Old 02-10-2011, 09:59 AM   #1 (permalink)
Newbie
 
Join Date: Feb 2011
Posts: 1
corndog is on a distinguished road
Default Why Administrative?

The Help screen for the Directory Connector specifies that it needs an Administrative account from the Active Directory, to connect and get names. This can be done with a regular account. Is there any real reason that the connector needs administrative rights to the AD? Or is this just a gratuitous admin grab, and a possible future security breach if there are vulnerabilities found in Untangle?
corndog is offline  
Old 02-10-2011, 10:14 AM   #2 (permalink)
Untangle Ninja
 
mrunkel's Avatar
 
Join Date: Jul 2008
Posts: 2,766
mrunkel is on a distinguished road
Default

<joke>Yes, we are collecting all your admin passwords and selling them to eastern european hackers so that they may take over the world.</joke>

In all seriousness, while you may connect with a non-admin account, an LDAP query does not return the full address list unless the account has admin rights.

Note: However, you can not use the administrator account, it needs to be another account with administrator rights.
__________________
m.


Big Frickin Disclaimer:
While I'm pretty sure, I can't guarantee that I know what I'm doing. There might be a better way to do this, and this way might actually suck. Make sure you understand the implications of what you're doing before trying to follow these directions.

It often helps troubleshooting if you have a good network map. Look here if you want my advice on how to draw one.
Attention: Support and help on the Untangle Forums is provided by volunteers and community members like yourself.
If you need Untangle support please call or email support@untangle.com
mrunkel is offline  
Old 02-10-2011, 10:27 AM   #3 (permalink)
Master Untangler
 
Big D's Avatar
 
Join Date: Nov 2008
Posts: 691
Big D is on a distinguished road
Default

Indeed the account needs to have enough access to query AD. It only performs queries and no alter commands so the account just needs to be able to view everything. Primarily for group membership and AD users.

So you could make a admin user that can only read and that should be sufficient in theory. Never tried so can't say for sure.
__________________
The beatings shall continue until morale improves!
Big D is offline  
Closed Thread

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 04:46 AM.


© 2010 Untangle, Inc. All Rights Reserved.   SEO by vBSEO 3.6.0 PL2