# LDAP Authentication bind

**URL:** https://discuss.tryton.org/t/ldap-authentication-bind/5016
**Category:** System Administrator
**Created:** [February 15, 2022, 11:33pm UTC](https://discuss.tryton.org/t/ldap-authentication-bind/5016 "2022-02-15T23:33:40Z")
**Posts on this page:** 11
**Page:** 1

<div class="post-metadata">

### Author: ![hannes](https://discuss-cdn.tryton.org/letter_avatar_proxy/v4/letter/h/f0a364/32.png) [@hannes](https://discuss.tryton.org/u/hannes)
#### Post date: [February 15, 2022, 11:33pm UTC](https://discuss.tryton.org/t/ldap-authentication-bind/5016/1 "2022-02-15T23:33:40Z")

</div>

Hello everyone,  
I´m trying to setup ldap authentication, but I´m not able to login with my ldap user. LDAP is working on other services like nextcloud.

This is my ldap config:

```auto
      TRYTOND_SESSION__AUTHENTICATIONS: password,ldap
      TRYTOND_LDAP_AUTHENTICATION__URI: ldap://openldap:389/ou=people,dc=innwerk,dc=org?objectClass?subtree??!bindname=cn=tryton%2cou=dsa%2cdc=innwerk%2cdc=org
      TRYTOND_LDAP_AUTHENTICATION__BIND_PASS: verysecurepassword
      TRYTOND_LDAP_AUTHENTICATION__UID: uid
      TRYTOND_LDAP_AUTHENTICATION__CREATE_USER: "false"

```

The only log entry i get is `ERROR trytond.security login failed for 'hannes' from '172.18.0.7' on database 'tryton'`. I would be happy about any hints on how to get this working!

Cheers  
Hannes

---

<div class="post-metadata">

### Author: ![ced](https://discuss-cdn.tryton.org/user_avatar/discuss.tryton.org/ced/32/1237_2.png) [@ced](https://discuss.tryton.org/u/ced)
#### Post date: [February 16, 2022, 12:37am UTC](https://discuss.tryton.org/t/ldap-authentication-bind/5016/2 "2022-02-16T00:37:42Z")

</div>

For me it looks like no user is found with the `uid`.  
I guess you will have to put some debug statement in the method `ldap_search_user`.

---

<div class="post-metadata">

### Author: ![edbo](https://discuss-cdn.tryton.org/letter_avatar_proxy/v4/letter/e/f14d63/32.png) [@edbo](https://discuss.tryton.org/u/edbo)
#### Post date: [February 16, 2022, 10:09am UTC](https://discuss.tryton.org/t/ldap-authentication-bind/5016/3 "2022-02-16T10:09:10Z")

</div>

Hello,

I use LDAP authentication without any problem. So there are a few things to check:

1. Does your user already exists in Tryton itself?
2. I also see some html formatted characters in your bindname.
3. I use `ldap,password` for my authentications, so first LDAP is checked and if that fails, it will look for the password in Tryton

---

<div class="post-metadata">

### Author: ![hannes](https://discuss-cdn.tryton.org/letter_avatar_proxy/v4/letter/h/f0a364/32.png) [@hannes](https://discuss.tryton.org/u/hannes)
#### Post date: [February 22, 2022, 1:06pm UTC](https://discuss.tryton.org/t/ldap-authentication-bind/5016/4 "2022-02-22T13:06:39Z")

</div>

Hi @ced, can you give me an example on how such debug statement should look like?

---

<div class="post-metadata">

### Author: ![ced](https://discuss-cdn.tryton.org/user_avatar/discuss.tryton.org/ced/32/1237_2.png) [@ced](https://discuss.tryton.org/u/ced)
#### Post date: [February 22, 2022, 1:09pm UTC](https://discuss.tryton.org/t/ldap-authentication-bind/5016/5 "2022-02-22T13:09:50Z")

</div>

I mean just putting some `print` statement to understand where and why no user is found.

