You are not logged in.

Announcement

 Téléchargez la dernière version stable de GLPI      -     Et vous, que pouvez vous faire pour le projet GLPI ? :  Contribuer
 Download last stable version of GLPI                      -     What can you do for GLPI ? :  Contribute

#1 2011-10-19 22:19:49

scharpf
Member
From: Brasil - São Paulo
Registered: 2009-02-26
Posts: 65

Logging loop with AD 2008

Hello folks...
I'm struggling with a problem since i updated  my GLPI to .80.4.
My conections tests with AD (windows 2008 server) are completed sucessfuly...  but...  when i try to login whith a user the login page keeps camming back with the message "try again".
anyone saw  this before?  sad
Thanks.

Last edited by scharpf (2011-10-19 22:21:40)


GLPI 0.90.1 / OCS Inventory 2.1.2 / OCS AGENTS  v2.1.1.1/ 1500 hosts
Debian Squeeze, Apache/2.2.16, PHP 5.4.45-1~dotdeb+6.1, MySQL 5.1.73

Offline

#2 2011-10-19 23:28:03

wawa
GLPI-DEV
From: Montpellier / France
Registered: 2006-07-03
Posts: 6,019
Website

Re: Logging loop with AD 2008

hello,
please post your LDAP configuration here

Offline

#3 2011-10-20 16:43:19

scharpf
Member
From: Brasil - São Paulo
Registered: 2009-02-26
Posts: 65

Re: Logging loop with AD 2008

my ldap configuration:

Server: ldap://sgr-sp-00X.sgr.net.br
Base DN: DC=sgr,DC=net,DC=br
Root DN: glpi-user@sgr.net.br
Connection Filter: (&(objectClass=user)(objectCategory=person)(!(userAccountControl:1.2.840.113556.1.4.803:=2)))
Login Field: samaccountname

Thanks a lot!...


GLPI 0.90.1 / OCS Inventory 2.1.2 / OCS AGENTS  v2.1.1.1/ 1500 hosts
Debian Squeeze, Apache/2.2.16, PHP 5.4.45-1~dotdeb+6.1, MySQL 5.1.73

Offline

#4 2011-10-20 18:29:08

wawa
GLPI-DEV
From: Montpellier / France
Registered: 2006-07-03
Posts: 6,019
Website

Re: Logging loop with AD 2008

scharpf wrote:

Root DN: glpi-user@sgr.net.br

it must be an LDAP DN

Offline

#5 2011-10-20 20:09:45

scharpf
Member
From: Brasil - São Paulo
Registered: 2009-02-26
Posts: 65

Re: Logging loop with AD 2008

My first configuration was with that  hmm
rootDN: CN=glpi-user,OU=Tecnologia Informática,OU=Usuarios,OU=SP,DC=sgr,DC=net,DC=br
But even that is not working.


GLPI 0.90.1 / OCS Inventory 2.1.2 / OCS AGENTS  v2.1.1.1/ 1500 hosts
Debian Squeeze, Apache/2.2.16, PHP 5.4.45-1~dotdeb+6.1, MySQL 5.1.73

Offline

#6 2011-10-20 21:01:45

wawa
GLPI-DEV
From: Montpellier / France
Registered: 2006-07-03
Posts: 6,019
Website

Re: Logging loop with AD 2008

Server: ldap://sgr-sp-00X.sgr.net.br => remove ldap:// (not needed, unless you use ldaps)

can you user connect to the directory using an ldap browser ? (for example adsiedit)

Offline

#7 2011-10-21 18:20:22

scharpf
Member
From: Brasil - São Paulo
Registered: 2009-02-26
Posts: 65

Re: Logging loop with AD 2008

Hi Wawa,

OK, "ldap://" removed...   doesn't working yet!

Yes, I can connect with ADSI...   even with my computer outside the network, disjoined from my domain...(giving the rigth user and password).

I also download a second ldap browser, named LDAPBROWSER from Softerra, and had the same results in and out domain. (no problems)

sad

Still having "Unable to connect to LDAP directory"  "login again" when on GLPI loguin page...

