[Freeipa-users] Re: rlm_ldap fails to extract user groups but ldapsearch succeeds

2020-08-06 Thread Alexander Bokovoy via FreeIPA-users
On to, 06 elo 2020, Victor via FreeIPA-users wrote: Hello Alexander, [06/Aug/2020:08:58:31.135610842 +0200] conn=719 fd=104 slot=104 connection from X.X.X.X to Y.Y.Y.Y [06/Aug/2020:08:58:31.135957181 +0200] conn=719 op=0 BIND dn="" method=128 version=3 [06/Aug/2020:08:58:31.136093561 +0200] c

[Freeipa-users] Re: rlm_ldap fails to extract user groups but ldapsearch succeeds

2020-08-06 Thread Victor via FreeIPA-users
Hello Alexander, [06/Aug/2020:08:58:31.135610842 +0200] conn=719 fd=104 slot=104 connection from X.X.X.X to Y.Y.Y.Y [06/Aug/2020:08:58:31.135957181 +0200] conn=719 op=0 BIND dn="" method=128 version=3 [06/Aug/2020:08:58:31.136093561 +0200] conn=719 op=0 RESULT err=0 tag=97 nentries=0 etime=0.0

[Freeipa-users] Re: rlm_ldap fails to extract user groups but ldapsearch succeeds

2020-08-06 Thread Alexander Bokovoy via FreeIPA-users
On to, 06 elo 2020, Victor via FreeIPA-users wrote: Hello Rob, The problem is the logs indicate the exact same search request (only timeLimit differs: 10 vs 0) and bind credentials which in the case of rlm_ldap request fail and succeed for ldapsearch: [06/Aug/2020:08:58:31.136692919 +0200] co

[Freeipa-users] Re: rlm_ldap fails to extract user groups but ldapsearch succeeds

2020-08-06 Thread Victor via FreeIPA-users
Hello Rob, The problem is the logs indicate the exact same search request (only timeLimit differs: 10 vs 0) and bind credentials which in the case of rlm_ldap request fail and succeed for ldapsearch: [06/Aug/2020:08:58:31.136692919 +0200] conn=718 op=2 BIND dn="uid=baseuser,cn=users,cn=account

[Freeipa-users] Re: rlm_ldap fails to extract user groups but ldapsearch succeeds

2020-08-05 Thread Rob Crittenden via FreeIPA-users
Victor via FreeIPA-users wrote: > Hello, > > Everything is set up on the same machine as described here: > https://www.freeipa.org/page/Using_FreeIPA_and_FreeRadius_as_a_RADIUS_based_software_token_OTP_system_with_CentOS/RedHat_7 > > I'm trying to check whether a user belongs to a group or not: >