_64
skype: massimo.bianchi
OTRS:3.1.14, ITSM:3.1.8, httpd, mysql, Centos 6.3 on X86_64
-
- Znuny newbie
- Posts: 67
- Joined: 02 Apr 2012, 12:18
- Znuny Version: 3.1.14
- Real Name: Massimo Bianchi
- Company: NPO Sistemi S.p.A.
- Contact:
Re: same customer login in multiple AD domain
You are a GENIUS !!!
IT worked perfectly for authentication, chaning the lines in Config.pm.
Regards,
Massimo
IT worked perfectly for authentication, chaning the lines in Config.pm.
Regards,
Massimo
Massimo Bianchi
skype: massimo.bianchi
OTRS:3.1.14, ITSM:3.1.8, httpd, mysql, Centos 6.3 on X86_64
skype: massimo.bianchi
OTRS:3.1.14, ITSM:3.1.8, httpd, mysql, Centos 6.3 on X86_64
-
- Znuny newbie
- Posts: 6
- Joined: 16 Apr 2012, 15:48
- Znuny Version: 3.1.3
- Real Name: Kevin Lawry
- Company: National Friendly
Re: [SOLVED] same customer login in multiple AD domain

