Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Groups
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse

Veyon Community Forum

  1. Home
  2. Help & Troubleshooting
  3. How to debug OpenLDAP

How to debug OpenLDAP

Scheduled Pinned Locked Moved Help & Troubleshooting
3 Posts 2 Posters 225 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • D Offline
    D Offline
    DerAndyK
    wrote on last edited by DerAndyK
    #1

    Hello Veyon team,
    I am trying to get Veyon running with FreeIPA as LDAP source. It works so far, but I have the problem that he can not resolve the "group members". With OpenLDAP there should be members as key. But unfortunately I always get an error message. And the user gets the message that he is not authorized, although he is in the appropriate group.

    Unfortunately I did not manage to set the logging to see what he is trying to do to fix my error. Can you please help me?

    Many greetings
    Andreas

    Paulinenpflege Winnenden e.V.

    jgordonJ 1 Reply Last reply
    0
    • jgordonJ Offline
      jgordonJ Offline
      jgordon
      replied to DerAndyK on last edited by
      #2

      @DerAndyK what user is the user logging in as on the client to access ldap?
      Docs suggest to create a read only user that client use to access ldap.
      Have you tried using ldapaearch or a GUI and bind to the user you use for ldap and see what errors you get?
      Some ldap systems don't store the group membership with the user. Where are you attempting to get group membership from and what attributes are you defining in veyon?
      An ldif file and/or screenshots would help of both your ldap layout and the client errors etc.

      1 Reply Last reply
      0
      • jgordonJ Offline
        jgordonJ Offline
        jgordon
        wrote on last edited by
        #3

        This is what I have setup for OpenLDAP, if it helps.

        In OpenLDAP it uses multiple memberUid's for members of groups.

        ldap-group-membership.png

        These setting seem to work with my limited testing and knowledge.

        veyon-env-settings.png

        I changed the group member identification and filtered objects on the different OU's and then used the test to ensure I got back the right objects.

        veyon-advanced-settings.png

        1 Reply Last reply
        0

        Powered by NodeBB | Contributors
        • Login

        • Don't have an account? Register

        • Login or register to search.
        • First post
          Last post
        0
        • Categories
        • Recent
        • Tags
        • Popular
        • Users
        • Groups