Hello,
So I am integrating SAML for our MR instance, and everything is setup correctly except for group privileges. In our Shibboleth instance I have released email and memberOf, which looks like this (CN=MunkiReport_Admins,OU=FSMunki,OU=Groups,OU=Admins,OU=Root,DC=ac,DC=REDACTED)
The release looks like this:
<saml2:AttributeStatement>
<saml2:Attribute FriendlyName="mail" Name="urn:oid:0.9.2342.19200300.100.1.3" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
<saml2:AttributeValue>REDACTED ( email was here )</saml2:AttributeValue>
</saml2:Attribute>
<saml2:Attribute FriendlyName="memberOf" Name="http://schemas.xmlsoap.org/claims/Group" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
<saml2:AttributeValue>CN=MunkiReport_Admins,OU=FSMunki,OU=Groups,OU=Admins,OU=Root,DC=ac,DC=REDACTED</saml2:AttributeValue>
</saml2:Attribute>
</saml2:AttributeStatement>
In my env config, I have:
AUTH_SAML_GROUP_ATTR=http://schemas.xmlsoap.org/claims/Group
AUTH_SAML_ALLOWED_GROUPS="CN=MunkiReport_Admins,OU=FSMunki,OU=Groups,OU=Admins,OU=Root,DC=ac,DC=REDACTED"
I am not able to get the env config working, and I have 3 groups I need to add, MunkiReport_Admins being one of them. I have tried every combination of 'CN=MunkiReport_Admins', just 'MunkiReport_Admins', and the full string like above.
Any assistance in figuring out how to troubleshoot this/set it up correctly would be great. Thank you.
--
You received this message because you are subscribed to the Google Groups "munkireport" group.
To unsubscribe from this group and stop receiving emails from it, send an email to munkireport...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/munkireport/83ab3baa-a0b6-4cc4-9c1d-db881a11faab%40googlegroups.com.
After logging in, you can retrieve the SAML group info by visiting:index.php?/auth/set_session_props/1
-Arjen
On 4 Feb 2020, at 19:29, Daniel Anner <danie...@danstechsupport.com> wrote:
Hello,
So I am integrating SAML for our MR instance, and everything is setup correctly except for group privileges. In our Shibboleth instance I have released email and memberOf, which looks like this (CN=MunkiReport_Admins,OU=FSMunki,OU=Groups,OU=Admins,OU=Root,DC=ac,DC=REDACTED)
The release looks like this:
<saml2:AttributeStatement> <saml2:Attribute FriendlyName="mail" Name="urn:oid:0.9.2342.19200300.100.1.3" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"> <saml2:AttributeValue>REDACTED ( email was here )</saml2:AttributeValue> </saml2:Attribute> <saml2:Attribute FriendlyName="memberOf" Name="http://schemas.xmlsoap.org/claims/Group" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"> <saml2:AttributeValue>CN=MunkiReport_Admins,OU=FSMunki,OU=Groups,OU=Admins,OU=Root,DC=ac,DC=REDACTED</saml2:AttributeValue> </saml2:Attribute> </saml2:AttributeStatement>
In my env config, I have:
AUTH_SAML_GROUP_ATTR=http://schemas.xmlsoap.org/claims/Group
AUTH_SAML_ALLOWED_GROUPS="CN=MunkiReport_Admins,OU=FSMunki,OU=Groups,OU=Admins,OU=Root,DC=ac,DC=REDACTED"
I am not able to get the env config working, and I have 3 groups I need to add, MunkiReport_Admins being one of them. I have tried every combination of 'CN=MunkiReport_Admins', just 'MunkiReport_Admins', and the full string like above.
Any assistance in figuring out how to troubleshoot this/set it up correctly would be great. Thank you.
--
You received this message because you are subscribed to the Google Groups "munkireport" group.
To unsubscribe from this group and stop receiving emails from it, send an email to munki...@googlegroups.com.
--
You received this message because you are subscribed to the Google Groups "munkireport" group.
To unsubscribe from this group and stop receiving emails from it, send an email to munkireport...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/munkireport/8ede1682-8425-4bf8-963f-ad6e1c01b3af%40googlegroups.com.
On 7 Feb 2020, at 14:53, Daniel Anner <daniel...@danstechsupport.com> wrote:
Do you happen to have any ideas?
--
You received this message because you are subscribed to the Google Groups "munkireport" group.
To unsubscribe from this group and stop receiving emails from it, send an email to munkireport...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/munkireport/6cb1946e-a31d-4322-acfb-7d6359166779%40googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/munkireport/E5AD8163-A15E-4827-90CF-270EA2B98B22%40mac.com.
On 7 Feb 2020, at 19:05, Daniel Anner <daniel...@danstechsupport.com> wrote:
To view this discussion on the web visit https://groups.google.com/d/msgid/munkireport/CADaXvhmEFrjkWM13Ogig-J0NFrnv8Mu8iBXHbCrMKido359w2w%40mail.gmail.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/munkireport/338FB379-4CB8-471A-87DB-BAED26ADCDAA%40mac.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/munkireport/CADaXvhkFp_qyCgvXpeB%2BX29VGnxTtRQ%2BJrD%2BvXLoxm6RtKV1FQ%40mail.gmail.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/munkireport/95DAB3E1-C641-4F32-90CE-93B216CFD5A7%40mac.com.
