Comments (3)
Aw please Vault team... surely you can change this to just use the full DN or the user or at least search by CN or something more common ?
from vault-plugin-secrets-ad.
For anyone facing the same issue, the main problem you might face is that you can't configure the filter to search in ldap. Vault api is fixed to use userPrincipalName
and this won't work directly for all ldap servers. The way to solve this is by adding a proxy (openldap proxy) and map attributes in slapd.conf
(after defining them in schema) using rwm-map
attribute.
from vault-plugin-secrets-ad.
Does anyone know if there's any other way around this problem?
It seems like a major downfall of the secrets engine if it isn't able to query active directory directly.
from vault-plugin-secrets-ad.
Related Issues (8)
- Unable to mount this plugin as an external plugin on current Vault master HOT 2
- Can I create an account in Active Directory using Active Directory secrets engine? HOT 1
- instructions for quick test HOT 8
- How to control the length of password generated by ad secret engine?
- Vault AD Engine Paths not working HOT 1
- AD secrets engine has poor behaviour when an account has been renamed or deleted HOT 1
- Documentation and code issue for AD secret engine config
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from vault-plugin-secrets-ad.