LDAP BULK PERMISSION

classic Classic list List threaded Threaded
2 messages Options
Reply | Threaded
Open this post in threaded view
|  
Report Content as Inappropriate

LDAP BULK PERMISSION

Michel Z. Santello
Hello,

My Question is, there is any way to give permission to all users from LDAP to a Connection Group? or maybe a way to give permission to a LDAP group to a Connection Group.

I didin't found an answer in Docs page.


I'm using guacamole 0.9.12, my environment is LDAP AUTH + Postgres Database.


Regards.

--
Att,

Michel Z. Santello

Reply | Threaded
Open this post in threaded view
|  
Report Content as Inappropriate

Re: LDAP BULK PERMISSION

Mike Jumper
On Thu, Jul 6, 2017 at 7:43 AM, Michel Z. Santello <[hidden email]> wrote:
> Hello,
>
> My Question is, there is any way to give permission to all users from LDAP
> to a Connection Group? or maybe a way to give permission to a LDAP group to
> a Connection Group.
>
> I didin't found an answer in Docs page.
>

You can grant an LDAP group access to a connection using the "seeAlso"
attribute on the guacConfigGroup representing that connection if you
define the "ldap-group-base-dn" property:

http://guacamole.incubator.apache.org/doc/gug/ldap-auth.html

Any such connections will need to be defined within LDAP, however.
Until the Guacamole extension API has its own support for groups,
there is no way to restrict access to connections defined in
MySQL/PostgreSQL based on LDAP group membership.

- Mike
Loading...