---

<div class="post-metadata">

### Author: ![hannes](https://discuss-cdn.tryton.org/letter_avatar_proxy/v4/letter/h/f0a364/32.png) [@hannes](https://discuss.tryton.org/u/hannes)
#### Post date: [February 22, 2022, 1:12pm UTC](https://discuss.tryton.org/t/ldap-authentication-bind/5016/6 "2022-02-22T13:12:09Z")

</div>

Hello @edbo

1. Yes, the usere exists and I can succesfully login to other services such as nextcloud.
2. I used these html formatted characters according to the [RFC Documentation](https://datatracker.ietf.org/doc/html/rfc2255#section-6). But I sinced tried without the encoding with the same result
3. I´ve changed the order, but I´m still not able to login

Can you give me an example of your working config? Thanks in advance for your helo so far 🙂

---

<div class="post-metadata">

### Author: ![hannes](https://discuss-cdn.tryton.org/letter_avatar_proxy/v4/letter/h/f0a364/32.png) [@hannes](https://discuss.tryton.org/u/hannes)
#### Post date: [February 22, 2022, 1:12pm UTC](https://discuss.tryton.org/t/ldap-authentication-bind/5016/7 "2022-02-22T13:12:39Z")

</div>

Okay, I will try! Thank you 😃

---

<div class="post-metadata">

### Author: ![2cadz](https://discuss-cdn.tryton.org/user_avatar/discuss.tryton.org/2cadz/32/130_2.png) [@2cadz](https://discuss.tryton.org/u/2cadz)
#### Post date: [February 22, 2022, 1:31pm UTC](https://discuss.tryton.org/t/ldap-authentication-bind/5016/8 "2022-02-22T13:31:27Z")

</div>

> [@hannes](#):
>
> Can you give me an example of your working config? Thanks in advance for your helo so far

```auto
[ldap_authentication]
# The LDAP URL to connect to the server following RFC-2255.
#uri = ldap://host:port/dn?attributes?scope?filter?extensions
# A basic default URL could look like
#
uri = ldap://<fqdn_or_ip>:389/ou=<name_of_ou>,dc=xxxx,dc=xxxx?sAMAccountName?subtree??bindname=CN=<your_bind_name>,dc=xxxx,dc=xxxx
# The LDAP password used to bind if needed.
bind_pass = <your_bind_pwd>
# If the LDAP server is an Active Directory.
active_directory = True

```

---

<div class="post-metadata">

### Author: ![edbo](https://discuss-cdn.tryton.org/letter_avatar_proxy/v4/letter/e/f14d63/32.png) [@edbo](https://discuss.tryton.org/u/edbo)
#### Post date: [February 22, 2022, 1:55pm UTC](https://discuss.tryton.org/t/ldap-authentication-bind/5016/9 "2022-02-22T13:55:24Z")

</div>

> [@hannes](#):
>
> Can you give me an example of your working config?

I’m using iredmail as mailserver which is using OpenLDAP. I added a service in the LDAP which I’m using to filter out users. I also use `onelevel` to search on instead of `subtree`

```auto
[ldap_authentication]
uri = ldap://server01.edbo-local.lan:389/ou=users,domainname=edbo-local.lan,o=domains,ou=mailsystem,dc=edbo-local,dc=lan??onelevel?(&(objectclass=inetOrgPerson)(enabledservice=trytonERP))?bindname=cn=vmail,ou=Mailsystem,dc=edbo-local,dc=lan
bind_pass = <very_secret_password>
active_directory = False
uid = uid
create_user = False

```

BTW, it’s a testserver which is not connected to the internet.

---

<div class="post-metadata">

### Author: ![hannes](https://discuss-cdn.tryton.org/letter_avatar_proxy/v4/letter/h/f0a364/32.png) [@hannes](https://discuss.tryton.org/u/hannes)
#### Post date: [March 1, 2022, 4:49pm UTC](https://discuss.tryton.org/t/ldap-authentication-bind/5016/10 "2022-03-01T16:49:21Z")

</div>

The problem was `create_user = False` which should have been true. Thanks for your help!

---

<div class="post-metadata">

### Author: ![system](https://discuss-cdn.tryton.org/uploads/default/original/1X/c6f8ec0a40525cdcd50058c734283450a4b3d38b.png) [@system](https://discuss.tryton.org/u/system)
#### Post date: [March 31, 2022, 4:49pm UTC](https://discuss.tryton.org/t/ldap-authentication-bind/5016/11 "2022-03-31T16:49:28Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
