Scalix and Active Directory (Win2003) for authentication

Discuss installation of Scalix software

Moderators: ScalixSupport, admin

asd_itops
Posts: 82
Joined: Tue Feb 06, 2007 12:33 pm

Scalix and Active Directory (Win2003) for authentication

Postby asd_itops » Mon Feb 26, 2007 1:11 pm

I have a fresh install of Scalix 11.0.1, and on its own it is working fine. However, trying to configure AD for authentication (don't want to synch because of dirty AD structure with non-user accounts intermixed) is not working. I have followed the directions for Kerberos, without SSO... but no luck. No errors that I can find either? Please help?

Scalix 11.0.1
RHEL 4
Confirmed connectivity between Scalix and Windows Servers
Only on screen (WEBMAIL) error is invalid password generic

asd_itops
Posts: 82
Joined: Tue Feb 06, 2007 12:33 pm

Update

Postby asd_itops » Mon Feb 26, 2007 1:26 pm

I also wanted to let you know that testing via kinit shows successful authentication

asd_itops
Posts: 82
Joined: Tue Feb 06, 2007 12:33 pm

RESOLVED

Postby asd_itops » Mon Feb 26, 2007 2:18 pm

See FAQ's for Scalix 11:

SWA uses SMTP authentication
SWA now authenticates with the SMTP Relay. If you are using external authentication such as OpenLDAP or Active Directory, you will need to make sure that the changes you made to /var/opt/scalix/NN/s/sys/pam.d/ual.remote is also applied to /var/opt/scalix/NN/s/sys/pam.d/smtpd.auth and the SMTP Relay is restarted.

If this is not configured, you may find that users are unable to send messages using SWA.


Thanks.... left the post up and the resolution in case anyone else runs across this...

Valerion
Scalix Star
Scalix Star
Posts: 2730
Joined: Thu Feb 26, 2004 7:40 am
Location: Johannesburg, South Africa
Contact:

Postby Valerion » Wed Feb 28, 2007 5:46 am

Glad you got it sorted out.

As an aside, for other people doing troubleshooting, is to use sxpamauth. Create a file in ~/sys/pam.d called pamcheck, containing your rules (copy ual.remote to this file). Right at the top add

auth required om_debug

then run

sxpamauth "User Name"

I managed to trace a Kerberos authentication failure to a clock skew issue this way. Useful if you're not sure where the exact problem is.


Return to “Installation”



Who is online

Users browsing this forum: No registered users and 16 guests