# Installing Open OnDemand with LDAP for Authentication

**URL:** <https://discourse.openondemand.org/t/installing-open-ondemand-with-ldap-for-authentication/3505>\
**Category:** Get Help\
**Created:** [May 17, 2024, 11:56pm UTC](https://discourse.openondemand.org/t/installing-open-ondemand-with-ldap-for-authentication/3505 "2024-05-17T23:56:31Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![michael.tang](https://avatars.discourse-cdn.com/v4/letter/m/43a26b/32.png) [@michael.tang](https://discourse.openondemand.org/u/michael.tang)\
**Post date:** [May 17, 2024, 11:56pm UTC](https://discourse.openondemand.org/t/installing-open-ondemand-with-ldap-for-authentication/3505/1 "2024-05-17T23:56:31Z")

</div>

Hello,

I am setting up a test instance of Open OnDemand (version 3.1) on Rocky 9.3. I am able to successfully install Open OnDemand by following the [provided instructions](https://osc.github.io/ood-documentation/latest/installation/install-software.html#).

When I access Open OnDemand via the web browser, I see the message " You have successfully installed Open OnDemand.

However, you now have to configurure authentication for this apache instance. See the authentication documentation for all the options available."

I followed the instructions to configure [OnDemand Dex for LDAP](https://osc.github.io/ood-documentation/latest/authentication/dex.html#configuring-ondemand-dex-for-ldap). However, Open OnDemand does not seem to recognize the authentication module.

I have the following in /etc/ood/config/ood\_portal.yml  
auth:

- ‘AuthType Basic’
- ‘AuthLDAPURL “ldap://:389”’
- ‘AuthBasicProvider ldap’
- ‘Require valid-user’  
connectors:  
- type: ldap  
id: ldap  
name: LDAP  
config:  
host: :389  
insecureSkipVerify: false  
bindDN: cn=admin,dc=organization,dc=com  
bindPW:   
userSearch:  
baseDN: ou=people,dc=organization,dc=com  
filter: “(objectClass=posixAccount)”  
username: uid  
idAttr: uid  
emailAttr: mail  
nameAttr: gecos  
preferredUsernameAttr: uid  
groupSearch:  
baseDN: ou=groups,dc=organization,dc=com  
filter: “(objectClass=posixGroup)”  
userMatchers:  
- userAttr: DN  
groupAttr: member  
nameAttr: cn  
frontend:  
theme: ondemand  
dir: /usr/share/ondemand-dex/web

Is the authentication module configured correctly?

---

<div class="post-metadata">

**Author:** ![hrandquist](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/hrandquist/32/2536_2.png) [@hrandquist](https://discourse.openondemand.org/u/hrandquist)\
**Post date:** [May 20, 2024, 2:51pm UTC](https://discourse.openondemand.org/t/installing-open-ondemand-with-ldap-for-authentication/3505/2 "2024-05-20T14:51:52Z")

</div>

Hello! Is this a direct copy-paste from your ood\_portal.yml? I’m noticing that there is not a key for `dex` before `connectors` and want to sanity check that.

---

<div class="post-metadata">

**Author:** ![michael.tang](https://avatars.discourse-cdn.com/v4/letter/m/43a26b/32.png) [@michael.tang](https://discourse.openondemand.org/u/michael.tang)\
**Post date:** [May 21, 2024, 10:20pm UTC](https://discourse.openondemand.org/t/installing-open-ondemand-with-ldap-for-authentication/3505/3 "2024-05-21T22:20:38Z")

</div>

Thank you @hrandquist . Thanks for catching that. I missed that part when I was copying the snippet in two parts. Before ‘connectors:’, I also have

dex:  
ssl: false  
http\_port: “5556”

---

<div class="post-metadata">

**Author:** ![hrandquist](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/hrandquist/32/2536_2.png) [@hrandquist](https://discourse.openondemand.org/u/hrandquist)\
**Post date:** [May 23, 2024, 5:15pm UTC](https://discourse.openondemand.org/t/installing-open-ondemand-with-ldap-for-authentication/3505/4 "2024-05-23T17:15:43Z")

