Spring Security Ldap, log in only users in specified group
Asked Answered
D

3

4

Just like in title, I want that only users of spec. Here is my authentication code:

public void configureGlobal(AuthenticationManagerBuilder auth) throws Exception {

    auth.ldapAuthentication().userSearchFilter("(sAMAccountName={0})")
    .contextSource(contextSource());
}

I found that there are functions like groupSearchFilter and groupSearchBase or groupRoleAttribute but I have no idea how to use them

Desiderate answered 2/6, 2017 at 11:13 Comment(0)
B
3

I made some modifications on Megha's solution

@Configuration
@EnableWebSecurity
public class SecurityConfig extends WebSecurityConfigurerAdapter {

    @Configuration
    protected static class AuthenticationConfiguration extends  GlobalAuthenticationConfigurerAdapter {

        @Override
        public void init(AuthenticationManagerBuilder auth) throws Exception {              
            DefaultSpringSecurityContextSource contextSource = new DefaultSpringSecurityContextSource("ldap://ip:port/DC=xxxx,DC=yyyy");
            contextSource.setUserDn("user_service_account");
            contextSource.setPassword("password_user_service_account");
            contextSource.setReferral("follow"); 
            contextSource.afterPropertiesSet();

            LdapAuthenticationProviderConfigurer<AuthenticationManagerBuilder> ldapAuthenticationProviderConfigurer = auth.ldapAuthentication();

            ldapAuthenticationProviderConfigurer
                .userSearchBase("OU=Users,OU=Servers")
                .userSearchFilter("(&(cn={0})(memberOf=CN=GROUP_NAME,OU=Groups,OU=Servers,DC=xxxx,DC=yyyy))")
                .contextSource(contextSource);
        }
    }

    @Override
    protected void configure(HttpSecurity http) throws Exception {

        http.authorizeRequests()
            .antMatchers("/admin/**").authenticated().and()
            .httpBasic();
    }
}
Bigamy answered 6/1, 2018 at 20:22 Comment(0)
V
2
"(sAMAccountName={0})"

should be replaced with following

"(&(objectCategory=Person)(sAMAccountName=*)(memberOf=cn=entergroup,ou=users,dc=company,dc=com))"

where cn, ou,dc are the specifications of the group in directory

Vitebsk answered 20/8, 2017 at 8:50 Comment(0)
G
0

It depends on how your group membership is set up. Something like the following might work, replacing your group dn and objectclasses as necessary:

groupSearchBase("cn=yourgroup,ou=groups")
groupSearchFilter("(uniqueMember={0})")
Garton answered 2/6, 2017 at 15:6 Comment(0)

© 2022 - 2025 — McMap. All rights reserved.