Quantcast
Channel: PTC Community : Unanswered Discussions - Windchill
Viewing all articles
Browse latest Browse all 3592

Invalid characters in ldap group names: users not allowed to log in

$
0
0

We are currently testing the upgrade from PDMLink 9.1 to 10.1 with a full integration to the company ldap.

Here we see a major problem for us:

It is not allowed to have fwd / in group names that the users in PDMLink are member of. The characters are allowed in ldap but not in PDMLink.

The groups containing the / are not used in PDMLink, but we use other AD groups to control assignments to roles.

This problem means, that we are not able to move to 10.x as the ldap integration is broken.

 

Do any of you see the same problem in 10.x and have you found a work around for this?

 

 

 

More info:

-Issue is not related to usernames we create, but to information in the MS AD pulled by Windchill

-The problem is not seen in user names (have not seen fwd / in user names so far)

-The problem has been detected for users that are member of groups where fwd/ is part of the group dn.

-We cannot control which groups a user is member of – nor the name of the group

-We rely on access to MS AD groups in the setup of Windchill

-The groups in MS AD with fwd/ has an escape \ before the fwd/

-Is it part of the LDAP v3 standard to allow fwd/ if escaped with \.

-we ran windu and it crashes at the part with the / group

-LDAP: error code 34 - 0000208F: LdapErr: DSID-0C090715, comment: Error processing name


Viewing all articles
Browse latest Browse all 3592

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>