On 10 Feb 2020, at 15:48, Daniel Anner <daniel...@danstechsupport.com> wrote:
To view this discussion on the web visit https://groups.google.com/d/msgid/munkireport/CADaXvhk1GZ-Of_tnXrEZQXQrnSirJ%2BOFTE-J1jOBsYBscAETBg%40mail.gmail.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/munkireport/AC6E26DA-CE27-4C33-BB7E-228B4199DA34%40mac.com.
Does that mean that the group is now working?
Not specifying a user and a group assumes that everyone can login. We could change that behavior if that makes better senseSent from my iPhone
On 10 Feb 2020, at 15:48, Daniel Anner <danie...@danstechsupport.com> wrote:
Figured it out, I tested the fix and I am experiencing a weird issue. I have my config as following:AUTH_SAML_USER_ATTR=urn:oid:0.9.2342.19200300.100.1.3
AUTH_SAML_ALLOWED_USERS=""
AUTH_SAML_GROUP_ATTR="http://schemas.xmlsoap.org/claims/Group"
AUTH_SAML_ALLOWED_GROUPS=""And when I attempt to login, it allows me in without any issue. Any idea why I would be able to login without any groups defined?
On Mon, Feb 10, 2020 at 9:34 AM Daniel Anner <danie...@danstechsupport.com> wrote:
I will give it a shot, I am currently receiving a 500 error but I do not see errors in my NGINX or php-fpm logs. I'll keep digging into it and see if I can figure out what the issue is
On Sat, Feb 8, 2020 at 3:12 AM 'A.E. van Bochoven' via munkireport <munki...@googlegroups.com> wrote:
I pushed a fix for your issue to a new branch:Please check out this code and see if that fixes your issue. Note that the code is now replacing ‘,’ with ‘_’ in the group names, so you would need to change the group name in .env toCN=MunkiReport_Admins_OU=FSMunki_OU=Groups_OU=Admins_OU=Root_DC=ac_DC=REDACTED
-Arjen
On 7 Feb 2020, at 19:36, Daniel Anner <danie...@danstechsupport.com> wrote:
Nevermind, that does not work: Failed to parse dotenv file due to an unexpected escape sequence. Failed at ["CN=MunkiReport_Admins\,OU=FSMunki\,OU=Groups\,OU=Admins\,OU=Root\,DC=ac\,DC=REDACTED"].
On Fri, Feb 7, 2020 at 1:32 PM Daniel Anner <danie...@danstechsupport.com> wrote:
We cannot as we have multiple other applications that require memberOf, which are already setup using this format. None of these other applications have issues with the format either. I can try escaping the commas if you think that may be the issue?
On Fri, Feb 7, 2020 at 1:18 PM 'A.E. van Bochoven' via munkireport <munki...@googlegroups.com> wrote:
Any chance your SAML admin is able to map the group to something shorter, without commas?Sent from my iPhoneOn 7 Feb 2020, at 19:05, Daniel Anner <danie...@danstechsupport.com> wrote:
Yes it is, adding my email to allowed users works perfectly fine.
On Fri, Feb 7, 2020, 12:47 'A.E. van Bochoven' via munkireport <munki...@googlegroups.com> wrote:
AUTH_SAML_ALLOWED_USERS Is working for you?Sent from my iPadOn 7 Feb 2020, at 14:53, Daniel Anner <danie...@danstechsupport.com> wrote:
Do you happen to have any ideas?--
You received this message because you are subscribed to the Google Groups "munkireport" group.
To unsubscribe from this group and stop receiving emails from it, send an email to munki...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/munkireport/6cb1946e-a31d-4322-acfb-7d6359166779%40googlegroups.com.
--
You received this message because you are subscribed to the Google Groups "munkireport" group.
To unsubscribe from this group and stop receiving emails from it, send an email to munki...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/munkireport/E5AD8163-A15E-4827-90CF-270EA2B98B22%40mac.com.
--
You received this message because you are subscribed to the Google Groups "munkireport" group.
To unsubscribe from this group and stop receiving emails from it, send an email to munki...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/munkireport/CADaXvhmEFrjkWM13Ogig-J0NFrnv8Mu8iBXHbCrMKido359w2w%40mail.gmail.com.
--
You received this message because you are subscribed to the Google Groups "munkireport" group.
To unsubscribe from this group and stop receiving emails from it, send an email to munki...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/munkireport/338FB379-4CB8-471A-87DB-BAED26ADCDAA%40mac.com.
----Regards,Daniel W. AnnerDan's Tech Support UnlimitedOwner/Operator
----Regards,Daniel W. AnnerDan's Tech Support UnlimitedOwner/Operator--
You received this message because you are subscribed to the Google Groups "munkireport" group.
