guacamole-user mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From Nick Couchman <>
Subject Re: Guacamole ldap-group-base-dn
Date Tue, 17 Oct 2017 18:27:24 GMT
On Tue, Oct 17, 2017 at 2:14 PM, Carter Sema <> wrote:

> I read the following article
> jira/browse/GUACAMOLE-12 when I was looking for how to assign connections
> to LDAP users. From the article it sounds like I can use AD Security
> Groups? Is this possible without updating my Schema? Updating my Schema is
> off the table for options. So im looking for the 2nd best without needing
> to import a ton of users into the guac sql database.

Using that method requires that you store the connection information inside
LDAP, which requires schema modifications.

If you stack authentication modules, like JDBC and LDAP, you can have users
log in with LDAP, make sure those same users are created in JDBC, and then
assign the permissions to the user accounts objects in the JDBC module.  As
long as the LDAP and JDBC usernames match, this will map through.


View raw message