Testing OpenLDAP with rancher. But haven’t been able to get the groups working. Not the most familiar with LDAP. So i think the issue is how im filtering for groups. Below are some example ldapsearch commands and output I’ve been using to try to configure with. And my config settings. Anyone have an idea of what I am doing wrong?
Groups/Roles
ldapsearch -H ldaps://ldap.us.onelogin.com:636 -D "cn=ops-team@company.co,ou=users,dc=company,dc=onelogin,dc=com" -b "cn=coolguys,cn=groups,dc=company,dc=onelogin,dc=com"
# coolguys, roles, company.onelogin.com
dn: cn=coolguys, cn=roles, dc=company, dc=onelogin, dc=com
cn: coolguys
objectClass: groupOfNames
member: cn=person1@company.co,ou=users,dc=company,dc=onel1ogin,dc=com
member: cn=person2@company.co,ou=users,dc=company,dc=onelogin,dc=com
member: cn=person3@company.co,ou=users,dc=company,dc=onelogin,dc=com
Users
ldapsearch -H ldaps://ldap.us.onelogin.com:636 -D "cn=ops-team@company.co,ou=users,dc=company,dc=onelogin,dc=com" -b "ou=users,dc=company,dc=onelogin,dc=com"
# ops-team@company.co, users, company.onelogin.com
dn: cn=ops-team@company.co, ou=users, dc=company, dc=onelogin, dc=com
username: ops-team
loginShell: /bin/bash
homeDirectory: /Users/ops-team@company.co
cn: ops-team@company.co
mail: ops-team@company.co
givenName: SVC
uid: 31812504
surname: OPS-TEAM
objectClass: top
objectClass: inetOrgPerson
objectClass: ldapsubentry
objectClass: subentry
name: SVC OPS-TEAM
uidNumber: 31812504
samaccountname:
gidNumber: 99419