To unsubscribe from this group and stop receiving emails from it, send an email to munki...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/munkireport/CADaXvhkFp_qyCgvXpeB%2BX29VGnxTtRQ%2BJrD%2BvXLoxm6RtKV1FQ%40mail.gmail.com.
--
You received this message because you are subscribed to the Google Groups "munkireport" group.
To unsubscribe from this group and stop receiving emails from it, send an email to munki...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/munkireport/95DAB3E1-C641-4F32-90CE-93B216CFD5A7%40mac.com.
----Regards,Daniel W. AnnerDan's Tech Support UnlimitedOwner/Operator
------Regards,Daniel W. AnnerDan's Tech Support UnlimitedOwner/Operator
You received this message because you are subscribed to the Google Groups "munkireport" group.
To unsubscribe from this group and stop receiving emails from it, send an email to munki...@googlegroups.com.
--
You received this message because you are subscribed to the Google Groups "munkireport" group.
To unsubscribe from this group and stop receiving emails from it, send an email to munkireport...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/munkireport/1DE60E55-C0C0-487F-BFA6-3B0AD43AC264%40mac.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/munkireport/CADaXvh%3D47AYRY%2BS9hUUt6X7sXBCBSjgjAmmBLY4GVZXYLq4ejw%40mail.gmail.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/munkireport/830F7DBC-AA17-4F23-AFB4-D3B7305F1407%40mac.com.
On 13 Feb 2020, at 14:30, Daniel Anner <daniel...@danstechsupport.com> wrote:
To view this discussion on the web visit https://groups.google.com/d/msgid/munkireport/CADaXvhkyLVi0y3yA65MAX3q7S-%3DUXpmBWM5AeG094VR1TtMfyA%40mail.gmail.com.
It will be in the next release (5.2). But we’ll need some documentation, it would be great if you could write something about your SAML setup in the wiki
ArjenSent from my iPad
On 13 Feb 2020, at 14:30, Daniel Anner <danie...@danstechsupport.com> wrote:
Perfect, everything is working as expected now. Roughly, when can we expect this to be merged into master?
On Wed, Feb 12, 2020 at 3:44 PM 'A.E. van Bochoven' via munkireport <munki...@googlegroups.com> wrote:
Ok, I found a bug in the code. Could you please check out the branch again and test?
-Arjen
To unsubscribe from this group and stop receiving emails from it, send an email to munki...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/munkireport/1DE60E55-C0C0-487F-BFA6-3B0AD43AC264%40mac.com.
----Regards,Daniel W. AnnerDan's Tech Support UnlimitedOwner/Operator--
You received this message because you are subscribed to the Google Groups "munkireport" group.
To unsubscribe from this group and stop receiving emails from it, send an email to munki...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/munkireport/CADaXvh%3D47AYRY%2BS9hUUt6X7sXBCBSjgjAmmBLY4GVZXYLq4ejw%40mail.gmail.com.
--
You received this message because you are subscribed to the Google Groups "munkireport" group.
To unsubscribe from this group and stop receiving emails from it, send an email to munki...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/munkireport/830F7DBC-AA17-4F23-AFB4-D3B7305F1407%40mac.com.
------Regards,Daniel W. AnnerDan's Tech Support UnlimitedOwner/Operator
You received this message because you are subscribed to the Google Groups "munkireport" group.
To unsubscribe from this group and stop receiving emails from it, send an email to munki...@googlegroups.com.
It will be in the next release (5.2). But we’ll need some documentation, it would be great if you could write something about your SAML setup in the wiki
ArjenSent from my iPad
On 13 Feb 2020, at 14:30, Daniel Anner <danie...@danstechsupport.com> wrote:
Perfect, everything is working as expected now. Roughly, when can we expect this to be merged into master?
On Wed, Feb 12, 2020 at 3:44 PM 'A.E. van Bochoven' via munkireport <munki...@googlegroups.com> wrote:
Ok, I found a bug in the code. Could you please check out the branch again and test?
-Arjen
To unsubscribe from this group and stop receiving emails from it, send an email to munki...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/munkireport/1DE60E55-C0C0-487F-BFA6-3B0AD43AC264%40mac.com.
----Regards,Daniel W. AnnerDan's Tech Support UnlimitedOwner/Operator--
You received this message because you are subscribed to the Google Groups "munkireport" group.
To unsubscribe from this group and stop receiving emails from it, send an email to munki...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/munkireport/CADaXvh%3D47AYRY%2BS9hUUt6X7sXBCBSjgjAmmBLY4GVZXYLq4ejw%40mail.gmail.com.
--
You received this message because you are subscribed to the Google Groups "munkireport" group.
To unsubscribe from this group and stop receiving emails from it, send an email to munki...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/munkireport/830F7DBC-AA17-4F23-AFB4-D3B7305F1407%40mac.com.
------Regards,Daniel W. AnnerDan's Tech Support UnlimitedOwner/Operator
You received this message because you are subscribed to the Google Groups "munkireport" group.
To unsubscribe from this group and stop receiving emails from it, send an email to munki...@googlegroups.com.