<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[LDAP for Win10 Authentication/Authorization with pGina]]></title><description><![CDATA[<p dir="auto"><strong>tl;dr</strong>:<br />
Has anybody got a working setup for using pGina for Win10 Authentication/Authorization with the Cloudron built-in LDAP-Server?</p>
<p dir="auto">Hi everybody,</p>
<p dir="auto">I am currently trying to generate a setup for a client where he can have his primary user-management in Cloudron as he will mostly use the Web-Services anyway. The client now requested that the Login for his Windows10 machines should also use the same login.</p>
<p dir="auto">One Google-Search (and 2 ChatGPT prompts) later I found that there is the <a href="http://pgina.org/" target="_blank" rel="noopener noreferrer nofollow ugc">pGina</a> Project which allows to do just that.</p>
<p dir="auto">After <a href="https://docs.foxpass.com/docs/windows-ldap-auth-with-pgina" target="_blank" rel="noopener noreferrer nofollow ugc">following some Tutorials</a> and tinkering around with the setup, I can get my machine to Authenticate to the LDAP Server correctly:</p>
<p dir="auto"><img src="/assets/uploads/files/1704298166250-e6d0ea6d-a636-4ff0-b9e4-66fd0a22926f-image.png" alt="e6d0ea6d-a636-4ff0-b9e4-66fd0a22926f-image.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">However the Authorization part does not work currently:<br />
<img src="/assets/uploads/files/1704298296995-a4d95970-4ab6-4ae3-9a40-f8cff359aba9-image.png" alt="a4d95970-4ab6-4ae3-9a40-f8cff359aba9-image.png" class=" img-fluid img-markdown" /><br />
If in the Authorization Rule-Set, I set Default to allow, it will allow access without checking if my given user is part of the Group, that I care about as specified in the rule-set below. Which is not the behavior I want to have.</p>
<p dir="auto">I can check with other tools like <a href="https://www.jxplorer.org/" target="_blank" rel="noopener noreferrer nofollow ugc">JXplorer</a> that the User I am testing actually is in the group I care about: <img src="/assets/uploads/files/1704298496941-027971cb-411d-43e2-89f2-d4c8300d81b6-image-resized.png" alt="027971cb-411d-43e2-89f2-d4c8300d81b6-image.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">Did anybody try something similar and succeed here? Would love to get your insights on this <img src="https://forum.cloudron.io/assets/plugins/nodebb-plugin-emoji/emoji/android/1f642.png?v=af5271e93de" class="not-responsive emoji emoji-android emoji--slightly_smiling_face" style="height:23px;width:auto;vertical-align:middle" title=":-)" alt="🙂" /></p>
<p dir="auto">Best regards,<br />
Jan</p>
]]></description><link>https://forum.cloudron.io/topic/10780/ldap-for-win10-authentication-authorization-with-pgina</link><generator>RSS for Node</generator><lastBuildDate>Wed, 15 Jul 2026 01:12:12 GMT</lastBuildDate><atom:link href="https://forum.cloudron.io/topic/10780.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 03 Jan 2024 16:17:38 GMT</pubDate><ttl>60</ttl></channel></rss>