<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40"><head><META HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=us-ascii"><meta name=Generator content="Microsoft Word 15 (filtered medium)"><style><!--
/* Font Definitions */
@font-face
        {font-family:"Cambria Math";
        panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0in;
        margin-bottom:.0001pt;
        font-size:11.0pt;
        font-family:"Calibri",sans-serif;}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:#0563C1;
        text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
        {mso-style-priority:99;
        color:#954F72;
        text-decoration:underline;}
span.EmailStyle17
        {mso-style-type:personal-compose;
        font-family:"Calibri",sans-serif;
        color:windowtext;}
.MsoChpDefault
        {mso-style-type:export-only;}
@page WordSection1
        {size:8.5in 11.0in;
        margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
        {page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]--></head><body lang=EN-US link="#0563C1" vlink="#954F72"><div class=WordSection1><p class=MsoNormal>Hello, <o:p></o:p></p><p class=MsoNormal> I cannot seem to get AD authentication to work properly. I am able to use the ldapserch tool to connect and pull information from my lab setup; however, when I attempt to login I keep getting “Authentication Error, The Username and Password was incorrect”. I’ve included the ldapsearch text and my AD portion preferences.php file that I’m using for my AD bind. Can anyone offer a suggestion as to where to look for my mistake? <span style='color:#1F497D'><o:p></o:p></span></p><p class=MsoNormal><o:p> </o:p></p><p class=MsoNormal>ldapsearch -x -LLL -E pr=200/noprompt -h 192.168.1.142 -D 'ad@dixon.local' -w 'Password' -b 'OU=staff,DC=dixon,DC=local' -s sub '(sAMAccountName=*)'<o:p></o:p></p><p class=MsoNormal><o:p> </o:p></p><p class=MsoNormal><o:p> </o:p></p><p class=MsoNormal> 'authenticator' => 'AD',<o:p></o:p></p><p class=MsoNormal> 'authLDAPBaseDN1' => array('OU=staff,DC=dixon,DC=local'),<o:p></o:p></p><p class=MsoNormal> 'authLDAPServers1' => array('192.168.1.142'),<o:p></o:p></p><p class=MsoNormal> 'authLDAPAccountSuffix1' => '@dixon.local',<o:p></o:p></p><p class=MsoNormal> 'authLDAPUseSSL1' => false,<o:p></o:p></p><p class=MsoNormal> 'authLDAPBindUser1' => 'ad@dixon.local',<o:p></o:p></p><p class=MsoNormal> 'authLDAPBindPass1' => 'Password',<o:p></o:p></p><p class=MsoNormal> 'authLDAPOrganization1' => 'Dixon',<o:p></o:p></p><p class=MsoNormal> // If you are not using this 2nd set of settings for a 2nd AD forest,<o:p></o:p></p><p class=MsoNormal> // do not comment them out, but instead set them to be empty.<o:p></o:p></p><p class=MsoNormal> 'authLDAPBaseDN2' => '',<o:p></o:p></p><p class=MsoNormal> // Set<o:p></o:p></p><p class=MsoNormal> // 'authLDAPServers2' => array(),<o:p></o:p></p><p class=MsoNormal> // if you only have to search 1 AD forest/domain.<o:p></o:p></p><p class=MsoNormal> 'authLDAPServers2' => array(),<o:p></o:p></p><p class=MsoNormal> 'authLDAPAccountSuffix2' => '',<o:p></o:p></p><p class=MsoNormal> 'authLDAPUseSSL2' => false, <o:p></o:p></p><p class=MsoNormal> 'authLDAPBindUser2' => '',<o:p></o:p></p><p class=MsoNormal> 'authLDAPBindPass2' => '',<o:p></o:p></p><p class=MsoNormal> 'authLDAPOrganization2' => '',<o:p></o:p></p><p class=MsoNormal><o:p> </o:p></p><p class=MsoNormal>Thanks,<o:p></o:p></p><p class=MsoNormal><o:p> </o:p></p><p class=MsoNormal>Chris Dixon<o:p></o:p></p></div></body></html>