Return-Path: X-Original-To: archive-asf-public-internal@cust-asf2.ponee.io Delivered-To: archive-asf-public-internal@cust-asf2.ponee.io Received: from cust-asf.ponee.io (cust-asf.ponee.io [163.172.22.183]) by cust-asf2.ponee.io (Postfix) with ESMTP id 6DC33200CA4 for ; Wed, 7 Jun 2017 12:55:04 +0200 (CEST) Received: by cust-asf.ponee.io (Postfix) id 6C635160BD0; Wed, 7 Jun 2017 10:55:04 +0000 (UTC) Delivered-To: archive-asf-public@cust-asf.ponee.io Received: from mail.apache.org (hermes.apache.org [140.211.11.3]) by cust-asf.ponee.io (Postfix) with SMTP id B4584160BB6 for ; Wed, 7 Jun 2017 12:55:03 +0200 (CEST) Received: (qmail 11549 invoked by uid 500); 7 Jun 2017 10:54:57 -0000 Mailing-List: contact user-help@guacamole.incubator.apache.org; run by ezmlm Precedence: bulk List-Help: List-Unsubscribe: List-Post: List-Id: Reply-To: user@guacamole.incubator.apache.org Delivered-To: mailing list user@guacamole.incubator.apache.org Received: (qmail 11539 invoked by uid 99); 7 Jun 2017 10:54:57 -0000 Received: from pnap-us-west-generic-nat.apache.org (HELO spamd2-us-west.apache.org) (209.188.14.142) by apache.org (qpsmtpd/0.29) with ESMTP; Wed, 07 Jun 2017 10:54:57 +0000 Received: from localhost (localhost [127.0.0.1]) by spamd2-us-west.apache.org (ASF Mail Server at spamd2-us-west.apache.org) with ESMTP id 74CE91AFE53 for ; Wed, 7 Jun 2017 10:54:57 +0000 (UTC) X-Virus-Scanned: Debian amavisd-new at spamd2-us-west.apache.org X-Spam-Flag: NO X-Spam-Score: 2.099 X-Spam-Level: ** X-Spam-Status: No, score=2.099 tagged_above=-999 required=6.31 tests=[HTML_MESSAGE=2, KAM_UNSUB1=0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001] autolearn=disabled Received: from mx1-lw-eu.apache.org ([10.40.0.8]) by localhost (spamd2-us-west.apache.org [10.40.0.9]) (amavisd-new, port 10024) with ESMTP id t7WGbUe94N5E for ; Wed, 7 Jun 2017 10:54:53 +0000 (UTC) Received: from ns1.horiba.co.jp (ns1.horiba.co.jp [202.250.32.2]) by mx1-lw-eu.apache.org (ASF Mail Server at mx1-lw-eu.apache.org) with ESMTP id 24B8F5F2AE for ; Wed, 7 Jun 2017 10:54:51 +0000 (UTC) Received: from ns2b.horiba.co.jp (ns2b.horiba.co.jp [202.250.36.23]) by ns1.horiba.co.jp (Postfix) with ESMTP id 5332D88908 for ; Wed, 7 Jun 2017 19:54:45 +0900 (JST) Received: from SRHDC1.SRH.local ([149.240.170.254]) by ns2b.horiba.co.jp (8.12.11/8.12.11) with ESMTP id v57Ashhe003194 for ; Wed, 7 Jun 2017 19:54:44 +0900 Received: from SRHDC1.SRH.local ([fe80::6c34:22f8:200d:757b]) by SRHDC1.SRH.local ([fe80::6c34:22f8:200d:757b%10]) with mapi id 14.03.0319.002; Wed, 7 Jun 2017 11:54:42 +0100 From: Andy Pattrick To: "user@guacamole.incubator.apache.org" Subject: RE: LDAP_USER_BASE_DN pointing to an AD Security Group Thread-Topic: LDAP_USER_BASE_DN pointing to an AD Security Group Thread-Index: AQHS3syOzlO7nf/DZ0SUjDON5i3RBaIYzfuAgABHwBH///9DAIAAJb8n Date: Wed, 7 Jun 2017 10:54:41 +0000 Message-ID: <0B640BC754C823498D4BFFC8F94A25F601E2E430@SRHDC1.SRH.local> References: <0B640BC754C823498D4BFFC8F94A25F601E2DCB6@SRHDC1.SRH.local> <7836d37b-de1c-599f-b9d2-bf8d6bcf62f5@pcfreak.de> <0B640BC754C823498D4BFFC8F94A25F601E2E359@SRHDC1.SRH.local>,<16F07919-C528-4AAB-B3CE-5774F2F1267A@ospedaliriuniti.marche.it> In-Reply-To: <16F07919-C528-4AAB-B3CE-5774F2F1267A@ospedaliriuniti.marche.it> Accept-Language: en-GB, en-US Content-Language: en-GB X-MS-Has-Attach: X-MS-TNEF-Correlator: x-originating-ip: [109.151.217.227] Content-Type: multipart/alternative; boundary="_000_0B640BC754C823498D4BFFC8F94A25F601E2E430SRHDC1SRHlocal_" MIME-Version: 1.0 archived-at: Wed, 07 Jun 2017 10:55:04 -0000 --_000_0B640BC754C823498D4BFFC8F94A25F601E2E430SRHDC1SRHlocal_ Content-Type: text/plain; charset="Windows-1252" Content-Transfer-Encoding: quoted-printable Hi Marco, Thanks for your reply. That's exactly what I would like to do but unfortuna= tely I am running guacamole in docker so I'm not sure I can use this patch = very easily. Hopefully this will find it's way into the official docker ima= ge. Cheers Andy ________________________________ From: Marco Casavecchia Morganti [marco.casavecchia@ospedaliriuniti.marche.= it] Sent: 07 June 2017 10:37 To: user@guacamole.incubator.apache.org Subject: Re: LDAP_USER_BASE_DN pointing to an AD Security Group Hello, I developed a small patch for the guacamole-auth-ldap extension that allows= you to specify in the guacamole.properties a new property: ldap-users-filt= er. Basically if you apply the patch, you can add an LDAP condition that must b= e satisfied by the users to become guacamole users. So if you set it as som= ething like this: ldap-users-filter: memberOf=3DCN=3DGuacamole,OU=3DService Gropus,OU=3DDomai= n,DC=3Dmy,DC=3Dlan only the users that belongs to the specified group will be listed in the gu= acamole interface and will be allowed to access Guacamole. At that time I tried to submit the patch to the developers but I wasn=92t a= ble to set up the whole environment needed to do that, so I gave up, hoping= that my patch would be added by someone else sooner or later. The patch is very simple and you can find it attached to this mail. I applied it successfully to the latest incubating releases (0.9.11 and 0.9= .12), I hope it will be helpful. Best Regards =97 MCM Click here to report this= email as spam. --_000_0B640BC754C823498D4BFFC8F94A25F601E2E430SRHDC1SRHlocal_ Content-Type: text/html; charset="Windows-1252" Content-Transfer-Encoding: quoted-printable

