Running with packetFence 6.3.1.
We need to create a separate role on our public WiFi for visiting school aged
children.
I have not had any problems with assigning roles based on AD group membership
before but
this one has me stumped as it flatly refuses to work.
Can you guys cast your eyes over this and let me know what the heck is wrong,
ldapsearch is
not failing but the LDAPSource.pm code is failing to match the memberOf
attribute. Usernames
and passwords have been sanitized to protect the innocent.
====================Authentication.conf==========================
[STUDENT_LDAP]
description=Authenticate against student.fal.ac.uk
password=XXXXXXX
scope=sub
binddn=CN=XXXXXX,OU=Service Accounts,DC=fal,DC=ac,DC=uk
basedn=dc=student,dc=fal,dc=ac,dc=uk
email_attribute=mail
usernameattribute=sAMAccountName
connection_timeout=10
stripped_user_name=yes
encryption=none
dynamic_routing_module=AuthModule
port=3268
type=AD
host=10.11.150.1
[STUDENT_LDAP rule CreateRestrictedUser]
description=
class=authentication
match=all
action0=set_role=RestrictedUser
action1=set_access_duration=1W
condition0=memberOf,equals,CN=Under18,OU=External Student Groups,OU=Domain
Groups,DC=student,DC=fal,DC=ac,DC=uk
[STUDENT_LDAP rule CreateGuestStudentUser]
description=
class=authentication
match=all
action0=set_role=Student
action1=set_access_duration=1W
condition0=SSID,equals,Guest
[STUDENT_LDAP rule CatchAll]
description=
class=authentication
match=all
action0=set_role=Student
action1=set_unreg_date=2017-07-07
=================================================================================
=======================Results of running
PFTEST=====================================
Testing authentication for "gac999999"
Authenticating against STUDENT_LDAP
Authentication SUCCEEDED against STUDENT_LDAP (Authentication successful.)
Matched against STUDENT_LDAP for 'authentication' rules
set_role : Student
set_unreg_date : 2017-07-07
Did not match against STUDENT_LDAP
=================================================================================
===========================contents of
httpd.portal.log================================
Oct 31 12:53:01 httpd.portal(13061) DEBUG: [mac:e0:5f:45:7e:41:8f]
[STUDENT_LDAP CreateRestrictedUser] Searching for
(&(sAMAccountName=gac999999)(memberOf=CN=Under18, OU=External Student Groups,
OU=Domain Groups, DC=student, DC=fal, DC=ac, DC=uk)), from
dc=student,dc=fal,dc=ac,dc=uk, with scope sub
(pf::Authentication::Source::LDAPSource::match_in_subclass)
Oct 31 12:53:01 httpd.portal(13061) DEBUG: [mac:e0:5f:45:7e:41:8f]
[STUDENT_LDAP CreateRestrictedUser] Found 0 results
(pf::Authentication::Source::LDAPSource::match_in_subclass)
=================================================================================
=========Results of running LDAPSEARCH using same filter string as above on the
same user===================================
ldapsearch -v -x -w XXXXXXXX
'(&(sAMAccountName=gac999999)(memberOf=CN=Under18,OU=External Student
Groups,OU=Domain Groups,DC=student,
DC=fal,DC=ac,DC=uk))'
ldap_initialize( <DEFAULT> )
filter: (&(sAMAccountName=gac999999)(memberOf=CN=Under18,OU=External Student
Groups,OU=Domain Groups,DC=student,DC=fal,DC=ac,DC=uk))
requesting: All userApplication attributes
# extended LDIF
#
# LDAPv3
# base <dc=fal,dc=ac,dc=uk> (default) with scope subtree
# filter: (&(sAMAccountName=gac999999)(memberOf=CN=Under18,OU=External Student
Groups,OU=Domain Groups,DC=student,DC=fal,DC=ac,DC=uk))
# requesting: ALL
#
# gac999999, Penryn College Students, Guest Accounts, All Users, student.fal.ac
.uk
dn: CN=gac999999,OU=Penryn College Students,OU=Guest Accounts,OU=All Users,DC=
student,DC=fal,DC=ac,DC=uk
objectClass: top
objectClass: person
objectClass: organizationalPerson
objectClass: user
cn: gac999999
givenName: gac999999
distinguishedName: CN=gac999999,OU=Penryn College Students,OU=Guest Accounts,O
U=All Users,DC=student,DC=fal,DC=ac,DC=uk
instanceType: 4
whenCreated: 20161027150125.0Z
whenChanged: 20161031123633.0Z
displayName: gac999999
uSNCreated: 140589423
memberOf: CN=Under18,OU=External Student Groups,OU=Domain Groups,DC=student,DC
=fal,DC=ac,DC=uk
memberOf: CN=Fal Students,OU=Fal Student Groups,OU=Domain Groups,DC=student,DC
=fal,DC=ac,DC=uk
uSNChanged: 140936620
name: gac999999
objectGUID:: JVJ3AUM560+AMbFtxz6xtg==
userAccountControl: 66048
pwdLastSet: 131220540854781805
primaryGroupID: 513
objectSid:: AQUAAAAAAAUVAAAANNnH5jhfRi/MEokkveYBAA==
sAMAccountName: gac999999
sAMAccountType: 805306368
userPrincipalName: [email protected]
objectCategory: CN=Person,CN=Schema,CN=Configuration,DC=fal,DC=ac,DC=uk
dSCorePropagationData: 16010101000000.0Z
lastLogonTimestamp: 131221161347433241
# search result
search: 2
result: 0 Success
# numResponses: 2
# numEntries: 1
-----------------------------
Falmouth University
-----------------------------
------------------------------------------------------------------------------
Developer Access Program for Intel Xeon Phi Processors
Access to Intel Xeon Phi processor-based developer platforms.
With one year of Intel Parallel Studio XE.
Training and support from Colfax.
Order your platform today. http://sdm.link/xeonphi
_______________________________________________
PacketFence-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/packetfence-users