# Can't get LDAP auth working

**URL:** <https://forums.suse.com/t/cant-get-ldap-auth-working/13504>\
**Category:** SUSE Rancher Prime\
**Created:** [February 28, 2019, 5:49pm UTC](https://forums.suse.com/t/cant-get-ldap-auth-working/13504 "2019-02-28T17:49:07Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![mmarseglia](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/mmarseglia/32/4872_2.png) [@mmarseglia](https://forums.suse.com/u/mmarseglia)\
**Post date:** [February 28, 2019, 5:49pm UTC](https://forums.suse.com/t/cant-get-ldap-auth-working/13504/1 "2019-02-28T17:49:07Z")

</div>

I’ve got Rancher HA and trying to get LDAP working. I keep getting authentication failed error even though the credentials work. I verified the credentials in a separate LDAP client. I’ve tried plain LDAP and LDAPS, using the domain\username and user principle name format. I just can’t get this config working.

I got the logs from the rancher container, “2019/02/28 16:08:45 [ERROR] API error response 401 for POST /v3/activeDirectoryConfigs/activedirectory?action=testAndApply. Cause: LDAP Result Code 49 “Invalid Credentials”: 80090308: LdapErr: DSID-0C09042A, comment: AcceptSecurityContext error, data 52e, v3839”

---

<div class="post-metadata">

**Author:** ![mmarseglia](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/mmarseglia/32/4872_2.png) [@mmarseglia](https://forums.suse.com/u/mmarseglia)\
**Post date:** [February 28, 2019, 7:35pm UTC](https://forums.suse.com/t/cant-get-ldap-auth-working/13504/2 "2019-02-28T19:35:47Z")

</div>

So we threw Rancher into debug mode and got this error,

[DEBUG] Failed to determine if object is type: person

---

<div class="post-metadata">

**Author:** ![Stonedge](https://avatars.discourse-cdn.com/v4/letter/s/d07c76/32.png) [@Stonedge](https://forums.suse.com/u/Stonedge)\
**Post date:** [February 28, 2019, 9:54pm UTC](https://forums.suse.com/t/cant-get-ldap-auth-working/13504/3 "2019-02-28T21:54:11Z")

</div>

Here is the config that work on my side on an active directory server… log in rancher using domain\user1 format.

but for the service account username in the rancher config, I use the format [user.name@domain.com](mailto:user.name@domain.com)

Did your ldap server is an windows active directory ldap server?

the error message seem to tell that the connection is successful but the issue is on the object… look like your ldap user didn’t have right to see the object class of the user and/or object class is empty… (but i could be wrong… a connection error could also be the cause)

using your other ldap tool… are you able to see the object class/type?

### General

**Server:** [server.domain.com:389](http://server.domain.com:389)  
**TLS:** No  
**Service Account Username:** [ldap.user@domain.com](mailto:ldap.user@domain.com)  
**Default Domain:**  
**Server Connection Timeout:** 5000

### Users

**Object Class:** person  
**Login Attribute:** sAMAccountName  
**Username Attribute:** name  
**Search Attribute:** sAMAccountName|sn|givenName  
**Status Attribute:** userAccountControl  
**Disabled BitMask:** 2

Stonedge

---

<div class="post-metadata">

**Author:** ![mmarseglia](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/mmarseglia/32/4872_2.png) [@mmarseglia](https://forums.suse.com/u/mmarseglia)\
**Post date:** [March 1, 2019, 1:11pm UTC](https://forums.suse.com/t/cant-get-ldap-auth-working/13504/4 "2019-03-01T13:11:03Z")

</div>

Thank you for your help,

I should clarify, I’m trying to use the Authentication mechanism, “Active Directory” as described in this document. [https://rancher.com/docs/rancher/v2.x/en/admin-settings/authentication/ad/](https://rancher.com/docs/rancher/v2.x/en/admin-settings/authentication/ad/)

The server we’re trying to connect to is a Windows Active Directory domain controller.

I’m using Apache Directory Studio as my ldap client. I can see the objectclass when I look at a user.

We tried using the OpenLDAP Authentication mechanism and that works.

---

<div class="post-metadata">

**Author:** ![imlight](https://avatars.discourse-cdn.com/v4/letter/i/57b2e6/32.png) [@imlight](https://forums.suse.com/u/imlight)\
**Post date:** [March 27, 2020, 12:30pm UTC](https://forums.suse.com/t/cant-get-ldap-auth-working/13504/5 "2020-03-27T12:30:17Z")

</div>

We are seeing excalty same behaviour as mmarseglia suggests.

Has anyone got solution for this ?

---

<div class="post-metadata">

**Author:** ![teddyphreak](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/teddyphreak/32/6232_2.png) [@teddyphreak](https://forums.suse.com/u/teddyphreak)\
**Post date:** [April 2, 2020, 1:19am UTC](https://forums.suse.com/t/cant-get-ldap-auth-working/13504/6 "2020-04-02T01:19:47Z")

</div>

Yes, with the following settings. Fill [values] with your settings, all other values should be pasted verbatim:

# General

Service Account Username: [user]@[domain].[tld]  
Service Account Password: [password]  
Default Login Domain: [blank]  
User Search Base: dc=[domain],dc=[tld]  
Group Search Base: dc=[domain],dc=[tld]

# Users

Object Class: person  
Username Attribute: name  
Login Attribute: userPrincipalName  
User Member Attribute: memberOf  
Search Filter: [blank]  
User Enabled Attribute: userAccountControl  
DisabledStatusBitmask: 2

# Groups

Object Class: person  
Name Attribute: name  
Group Member User Attribute: distinguishedName  
Search Attribute: sAMAccountName  
Search Filter: [blank]  
Group Member Mapping Attribute: member  
Group DN Attribute: distinguishedName

# Test

Your username: [user]@[domain].[tld]  
Your Password: [password]

---

<div class="post-metadata">

**Author:** ![imlight](https://avatars.discourse-cdn.com/v4/letter/i/57b2e6/32.png) [@imlight](https://forums.suse.com/u/imlight)\
**Post date:** [April 3, 2020, 4:27am UTC](https://forums.suse.com/t/cant-get-ldap-auth-working/13504/7 "2020-04-03T04:27:38Z")

</div>

thanks , It worked , What we were missing was

Service Account Username Enter the username of an AD account with read-only access to your domain partition (see [Prerequisites](https://rancher.com/docs/rancher/v2.x/en/admin-settings/authentication/ad/#prerequisites)). The username can be entered in NetBIOS format (e.g. “DOMAIN\serviceaccount”) or UPN format (e.g. “serviceaccount@domain.com”).

With other providers we have used in CN=X,OU=Z,DC=Y, which was not working with rancher. Passing service account in above format worked for us. Thanks to Gaurav Mehta for guidance.
