PWM w/ FreeIPA

211 views
Skip to first unread message

Andrew Meyer

unread,
Aug 30, 2018, 4:05:30 PM8/30/18
to pwm-general
I have pwm setup and i'm using the OpenLDAP profile.  Should I be using 'other' instead?

Andrea Favero

unread,
Aug 30, 2018, 4:09:16 PM8/30/18
to pwm-g...@googlegroups.com
I use OpenLDAP even if my backend is freeIPA

Il gio 30 ago 2018, 22:05 Andrew Meyer <andrew...@gatewayblend.com> ha scritto:
I have pwm setup and i'm using the OpenLDAP profile.  Should I be using 'other' instead?

--
You received this message because you are subscribed to the Google Groups "pwm-general" group.
To unsubscribe from this group and stop receiving emails from it, send an email to pwm-general...@googlegroups.com.
To post to this group, send email to pwm-g...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/pwm-general/652539f3-a779-462c-be1a-7d44154c404a%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.

Andrew Meyer

unread,
Aug 30, 2018, 4:12:53 PM8/30/18
to pwm-g...@googlegroups.com
Ok thanks for the input

Also, I'm having an issue w/ my config.  It won't read the test user account.  

I'm getting this in my logs.

Aug 30 15:06:19 pwm01 server: 2018-08-30T15:06:19Z, ERROR, cluster.ClusterMachine, 5093 ERROR_CLUSTER_SERVICE_ERROR (error writing database cluster heartbeat: 5079 ERROR_LDAP_DATA_ERROR (error writing cluster data: javax.naming.NoPermissionException: [LDAP: error code 50 - Insufficient 'write' privilege to the 'pwmresponseset' attribute of entry 'uid=pwmtest,cn=users,cn=accounts,dc=gatewayblend,dc=net'.







Andrew Meyer
Linux DevOps Engineer
GatewayBlend


Andrea Favero

unread,
Aug 30, 2018, 4:21:04 PM8/30/18
to pwm-g...@googlegroups.com
I could be wrong but that account might need to have admin or smiliar priviliges, that is should be part of Admins group. Try adding it to that group and see what happens

Andrew Meyer

unread,
Aug 30, 2018, 4:29:32 PM8/30/18
to pwm-general
That did not work.  Did you have to do any of the changes described here?


On Thursday, August 30, 2018 at 3:21:04 PM UTC-5, Andrea Favero wrote:
I could be wrong but that account might need to have admin or smiliar priviliges, that is should be part of Admins group. Try adding it to that group and see what happens

Il gio 30 ago 2018, 22:12 Andrew Meyer <andrew...@gatewayblend.com> ha scritto:
Ok thanks for the input

Also, I'm having an issue w/ my config.  It won't read the test user account.  

I'm getting this in my logs.

Aug 30 15:06:19 pwm01 server: 2018-08-30T15:06:19Z, ERROR, cluster.ClusterMachine, 5093 ERROR_CLUSTER_SERVICE_ERROR (error writing database cluster heartbeat: 5079 ERROR_LDAP_DATA_ERROR (error writing cluster data: javax.naming.NoPermissionException: [LDAP: error code 50 - Insufficient 'write' privilege to the 'pwmresponseset' attribute of entry 'uid=pwmtest,cn=users,cn=accounts,dc=gatewayblend,dc=net'.

Andrea Favero

unread,
Aug 30, 2018, 4:47:58 PM8/30/18
to pwm-g...@googlegroups.com
I did read that guide but I ignored it and did my own way. I never had to edit the ldap config that deeply. 

Il gio 30 ago 2018, 22:29 Andrew Meyer <andrew...@gatewayblend.com> ha scritto:
That did not work.  Did you have to do any of the changes described here?


On Thursday, August 30, 2018 at 3:21:04 PM UTC-5, Andrea Favero wrote:
I could be wrong but that account might need to have admin or smiliar priviliges, that is should be part of Admins group. Try adding it to that group and see what happens

Il gio 30 ago 2018, 22:12 Andrew Meyer <andrew...@gatewayblend.com> ha scritto:
Ok thanks for the input

Also, I'm having an issue w/ my config.  It won't read the test user account.  

I'm getting this in my logs.