Last edited by scharpf (2011-10-21 19:26:23)


GLPI 0.90.1 / OCS Inventory 2.1.2 / OCS AGENTS  v2.1.1.1/ 1500 hosts
Debian Squeeze, Apache/2.2.16, PHP 5.4.45-1~dotdeb+6.1, MySQL 5.1.73

Offline

#8 2011-10-21 19:25:13

scharpf
Member
From: Brasil - São Paulo
Registered: 2009-02-26
Posts: 65

Re: Logging loop with AD 2008

The strange thing here is the test button, inside GLPI, with success results when pressed to connect on ldap. 
O gosh. roll

I don't know if it helps but the loguin page returns always to "http://sgr-sp-10/glpi/index.php?noAUTO=1"

Last edited by scharpf (2011-10-21 19:32:06)


GLPI 0.90.1 / OCS Inventory 2.1.2 / OCS AGENTS  v2.1.1.1/ 1500 hosts
Debian Squeeze, Apache/2.2.16, PHP 5.4.45-1~dotdeb+6.1, MySQL 5.1.73

Offline

#9 2011-10-24 21:34:39

scharpf
Member
From: Brasil - São Paulo
Registered: 2009-02-26
Posts: 65

Re: Logging loop with AD 2008

Hello,
I can import and synchronize users from 2008 AD from GLPI...
But I still have problems to login...

If I enter an wrong user or password, the system is capable to identify that and returns the message I'm giving something wrong.
I'm  thinking maybe this is a problem only on loguin.php... perhaps...
Is it  possible?

I don't know what to do anymore. Any suggestions?

Thanks yikes  sad

Last edited by scharpf (2011-10-24 22:21:53)


GLPI 0.90.1 / OCS Inventory 2.1.2 / OCS AGENTS  v2.1.1.1/ 1500 hosts
Debian Squeeze, Apache/2.2.16, PHP 5.4.45-1~dotdeb+6.1, MySQL 5.1.73

Offline

#10 2011-10-25 18:04:06

scharpf
Member
From: Brasil - São Paulo
Registered: 2009-02-26
Posts: 65

Re: Logging loop with AD 2008

Hello folks...

I' installed a fresh server and the problem was solved...  I Don't know what it was exactly, but all of my four servers updated to 80.4 had the same problem.

Next step will be import my database to this new server and see what happens...   


Regards

smile

Last edited by scharpf (2011-10-25 18:09:01)


GLPI 0.90.1 / OCS Inventory 2.1.2 / OCS AGENTS  v2.1.1.1/ 1500 hosts
Debian Squeeze, Apache/2.2.16, PHP 5.4.45-1~dotdeb+6.1, MySQL 5.1.73

Offline

#11 2011-10-25 19:35:18

scharpf
Member
From: Brasil - São Paulo
Registered: 2009-02-26
Posts: 65

Re: Logging loop with AD 2008

After database import, the login page doesn't work anymore...   

How is it possible?   The first thing coming in my mind now is the "glpi_users" table... 

I remove an user from it and reimport...  Works! this user can login... But lose historical associated assets and tickets.   

To do not lose the historical associated tickets from each user, I try to synchronize one of them but this doesn't work...  I must figure out how reimport or synchronize this table without losses.

Any suggestions?   
Thanks.


GLPI 0.90.1 / OCS Inventory 2.1.2 / OCS AGENTS  v2.1.1.1/ 1500 hosts
Debian Squeeze, Apache/2.2.16, PHP 5.4.45-1~dotdeb+6.1, MySQL 5.1.73

Offline

#12 2011-10-25 21:05:46

scharpf
Member
From: Brasil - São Paulo
Registered: 2009-02-26
Posts: 65

Re: Logging loop with AD 2008

I figure out!..!   big_smile

It was not a bug or a problem on update procedure...   

   after change the glpi version, i had to recreate the authentication method to a new one... 

The secret was..., change the authentication method for all accounts.

I hope this help someone one day.

Regards.


GLPI 0.90.1 / OCS Inventory 2.1.2 / OCS AGENTS  v2.1.1.1/ 1500 hosts
Debian Squeeze, Apache/2.2.16, PHP 5.4.45-1~dotdeb+6.1, MySQL 5.1.73

Offline

#13 2011-11-26 11:54:18

storylove
Member
Registered: 2011-11-26
Posts: 3

Re: Logging loop with AD 2008

It’s hard to find knowledgeable people on this topic, but you sound like you know what you’re talking about!

Offline

#14 2011-12-20 19:56:21

PomTom
Member
Registered: 2011-12-20
Posts: 2

Re: Logging loop with AD 2008

I'm having exactly the same problem using OpenLDAP as authentication backend. My GLPI version is 0.80.5.

It used to work for some days after the initial installation. Now, I get this "Login again" message with every LDAP user. I don't know how to debug this since the way described at http://www.glpi-project.org/wiki/doku.p … nfig:debug doesn't work anymore (the corresponding MySQL tables don't exist).

Where exactly can I recreate or reconfigure  the authentication method?

Offline

#15 2011-12-20 20:03:08

PomTom
Member
Registered: 2011-12-20
Posts: 2

Re: Logging loop with AD 2008

Please ignore my post...someone obviously removed the php5-ldap package. Everything is working fine after reinstalling it :-)

Offline

Board footer

Powered by FluxBB