CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA or CCSE One-Week Certification Training Courses with CPUG in Beautiful San Francisco!
    R70 CCSA Courses Starting (2010) 6/7, 7/12, 8/9, 10/11, 11/8, 12/6.  R70 CCSE Courses Starting (2010) 8/16.
2. CPUG CON 2010 EUROPE, the User Conference in Switzerland, September 20th-22nd, 2010!
3. Join Our CPUG Groups On LinkedIn and Facebook.  See Our Channel on YouTube.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SmartDirectory/LDAP/Active Directory
Register Projects FAQ Members List Social Groups Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 2006-10-26
Senior Member
 
Join Date: 2006-10-03
Location: Offenbach/ Germany
Posts: 147
Rep Power: 4
Yasushi Kono has an average reputation (10+)
Default OpenLDAP Integration failed!

Hi everybody,

I could solve the SunONE Directory Server Integration problem!
Although the RootDN is displayed as cn=Directory Manager, you have to type "cn=directory manager" in the LDAP Account Unit of Check Point.
Another strange thing is, that as far as you created another administrator, his RootDN is NOT cn=dsadmin,ou=support,dc=company,dc=com but:uid=dsadmin,ou=support,dc=company,dc=com!!!!!

This is true although an entry with cn= is created for that particular user! As a Novell CNE and CNI, it is not very intuitive for me to unterstand the philosophy of the naming convention of Sun ONE Directory Server!

The other problem I have is the integration of OpenLDAP with Check Point. Although, I can browse the Directory with LDAPBrowser (Softerra), I cannot authenticate the LDAP Account Unit with the same RootDN! One ugly thing is, if you use an anonymous BIND with your Internet Explorer like this:
ldap://10.20.30.210/dc=konolab,dc=com??sub?(objectclass=*)
you will get one object, which correspond to that of the Manager
But, if you type:
ldap://10.20.30.210/dc=konolab,dc=com??sub?uid=*
you won't get any one user object. So, the Manager does not reside within the Domain dc=konolab,dc=com. This seems to be the crucial problem, which has to be solved in order to be successful with the whole integration!

Any ideas?
Any hint will highly be appreciated!
Thank you in advance,
Yasushi
Reply With Quote
Reply

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 05:59.


Powered by vBulletin® Version 3.8.5
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.5.1