Aug 30 15:06:19 pwm01 server: 2018-08-30T15:06:19Z, ERROR, cluster.ClusterMachine, 5093 ERROR_CLUSTER_SERVICE_ERROR (error writing database cluster heartbeat: 5079 ERROR_LDAP_DATA_ERROR (error writing cluster data: javax.naming.NoPermissionException: [LDAP: error code 50 - Insufficient 'write' privilege to the 'pwmresponseset' attribute of entry 'uid=pwmtest,cn=users,cn=accounts,dc=gatewayblend,dc=net'.

Andrew Meyer

unread,
Aug 30, 2018, 4:49:16 PM8/30/18
to pwm-g...@googlegroups.com
Would you mind sharing how you set it up?  

Andrew Meyer

unread,
Aug 30, 2018, 5:02:05 PM8/30/18
to pwm-general
Specifically the LDAP settings.  Obviously removing your ORG info.


On Thursday, August 30, 2018 at 3:49:16 PM UTC-5, Andrew Meyer wrote:
Would you mind sharing how you set it up?  

On Thu, Aug 30, 2018, 15:47 Andrea Favero <fav...@gmail.com> wrote:
I did read that guide but I ignored it and did my own way. I never had to edit the ldap config that deeply. 

Il gio 30 ago 2018, 22:29 Andrew Meyer <andrew...@gatewayblend.com> ha scritto:
That did not work.  Did you have to do any of the changes described here?


On Thursday, August 30, 2018 at 3:21:04 PM UTC-5, Andrea Favero wrote:
I could be wrong but that account might need to have admin or smiliar priviliges, that is should be part of Admins group. Try adding it to that group and see what happens

Il gio 30 ago 2018, 22:12 Andrew Meyer <andrew...@gatewayblend.com> ha scritto:
Ok thanks for the input

Also, I'm having an issue w/ my config.  It won't read the test user account.  

I'm getting this in my logs.

Aug 30 15:06:19 pwm01 server: 2018-08-30T15:06:19Z, ERROR, cluster.ClusterMachine, 5093 ERROR_CLUSTER_SERVICE_ERROR (error writing database cluster heartbeat: 5079 ERROR_LDAP_DATA_ERROR (error writing cluster data: javax.naming.NoPermissionException: [LDAP: error code 50 - Insufficient 'write' privilege to the 'pwmresponseset' attribute of entry 'uid=pwmtest,cn=users,cn=accounts,dc=gatewayblend,dc=net'.

To unsubscribe from this group and stop receiving emails from it, send an email to pwm-general+unsubscribe@googlegroups.com.

To post to this group, send email to pwm-g...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/pwm-general/d329dc0a-2485-415d-8b76-0184ff2570e4%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.

--
You received this message because you are subscribed to the Google Groups "pwm-general" group.
To unsubscribe from this group and stop receiving emails from it, send an email to pwm-general+unsubscribe@googlegroups.com.

Andrea Favero

unread,
Aug 30, 2018, 6:50:03 PM8/30/18
to pwm-g...@googlegroups.com
Yes, I can give assistence but please wait for tomorrow since its 1am here. Thanks! 

Il gio 30 ago 2018, 23:02 Andrew Meyer <andrew...@gatewayblend.com> ha scritto:
Specifically the LDAP settings.  Obviously removing your ORG info.

On Thursday, August 30, 2018 at 3:49:16 PM UTC-5, Andrew Meyer wrote:
Would you mind sharing how you set it up?  

On Thu, Aug 30, 2018, 15:47 Andrea Favero <fav...@gmail.com> wrote:
I did read that guide but I ignored it and did my own way. I never had to edit the ldap config that deeply. 

Il gio 30 ago 2018, 22:29 Andrew Meyer <andrew...@gatewayblend.com> ha scritto:
That did not work.  Did you have to do any of the changes described here?


On Thursday, August 30, 2018 at 3:21:04 PM UTC-5, Andrea Favero wrote:
I could be wrong but that account might need to have admin or smiliar priviliges, that is should be part of Admins group. Try adding it to that group and see what happens

Il gio 30 ago 2018, 22:12 Andrew Meyer <andrew...@gatewayblend.com> ha scritto:
Ok thanks for the input

Also, I'm having an issue w/ my config.  It won't read the test user account.  

I'm getting this in my logs.

Aug 30 15:06:19 pwm01 server: 2018-08-30T15:06:19Z, ERROR, cluster.ClusterMachine, 5093 ERROR_CLUSTER_SERVICE_ERROR (error writing database cluster heartbeat: 5079 ERROR_LDAP_DATA_ERROR (error writing cluster data: javax.naming.NoPermissionException: [LDAP: error code 50 - Insufficient 'write' privilege to the 'pwmresponseset' attribute of entry 'uid=pwmtest,cn=users,cn=accounts,dc=gatewayblend,dc=net'.

