Friday, August 2, 2013

LDAP Bind account and disappearing groups in Sametime

On a production environment, the LDAP Bind account is in LocalDomainAdmins group. That's historical but poses a threat to security. However, when removed, LDAP groups appeared as empty for users in Sametime!

Solving


Testing access to LDAP you have :
- ldapsearch which is delivered with lotus notes
- Ldap Browser from Softerra which i use a lot, and it's free

Clic there to access the free tool

With LDAP testing I found that some groups had the problem and other not. This is LDAP related.


Finally

Some groups had reader field and I had not made aware of them. I guess you never know what's in a production environment until you break your head on it!
I just added the LDAP Bind account to reader access, restarted LDAP task and it rolled.

No comments:

Post a Comment