This forum is closed to new posts and responses. Individual names altered for privacy purposes. The information contained in this website is provided for informational purposes only and should not be construed as a forum for customer support requests. Any customer support requests should be directed to the official HCL customer support channels below:

HCL Software Customer Support Portal for U.S. Federal Government clients
HCL Software Customer Support Portal


Jun 7, 2013, 6:42 PM
20 Posts

Trying to use AD LDAP for iNotes authentication

  • Category: Administration,iNotes
  • Platform: Windows
  • Release: 9.0
  • Role: Administrator
  • Tags: inotes,Active Directory,LDAP,Directory Assistance
  • Replies: 4
Hoping someone can offer assistance.

I have a secondary addressbook that my students are all in. I have Directory Assistance setup pointing to the StudentNab (Student Addressbook) and my students are able to successfully log into their iNotes email accounts. We are looking to switch it over so the students authenticate with their Active Directory accounts. I created a new Directory Assistance and setup it up to search against the Active Directory LDAP.

I tested it out and with a couple of student and ran into a couple of issues.

A.) We are using the WebmailRedirect DB. When I log in as a student, the student authenticates as the Web Mail redirect goes to the Redirecting page. But instead of going to the student mailfile, the browser goes to http://<server>/Mail/.nsf and not the students mailfile.

B.) I tried to authenticate directly to the students mailfile, bypassing the WebmailRedirect. I again authenticated, but got a right error:




So it would appear to be using the AD hierarchical information. I would really like to keep using the Webmail redirect if possible. Any idea what is occurring in both situations?


Thanks
Jun 7, 2013, 8:25 PM
34 Posts
Fullname

Hi,

you have to add the ADD hierarchical name as a additional fullname to each student, then the lookup for mailfile gets the right redirect address.

Regards

Chris

Jun 10, 2013, 7:13 PM
20 Posts
Thank you Christopher.....
Thank you for the information Christopher.  Adding the Active Directory hierarchical name to the ACL of the student mailfile allowed us to authenticate to the person mailfile with his AD credentials.

Any suggestions on using the webmail redirect database with this?  When I go to the email web site, it brings up the WebMailredirect.nsf db first.  If I enter the AD credentials, it will redirect to http://<EmailServer>/.nsf instead of the students mailfile.  If I put in the URL to the student's mailfile and enter the credentials, we get into the mail file no problem.


Thanks again
Jun 11, 2013, 12:52 PM
34 Posts
Add the hierachical name to fullname

I'm sure, that you have to add the hierachical AD name to the person document of your users, that's the only way, that the redirect database may find the user mailfile.

I don't know your complete environment, perhaps you must delete the http password in the person document, then the login goes against AD (through Directory Assistance).

 

Regards

Chris

Jun 20, 2013, 12:41 PM
20 Posts
Thank you Christoph
Everything is working fine now.  Adding the hierarchical name to the person doc and mail file.  We also then setup our directory catalog to point to the secondary addressbook as search order 1 with no authentication and then search order number 2 was our AD LDAP with authentication.  Works like a charm.  Now to try to figure out using AD LDAP with my primary addressbook.


Thanks again,

This forum is closed to new posts and responses. Individual names altered for privacy purposes. The information contained in this website is provided for informational purposes only and should not be construed as a forum for customer support requests. Any customer support requests should be directed to the official HCL customer support channels below:

HCL Software Customer Support Portal for U.S. Federal Government clients
HCL Software Customer Support Portal