--
You received this message because you are subscribed to the Google Groups "pwm-general" group.
To unsubscribe from this group and stop receiving emails from it, send an email to pwm-general...@googlegroups.com.
To post to this group, send email to pwm-g...@googlegroups.com.

--
You received this message because you are subscribed to the Google Groups "pwm-general" group.
To unsubscribe from this group and stop receiving emails from it, send an email to pwm-general...@googlegroups.com.
To post to this group, send email to pwm-g...@googlegroups.com.

Andrew Meyer

unread,
Aug 30, 2018, 7:22:42 PM8/30/18
to pwm-g...@googlegroups.com
Sounds good.   Where are you located?



Andrew Meyer
Linux DevOps Engineer
GatewayBlend

Andrew Meyer

unread,
Aug 31, 2018, 9:56:11 AM8/31/18
to pwm-general
Let me know when you have time.


On Thursday, August 30, 2018 at 5:50:03 PM UTC-5, Andrea Favero wrote:
Yes, I can give assistence but please wait for tomorrow since its 1am here. Thanks! 

Il gio 30 ago 2018, 23:02 Andrew Meyer <andrew...@gatewayblend.com> ha scritto:
Specifically the LDAP settings.  Obviously removing your ORG info.

On Thursday, August 30, 2018 at 3:49:16 PM UTC-5, Andrew Meyer wrote:
Would you mind sharing how you set it up?  

On Thu, Aug 30, 2018, 15:47 Andrea Favero <fav...@gmail.com> wrote:
I did read that guide but I ignored it and did my own way. I never had to edit the ldap config that deeply. 

Il gio 30 ago 2018, 22:29 Andrew Meyer <andrew...@gatewayblend.com> ha scritto:
That did not work.  Did you have to do any of the changes described here?


On Thursday, August 30, 2018 at 3:21:04 PM UTC-5, Andrea Favero wrote:
I could be wrong but that account might need to have admin or smiliar priviliges, that is should be part of Admins group. Try adding it to that group and see what happens

Il gio 30 ago 2018, 22:12 Andrew Meyer <andrew...@gatewayblend.com> ha scritto:
Ok thanks for the input

Also, I'm having an issue w/ my config.  It won't read the test user account.  

I'm getting this in my logs.

Aug 30 15:06:19 pwm01 server: 2018-08-30T15:06:19Z, ERROR, cluster.ClusterMachine, 5093 ERROR_CLUSTER_SERVICE_ERROR (error writing database cluster heartbeat: 5079 ERROR_LDAP_DATA_ERROR (error writing cluster data: javax.naming.NoPermissionException: [LDAP: error code 50 - Insufficient 'write' privilege to the 'pwmresponseset' attribute of entry 'uid=pwmtest,cn=users,cn=accounts,dc=gatewayblend,dc=net'.

Andrea Favero

unread,
Aug 31, 2018, 10:11:43 AM8/31/18
to pwm-g...@googlegroups.com
Hi Andrew,
I live in Italy. If you want we can talk via Skype for a faster troubleshooting or I could even give you access to my developement setup (both IPA and PWM). After that, you can update this thread once we've found out what the problem is. Please note that I'm not an expert or affiliated with those products in any way, I just love to help since the community has helped me a lot in the past.

Andrew Meyer

unread,
Aug 31, 2018, 10:16:18 AM8/31/18
to pwm-g...@googlegroups.com
I'm ok doing either way of helping.  



Andrew Meyer
Linux DevOps Engineer
GatewayBlend

Andrew Meyer

unread,
Aug 31, 2018, 10:22:14 AM8/31/18
to pwm-g...@googlegroups.com
I'm getting skype setup either way.



Andrew Meyer
Linux DevOps Engineer
GatewayBlend

Andrew Meyer

unread,
Aug 31, 2018, 10:30:40 AM8/31/18
to pwm-g...@googlegroups.com
And yes I know you are not an expert or affiliated with pwm.  I appreciate all the help.



Andrew Meyer
Linux DevOps Engineer
GatewayBlend

Andrea Favero

unread,
Aug 31, 2018, 10:45:40 AM8/31/18
to pwm-g...@googlegroups.com
Feel free to chat me whenever you like at the skype address faverock96

Reply all
Reply to author
Forward
0 new messages