</div>

Another thing I noticed:

`host: :389` ← You’re only including the port, not the full `host:port`, from [Authentication Through LDAP |](https://dexidp.io/docs/connectors/ldap/) under the Configuration header:

> # Host and optional port of the LDAP server in the form “host:port”.  
> # If the port is not supplied, it will be guessed based on “insecureNoSSL”,  
> # and “startTLS” flags. 389 for insecure or StartTLS connections, 636  
> # otherwise.  
> host: [ldap.example.com:636](http://ldap.example.com:636)

---

<div class="post-metadata">

**Author:** ![michael.tang](https://avatars.discourse-cdn.com/v4/letter/m/43a26b/32.png) [@michael.tang](https://discourse.openondemand.org/u/michael.tang)\
**Post date:** [June 6, 2024, 10:36pm UTC](https://discourse.openondemand.org/t/installing-open-ondemand-with-ldap-for-authentication/3505/5 "2024-06-06T22:36:25Z")

</div>

Thank you @hrandquist. Good catch. I have the LDAP server’s IP address before the port number.

After installing a self-signed SSL certificate, I am now presented with the login screen. However, after entering my user’s username and password, I received the following error: “Login error: failed to connect: LDAP Result Code 200 “Network Error”: EOF”

To troubleshoot the issue, I reduced `connectors` to:

connectors:  
- type: ldap  
id: ldap  
name: LDAP  
config:  
host: \<LDAP\_Server\_IP\>:389  
insecureSkipVerify: true  
userSearch:  
baseDN: ou=people,dc=ood,dc=org  
filter: “(objectClass=posixAccount)”  
username: uid  
idAttr: uid  
preferredUsernameAttr: uid

Am I missing a configuration item? Or does the LDAP server require a SSL certificate?

Thank you

---

<div class="post-metadata">

**Author:** ![volhpc](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/volhpc/32/2291_2.png) [@volhpc](https://discourse.openondemand.org/u/volhpc)\
**Post date:** [June 9, 2024, 7:46am UTC](https://discourse.openondemand.org/t/installing-open-ondemand-with-ldap-for-authentication/3505/6 "2024-06-09T07:46:34Z")

</div>

Hi Michael,

These are my working settings for LDAP authentication in my org:

```auto
auth:
  - "AuthType Basic"
  - "AuthName 'Some Login Title'"
  - "AuthBasicProvider ldap"
  - "AuthLDAPURL 'ldap://<LDAP-SERVER>:389/OU=SOME_OU,DC=SOME_DC?sAMAccountName'"
  - "AuthLDAPGroupAttribute mailNickname"
  - "AuthLDAPGroupAttributeIsDN on"
  - "AuthLDAPBindDN 'DOMAIN\\AD-USER'"
  - "AuthLDAPBindPassword SOMEPASSWORD"
  - "RequestHeader unset Authorization"
  - "Require valid-user"

```

---

<div class="post-metadata">

**Author:** ![michael.tang](https://avatars.discourse-cdn.com/v4/letter/m/43a26b/32.png) [@michael.tang](https://discourse.openondemand.org/u/michael.tang)\
**Post date:** [June 19, 2024, 7:10pm UTC](https://discourse.openondemand.org/t/installing-open-ondemand-with-ldap-for-authentication/3505/7 "2024-06-19T19:10:24Z")

</div>

Thank you all! I successfully set up LDAP authentication for my test environment by including `insecureNoSSL: true` under dex → connectors → config.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex015/uploads/osc/original/2X/b/bae70bd0ed39a3ae769c2108155f4cb3e9da8385.png) [@system](https://discourse.openondemand.org/u/system)\
**Post date:** [December 16, 2024, 7:10pm UTC](https://discourse.openondemand.org/t/installing-open-ondemand-with-ldap-for-authentication/3505/8 "2024-12-16T19:10:48Z")

</div>

This topic was automatically closed 180 days after the last reply. New replies are no longer allowed.
