<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	
	>
<channel>
	<title>
	Comments on: Configuring pfSense authentication through Synology LDAP server	</title>
	<atom:link href="https://geekistheway.com/2020/07/12/configuring-pfsense-authentication-through-synology-ldap-server/feed/" rel="self" type="application/rss+xml" />
	<link>https://geekistheway.com/2020/07/12/configuring-pfsense-authentication-through-synology-ldap-server/</link>
	<description>Trying to learn just a bit!</description>
	<lastBuildDate>Mon, 30 Dec 2024 18:02:18 +0000</lastBuildDate>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	
	<item>
		<title>
		By: Andy		</title>
		<link>https://geekistheway.com/2020/07/12/configuring-pfsense-authentication-through-synology-ldap-server/#comment-220</link>

		<dc:creator><![CDATA[Andy]]></dc:creator>
		<pubDate>Sun, 06 Mar 2022 03:31:29 +0000</pubDate>
		<guid isPermaLink="false">http://crepaldi.us/?p=312#comment-220</guid>

					<description><![CDATA[Just to add; I&#039;ve gotten the authenticated connection working using a client specific profile, but the memberOf steps and changing to STARTTLS both currently break the connection (authentication fails) if I add either of those steps).  Any ideas what I may be missing here?  I have left &#039;disallow anonymous binds&#039; and &#039;force secure connections&#039; both off at this stage.

I can see the following; Synology DSM can connect to Synology LDAP Server using STARTTLS locally, MacOS doesn&#039;t support disallowing anonymous binds from what I can gather/research (I haven&#039;t gotten MacOS to connect yet - I don&#039;t get an authentication failure but after entering user credentials, it just presents the spinning wheel icon forever until you force restart).

I have also changed the SSL cert for Synology LDAP Server to use the certificate I created from your ACME SSL guide (I&#039;ve tried this and the default, neither seem to work).

I have also checked nothing funny with firewall rules potentially blocking ports, I&#039;m currently trying to figure out how to check any logs for hints as to what the problem may be.

Regards
Andy]]></description>
			<content:encoded><![CDATA[<p>Just to add; I&#8217;ve gotten the authenticated connection working using a client specific profile, but the memberOf steps and changing to STARTTLS both currently break the connection (authentication fails) if I add either of those steps).  Any ideas what I may be missing here?  I have left &#8216;disallow anonymous binds&#8217; and &#8216;force secure connections&#8217; both off at this stage.</p>
<p>I can see the following; Synology DSM can connect to Synology LDAP Server using STARTTLS locally, MacOS doesn&#8217;t support disallowing anonymous binds from what I can gather/research (I haven&#8217;t gotten MacOS to connect yet &#8211; I don&#8217;t get an authentication failure but after entering user credentials, it just presents the spinning wheel icon forever until you force restart).</p>
<p>I have also changed the SSL cert for Synology LDAP Server to use the certificate I created from your ACME SSL guide (I&#8217;ve tried this and the default, neither seem to work).</p>
<p>I have also checked nothing funny with firewall rules potentially blocking ports, I&#8217;m currently trying to figure out how to check any logs for hints as to what the problem may be.</p>
<p>Regards<br />
Andy</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Andy		</title>
		<link>https://geekistheway.com/2020/07/12/configuring-pfsense-authentication-through-synology-ldap-server/#comment-218</link>

		<dc:creator><![CDATA[Andy]]></dc:creator>
		<pubDate>Mon, 28 Feb 2022 21:45:34 +0000</pubDate>
		<guid isPermaLink="false">http://crepaldi.us/?p=312#comment-218</guid>

					<description><![CDATA[Hi Thiago,

Again - great guides thanks.  I can get this working without authenticating the connection, without SSL/STARTTLS, and without the LDAP group filter to pfsense_admins, but adding any of those steps results in pfsense not being able to connect to the Synology LDAP server.

A couple of questions, when you use STARTTLS (which I am trialling for this project to get my head around things, but I&#039;m not sure whether this will be an issue for me later with MacOS clients I want to try and get working with Synology LDAP server), did you change the certificate in Synology for the LDAP server to the one SSL cert you created previously in Acme?  It isn&#039;t in the instructions so I assumed not (and are just using the self signed cert that is the default), and I can see you also left (in pfSense) the Peer Certificate Authority as Global Root CA rather than switching to R3?

Otherwise I&#039;m scratching my head a bit, particularly around why the group filter and authenticated connections fail (on the later, I&#039;ve been using Client specific user profiles for other services connecting to Synology LDAP, but neither a pfSense specific client user, or the root seem to work for pfSense).

Any thoughts appreciated.

Regards
Andy]]></description>
			<content:encoded><![CDATA[<p>Hi Thiago,</p>
<p>Again &#8211; great guides thanks.  I can get this working without authenticating the connection, without SSL/STARTTLS, and without the LDAP group filter to pfsense_admins, but adding any of those steps results in pfsense not being able to connect to the Synology LDAP server.</p>
<p>A couple of questions, when you use STARTTLS (which I am trialling for this project to get my head around things, but I&#8217;m not sure whether this will be an issue for me later with MacOS clients I want to try and get working with Synology LDAP server), did you change the certificate in Synology for the LDAP server to the one SSL cert you created previously in Acme?  It isn&#8217;t in the instructions so I assumed not (and are just using the self signed cert that is the default), and I can see you also left (in pfSense) the Peer Certificate Authority as Global Root CA rather than switching to R3?</p>
<p>Otherwise I&#8217;m scratching my head a bit, particularly around why the group filter and authenticated connections fail (on the later, I&#8217;ve been using Client specific user profiles for other services connecting to Synology LDAP, but neither a pfSense specific client user, or the root seem to work for pfSense).</p>
<p>Any thoughts appreciated.</p>
<p>Regards<br />
Andy</p>
]]></content:encoded>
		
			</item>
	</channel>
</rss>

<!--
Performance optimized by W3 Total Cache. Learn more: https://www.boldgrid.com/w3-total-cache/?utm_source=w3tc&utm_medium=footer_comment&utm_campaign=free_plugin

Object Caching 53/77 objects using Memcached
Page Caching using Disk: Enhanced 
Lazy Loading (feed)
Minified using Disk
Database Caching 1/40 queries in 0.022 seconds using Redis

Served from: geekistheway.com @ 2026-05-07 15:34:16 by W3 Total Cache
-->