Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations biv343 on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Why does LDAP viewing of field depend upon user bound as?

Status
Not open for further replies.

cchipman

IS-IT--Management
Sep 16, 2002
125
US
I've been playing with the LDAP bind function on Active Directory (Window 2K). However, it seems like the viewability (and searchability) of the accounts are dependent upon which type of account you bind with. For example, when I bind with an Administrator account, I all of the groups accounts a user account is a member of, while when I bind with a single user account, I can only see a few accounts membership.

How do I control this? I want to have a PHP script that allows users to see who's in which business area of the company (defined by membership in a group) without having to hardcode the password of the admin account into a file.

Any ideas?
 
That is not a function of PHP, that is something you configure in your LDAP server.
 
Indeed it was. Turns out the for some reason the default property viewing rights for a basic domain user were not set to be able to view the "memberOf" field. Now it is fixed.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top