Secure LDAP to log into macOS with Google credentials

jstaime
New Contributor III

Good Day Team, 

I really need some assistance on this one...I would normally do research and test bed this, but we have a pressing situation going on at the moment preventing this...

 

Have any of you been able to successfully implement this? 

 

https://workspaceupdates.googleblog.com/2020/12/secure-ldap-mac-os-google-login.html

 

If so, what were your challenges, success, "wish I had knowns" and so forth? 

 

Any thoughts would be appreciated!!!

 

6 REPLIES 6

rdnixon
Contributor

We use it on a limited number of devices. Works fine. Faff to setup on the machine you use to clone to start with and the Google instructions are not that clear or I recall entirely accurate. Took a morning of fiddling to get it working.

Kim_Nilsson
Admin Moderator

I got halfway, and then gave up as we, at the time, didn't have an MDM, nor do I ever want to touch new devices before the user logs in the first time. Now we have Mosyle, and just ponied up the cash for oneK12-version, so we can look into using their own Mosyle Auth 2, which will let users log into their Macs with their Workspace credentials.

An alternative I have been looking into a little is Xcreds. Cheap and can be free if you compile it yourself.

--
https://wheretofind.me/@NoSubstitute

jasoncrcsd
Contributor II

We use an MDM called Mosyle it has a google auth ability we use. I wasn;t aware we could do it with just Google. I'll have to try this if we ever get rid of our MDM

jstaime
New Contributor III

Thanks everyone for your response. We are going to dig into this. Glad to know @rdnixon it is working for you. Going to do our own deep dive now. 


Thanks, 

lmcadams
New Contributor II

I wanted to use this to reduce our reliance on Active Directory for a Mac Lab with JAMF, but was unsuccessful.   The JAMF implementation could not support using it for logging into/authenticated on a mac.  I was able to successfully use the secure LDAP to log in and validate with a 3rd party application.  

Hope this help!

Kim_Nilsson
Admin Moderator

Yeah, the problem with Google's Secure LDAP is the same as with Google's SAML.

Google just doesn't support enough of the expected attributes for it to work with other modern secure systems.

--
https://wheretofind.me/@NoSubstitute