<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=29&amp;t=1184" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2013-10-16T15:48:43+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=29&amp;t=1184</id>
<entry>
<author><name><![CDATA[bbladesCSE]]></name></author>
<updated>2013-10-16T15:48:43+01:00</updated>
<published>2013-10-16T15:48:43+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1184&amp;p=4498#p4498</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1184&amp;p=4498#p4498"/>
<title type="html"><![CDATA[Re: [SOLVED] YubiRADIUS Bind to Active Directory fails]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1184&amp;p=4498#p4498"><![CDATA[
The only thing i can think of is I used an account that is in the Users OU, and the account name is a single word (where the username and the first name are the same, and there is no last name). I may have created the user on a different domain controller than the one i configured the VA to use to authenticate (i dont explicitly remember which one i used to create the account) and replication too a while, which could be why it 'just started working', perhaps.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2616">bbladesCSE</a> — Wed Oct 16, 2013 3:48 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[bbladesCSE]]></name></author>
<updated>2013-10-07T19:34:03+01:00</updated>
<published>2013-10-07T19:34:03+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1184&amp;p=4452#p4452</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1184&amp;p=4452#p4452"/>
<title type="html"><![CDATA[Re: [QUESTION] YubiRADIUS Bind to Active Directory fails]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1184&amp;p=4452#p4452"><![CDATA[
Thanks for replying! I always find that anything that uses canonical names and not just a plane old login are always a pain in the rear to get working. Using my example 'Yubi' is the login, and first name of the user I've created for ldap queries, there is no last name.  --<br /><br />I just logged into my YRVA to change the filter and ....<br />WHOA! All my AD users showed up What the EFF???<br /><br /><br /><br /><br /><br />I seriously have no idea how or why it started working.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2616">bbladesCSE</a> — Mon Oct 07, 2013 7:34 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[agonsman]]></name></author>
<updated>2013-10-05T07:50:11+01:00</updated>
<published>2013-10-05T07:50:11+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1184&amp;p=4450#p4450</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1184&amp;p=4450#p4450"/>
<title type="html"><![CDATA[Re: [QUESTION] YubiRADIUS Bind to Active Directory fails]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1184&amp;p=4450#p4450"><![CDATA[
This seems very poorly documented in the YubiRADIUS literature. I'm running successfully against 2012 to authenticate Cisco AnyConnect VPN clients. <br /><br />I spent a long time and went through quite a bit of swearing to get this to work. I was not (and still not) an AD/LDAP expert when I started this so if I point out some things that are obvious, my apologies. They were not obvious to me.<br /><br />User DN is the Full Name of the user, not the login. That is, if I create an AD user with first name LDAP and last name Query and give it the login ldapq, then use &quot;CN=LDAP Query&quot; and not &quot;CN=ldapq&quot;<br /><br />Also, the default filter is pretty poor. You'll probably want something more like: <br /><div class="codetitle"><b>Code:</b></div><div class="codecontent">(&amp;(objectCategory=person)(objectClass=user))</div> <br /><br />This should limit the accounts brought over to those that belong to real people.<br /><br />Lastly, LoginNameIdentifier should be sAMAccountName and not cn. Just like under User DN, cn will yield the full name as the login and not the login you're used to. <br /><br />Hope this helps.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2620">agonsman</a> — Sat Oct 05, 2013 7:50 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[bbladesCSE]]></name></author>
<updated>2013-10-16T15:44:36+01:00</updated>
<published>2013-10-03T15:31:35+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1184&amp;p=4444#p4444</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1184&amp;p=4444#p4444"/>
<title type="html"><![CDATA[[SOLVED] YubiRADIUS Bind to Active Directory fails]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1184&amp;p=4444#p4444"><![CDATA[
I'm trying to set up YubiRADIUS with Active Directory 2012. I've created a dedicated account for the VA to use to bind to AD. <br /><br /><img src="http://i.imgur.com/PDLl6Uq.jpg" alt="Image" /><br /><br /><br />Here is the error:<br /><div class="quotetitle"><b>Quote:</b></div><div class="quotecontent"><br />User Import operation started...<br />Connecting to LDAP/AD server.<br />Successfully connected to LDAP/AD server.<br />Binding to server with given user credentials.<br />Failed to bind to server.<br />Failed to find Users.<br />Please check login credentials or Directory Type.<br /></div><br /><br /><br />Any clue what i am doing wrong here?<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2616">bbladesCSE</a> — Thu Oct 03, 2013 3:31 pm</p><hr />
]]></content>
</entry>
</feed>