I've looked everywhere possible but simply can't find a solution for this issue anywhere, so I'm either doing something obviously wrong or this set up isn't used by anyone else, which would surprise me.

We've recently moved from an older 389-ds installation which worked fine to a FreeIPA server which "works". That is, Drupal and the server communicate properly, but to maintain various LDAP compatibility, FreeIPA maintains 2 active trees:
- uid=joeschmoe,cn=users,cn=accounts,dc=domain,dc=com
- uid=joeschmoe,cn=users,cn=compat,dc=domain,dc=com

No matter what I attempt to change in the settings, I always get 2 user objects returned which causes authentication to fail. Except for the server name and base DNs everything else is pretty much default.

I've tried including both Base DNs, and either one individually with no luck. Thanks for any help!

Comments

madnutz created an issue. See original summary.

madnutz’s picture

Title: LDAP frustration » LDAP Returning multiple user objects
grahl’s picture

Hi

I would have expected that setting the base DN to only one of those should solve your problem, I'd actually be very interested to know if you can still reproduce this on 8.x-4.x or if this is something we've not inherited from 7.x.

If it really is that broken, you might need to try to add filters, see #2887546: How can we add filters and #2843662: Add global filter for LDAP entries for exclude part of LDAP database users.

grahl’s picture

Status: Active » Closed (outdated)

Closing issue as outdated due to no further development on 7.x, if you feel this issue is still relevant and you are willing to work on a patch and/or debug the problem, please reopen.

madnutz’s picture

Thank you, I just wanted to follow up and let everyone know that this was a php configuration problem on our server. The LDAP cert was in the wrong place and somehow allowing the search but interfering with the results. We ended up doing a completely fresh OS install which seems to have fixed it.

grahl’s picture

Thanks for the feedback!