i am very thx for your effort, i changed many times the configuration but still not working, but i think i know where is the problem, i changed the filter for groups and base
my latest configuration are :
omero.ldap.base=dc=ad,dc=hhu,dc=de
omero.ldap.config=true
omero.ldap.group_filter=(&(cn=CAi_*)(memberof=cn=CAi_Allgemein,OU=FileShares,OU=Zentrum für Informations- und Medientechnologie,OU=Heinrich-Heine-Universität,dc=ad,dc=hhu,dc=de))
omero.ldap.group_mapping=name=cn
omero.ldap.new_user_group=:query:(member=@{dn})
omero.ldap.password=********
omero.ldap.referral=follow
omero.ldap.sync_on_login=true
omero.ldap.urls=ldap://SVR-HHU-DC-1.ad.hhu.de:389
omero.ldap.user_filter=(memberof:1.2.840.113556.1.4.1941:=cn=CAi_Allgemein,OU=FileShares,OU=Zentrum für Informations- und Medientechnologie,OU=Heinrich-Heine-Universität,dc=ad,dc=hhu,dc=de)
omero.ldap.user_mapping=omeName=sAMAccountName,firstName=givenName,lastName=sn,email=mail
omero.ldap.username=SVC_Omero
with this configuration
now when i am trying to do
- Code: Select all
bin/omero login -u saleht
giving me that, can not find a default group to saleht, if i disable sync_on_login and re setting the default group for this user i able to log in,
it is so clear to me that the problem in one of group conf parametter
filter or mapping or new_ user_group
Note:
my Group Filter is correct because it gives correspond groups list when i am run this query form ldapsearch command
my command is
ldapsearch -x -LLL -D "SVC_Omero" -w ************** -p 389 -h SVR-HHU-DC-1.ad.hhu.de -b 'dc=ad,dc=hhu,dc=de' -s sub "(&(cn=CAi_*)(memberof=cn=CAi_Allgemein,OU=FileShares,OU=Zentrum für Informations- und Medientechnologie,OU=Heinrich-Heine-Universität,dc=ad,dc=hhu,dc=de))" cn
snap from results :
dn:: Q049Q0FpX0FHX0JlbmdhLE9VPUZpbGVTaGFyZXMsT1U9WmVudHJ1bSBmw7xyIEluZm9ybWF0a
W9ucy0gdW5kIE1lZGllbnRlY2hub2xvZ2llLE9VPUhlaW5yaWNoLUhlaW5lLVVuaXZlcnNpdMOkdC
xEQz1BRCxEQz1oaHUsREM9ZGU=
cn: CAi_AG_Benga
dn:: Q049Q0FpX0FHX0JleWUsT1U9RmlsZVNoYXJlcyxPVT1aZW50cnVtIGbDvHIgSW5mb3JtYXRpb
25zLSB1bmQgTWVkaWVudGVjaG5vbG9naWUsT1U9SGVpbnJpY2gtSGVpbmUtVW5pdmVyc2l0w6R0LE
RDPUFELERDPWhodSxEQz1kZQ==
cn: CAi_AG_Beye
dn:: Q049Q0FpX0FHX0JvZWdlLE9VPUZpbGVTaGFyZXMsT1U9WmVudHJ1bSBmw7xyIEluZm9ybWF0a
W9ucy0gdW5kIE1lZGllbnRlY2hub2xvZ2llLE9VPUhlaW5yaWNoLUhlaW5lLVVuaXZlcnNpdMOkdC
xEQz1BRCxEQz1oaHUsREM9ZGU=
cn: CAi_AG_Boege
dn:: Q049Q0FpX0FHX0JyaWRnZXMsT1U9RmlsZVNoYXJlcyxPVT1aZW50cnVtIGbDvHIgSW5mb3JtY
XRpb25zLSB1bmQgTWVkaWVudGVjaG5vbG9naWUsT1U9SGVpbnJpY2gtSGVpbmUtVW5pdmVyc2l0w6
R0LERDPUFELERDPWhodSxEQz1kZQ==
cn: CAi_AG_Bridges
dn:: Q049Q0FpX0FHX0RfSGFlc2UsT1U9RmlsZVNoYXJlcyxPVT1aZW50cnVtIGbDvHIgSW5mb3JtY
XRpb25zLSB1bmQgTWVkaWVudGVjaG5vbG9naWUsT1U9SGVpbnJpY2gtSGVpbmUtVW5pdmVyc2l0w6
R0LERDPUFELERDPWhodSxEQz1kZQ==
cn: CAi_AG_D_Haese
dn:: Q049Q0FpX0FHX0RyZXhsZXIsT1U9RmlsZVNoYXJlcyxPVT1aZW50cnVtIGbDvHIgSW5mb3JtY
XRpb25zLSB1bmQgTWVkaWVudGVjaG5vbG9naWUsT1U9SGVpbnJpY2gtSGVpbmUtVW5pdmVyc2l0w6
R0LERDPUFELERDPWhodSxEQz1kZQ==
cn: CAi_AG_Drexler
dn:: Q049Q0FpX0FHX0VnZWxoYWFmLE9VPUZpbGVTaGFyZXMsT1U9WmVudHJ1bSBmw7xyIEluZm9yb
WF0aW9ucy0gdW5kIE1lZGllbnRlY2hub2xvZ2llLE9VPUhlaW5yaWNoLUhlaW5lLVVuaXZlcnNpdM
OkdCxEQz1BRCxEQz1oaHUsREM9ZGU=
cn: CAi_AG_Egelhaaf
dn:: Q049Q0FpX0FHX0VsdmVycyxPVT1GaWxlU2hhcmVzLE9VPVplbnRydW0gZsO8ciBJbmZvcm1hd
GlvbnMtIHVuZCBNZWRpZW50ZWNobm9sb2dpZSxPVT1IZWlucmljaC1IZWluZS1Vbml2ZXJzaXTDpH
QsREM9QUQsREM9aGh1LERDPWRl
cn: CAi_AG_Elvers
dn:: Q049Q0FpX0FHX0VybnN0LE9VPUZpbGVTaGFyZXMsT1U9WmVudHJ1bSBmw7xyIEluZm9ybWF0a
W9ucy0gdW5kIE1lZGllbnRlY2hub2xvZ2llLE9VPUhlaW5yaWNoLUhlaW5lLVVuaXZlcnNpdMOkdC
xEQz1BRCxEQz1oaHUsREM9ZGU=
cn: CAi_AG_Ernst
dn:: Q049Q0FpX0FHX0ZlaG0sT1U9RmlsZVNoYXJlcyxPVT1aZW50cnVtIGbDvHIgSW5mb3JtYXRpb
25zLSB1bmQgTWVkaWVudGVjaG5vbG9naWUsT1U9SGVpbnJpY2gtSGVpbmUtVW5pdmVyc2l0w6R0LE
RDPUFELERDPWhodSxEQz1kZQ==
cn: CAi_AG_Fehm
i think the problem in this line
omero.ldap.new_user_group=:query:(member=@{dn})
the problem is not related with
(memberof:1.2.840.113556.1.4.1941
because i try to disable the user filter i got same message
the blue line is the groups which should appear in Omero
thx again