Multiple LDAP Servers?

bumbletech
Contributor III

We might be adding in some users from another LDAP server—we've always had just one. Any gotcha's or things keep in mind as we look at implementing this?

6 REPLIES 6

thoule
Valued Contributor II

I use multiple LDAP servers and don't have any major issues. I do it to a single LDAP server, but I want multiple search bases and don't want to search the whole tree. When I look for an account to assign permissions, I may see it twice (via the different LDAP servers), but not a big deal - pick either of them!

ega
Contributor III

We have 8 LDAP servers in our hosted JSS and they work pretty well. Do be aware that searches for users is done by the ldap configuration id not alpha by name as the list of server configs might imply. Also be aware of name space collisions. If you have 2 servers with user bob in both then only the first bob from the server with the lowest config id will get to login via self service, etc. We have fixed that issue by using the emails instead of username in the mappings (i.e. bob@domainone.com and bob@domaintwo.com). This is not the case however for adding ldap users to a JSS group as you will get a choice of both bobs and can pick. FWIW, we have also done this with multiple JumpCloud instances so you can test out stuff before you get into production.

ega
Contributor III

Also should add that you should be careful on your timeout settings. We have seen login times for Self Service and JSS web console slow down with poor ldap response so keep the time outs short.

Lhsachs
Contributor II

We are merging several divisions into one Casper instance. We have several domains. We are shifting to using email address versus domainID for the lookups so we pull from the right domain.

csa
New Contributor III

@ega - We have 8 LDAP servers in our hosted JSS and they work pretty well.
Can you tell me how you have this setup? Our LDAP servers are on our internal network and I dont know anyone who directly exposes LDAP server over the internet. How do you have 8 LDAP servers configured in JSS?
Thanks in advance for your help...

conitsupport
Contributor

Ok we have taking over a primary school and are going to be uisng ipdas their via Casper / jamf pro, we already have AD setup for our school how do we go about integrating another AD into the system, this must be possible if people are using cloud controllers now????