<html>
<head>
<meta content="text/html; charset=ISO-8859-1"
http-equiv="Content-Type">
</head>
<body bgcolor="#FFFFFF" text="#000000">
On 01/28/2014 03:33 PM, Guillermo Fuentes wrote:
<blockquote
cite="mid:CAMAAbqUXM3_dTRZW_H_wSX9D5=usK_JqWZs+nyZUbS4rwmzCzw@mail.gmail.com"
type="cite">
<div dir="ltr">
<p class="MsoNormal">Hello,</p>
<p class="MsoNormal"> </p>
<p class="MsoNormal">We are deploying FreeIPA (which it’s a
great project BTW) as
our Identity Management System. As we don’t want any info from
the directory to be
publically available, we tried disabling anonymous binds but
it breaks UI
logins on Macs (10.8.5 and 10.9.1)</p>
<p class="MsoNormal"> </p>
<p class="MsoNormal">FreeIPA logs show that OS X retrieves
attributes using
anonymous bind and when it’s disabled it logs:</p>
<p class="MsoNormal">… authzid="(null)", anonymous search not
allowed </p>
<p class="MsoNormal"> </p>
<p class="MsoNormal">Has anyone been able to get this setup
working properly? <br>
</p>
</div>
</blockquote>
<br>
You need to look on the Mac side.<br>
It seems that in the configuration you used Mac tries to do a lookup
after anonymous bind. It might be that you need to configure a
special account on Mac to be able to work around this issue.<br>
<br>
<blockquote
cite="mid:CAMAAbqUXM3_dTRZW_H_wSX9D5=usK_JqWZs+nyZUbS4rwmzCzw@mail.gmail.com"
type="cite">
<div dir="ltr">
<p class="MsoNormal"> </p>
<p class="MsoNormal">Thanks in advance,</p>
<p class="MsoNormal">Guillermo</p>
</div>
<br>
<fieldset class="mimeAttachmentHeader"></fieldset>
<br>
<pre wrap="">_______________________________________________
Freeipa-users mailing list
<a class="moz-txt-link-abbreviated" href="mailto:Freeipa-users@redhat.com">Freeipa-users@redhat.com</a>
<a class="moz-txt-link-freetext" href="https://www.redhat.com/mailman/listinfo/freeipa-users">https://www.redhat.com/mailman/listinfo/freeipa-users</a></pre>
</blockquote>
<br>
<br>
<pre class="moz-signature" cols="72">--
Thank you,
Dmitri Pal
Sr. Engineering Manager for IdM portfolio
Red Hat Inc.
-------------------------------
Looking to carve out IT costs?
<a class="moz-txt-link-abbreviated" href="http://www.redhat.com/carveoutcosts/">www.redhat.com/carveoutcosts/</a>
</pre>
</body>
</html>