Hi Marco,

 

Thanks for your reply. That's exactly what I would like to do but unfort= unately I am running guacamole in docker so I'm not sure I can use this pat= ch very easily. Hopefully this will find it's way into the official docker = image.

 

Cheers Andy

 

From: Marco Casavecchia Morganti [marco.ca= savecchia@ospedaliriuniti.marche.it]
Sent: 07 June 2017 10:37
To: user@guacamole.incubator.apache.org
Subject: Re: LDAP_USER_BASE_DN pointing to an AD Security Group

Hello,
I developed a small patch for the guacamole-auth-ldap extension that a= llows you to specify in the guacamole.properties a new property: ldap-us= ers-filter.

Basically if you apply the patch, you can add an LDAP condition that m= ust be satisfied by the users to become guacamole users. So if you set it a= s something like this: 
ldap-users-filter: memberOf=3DCN=3DGuacamole,OU=3DService Grop= us,OU=3DDomain,DC=3Dmy,DC=3Dlan 
only the users that belongs to the specified group will be listed in t= he guacamole interface and will be allowed to access Guacamole.

At that time I tried to submit the patch to the developers but I wasn= =92t able to set up the whole environment needed to do that, so I gave up, = hoping that my patch would be added by someone else sooner or later.

The patch is very simple and you can find it attached to this mail.
I applied it successfully to the latest incubating releases (0.9.11 an= d 0.9.12), I hope it will be helpful.

Best Regards

=97
MCM



Click here to report this email as spam.

--_000_0B640BC754C823498D4BFFC8F94A25F601E2E430SRHDC1SRHlocal_--