all lists on lists.proxmox.com
 help / color / mirror / Atom feed
* [PVE-User] PBS3 - can't add LDAP realm, same settings work fine with PVE7
@ 2023-07-12 13:53 Jan Vlach
  2023-07-12 14:28 ` Stefan Sterz
  0 siblings, 1 reply; 4+ messages in thread
From: Jan Vlach @ 2023-07-12 13:53 UTC (permalink / raw)
  To: pve-user

Hello,
I’m preparing upgrade of our PVE7.4 + PBS2.4 infrastructure, I’ve started with PBS that boots in UEFI mode to verify that I have a re-bootable machine as per notes in upgrade guide.

I have LDAP authentication working successfully in PVE, but I can’t get it working in the PBS3
I’m trying to copy the settings from PVE, I’m missing Group classes and Group filter in PBS and I get weird error message on trying to add:

Could not search LDAP realm, base_dn could be incorrect: LDAP operation result rc=4 (sizeLimitExceeded), dn: “”, text: “”: rc=4 (sizeLimitExceeded), dn: “”, text: “”

bind user and server are redacted, there is no fallback server, password is managed by 1Password and is same. I can successfully lookup via ldapsearch from cli (no firewall). There’s no encryption.

What am I doing wrong? 
Thank you,
JV

Detailed settings follow:

=== PVE7.4-15 settings ===

TAB: GENERAL TAB:
Realm: ldap
Base Domain Name: dc=economia,dc=cz
User Attribute Name: sAMAccountName
Default: True
Server: <redacted>
Fallback Server: <empty>
Port: Default
SSL: False
Verify Certificate: False, greyed out
Require TFA: none
Comment: LDAP

TAB: SYNC OPTIONS:
Bind User: CN=<redacted>,CN=Users,DC=economia,DC=cz
Bind Password: Unchanged, greyed out (I know this)
E-mail attribute: mail
Groupname attr.: sAMAccountName
Default Sync Options
Scope: Users and Groups

User classes: user
Group classes: group
User Filter: (MemberOf=CN=IT_OPS,OU=External,OU=Groups,DC=economia,DC=cz)
Group Filter: (|(sAMAccountName=IT_OPS))
Enable new users: Yes (Default)
Remove vanished options
ACL: True
Entry: True
Properties: True

=== PBS3 settings ====
TAB: GENERAL
Realm: ldap
Base Domain Name: dc=economia,dc=cz
User Attribute Name: sAMAccountName
Anonymous search: false
Bind Domain Name: CN=<redacted>,CN=Users,DC=economia,DC=cz // same user as above
Bind Password: <same as above, from 1Pass>
Server: <redacted>
Fallback Server: <empty>
Port: Default
Mode: LDAP
Verify certificate: greyed out, false

TAB: SYNC OPTINS:
First Name attribute: givenName // verified with cli ldapsearch
Last Name attribute: sn
E-Mail attribute: mail

Default sync options
Enable new users: Yes (Default)

User classes: user
User filter: (MemberOf=CN=IT_OPS,OU=External,OU=Groups,DC=economia,DC=cz)
!! I miss group classes
!! I miss Group Filter

Remove vanished options
ACL: True
Entry: True
Properties: True

On pressing add I get:
Could not search LDAP realm, base_dn could be incorrect: LDAP operation result rc=4 (sizeLimitExceeded), dn: “”, text: “”: rc=4 (sizeLimitExceeded), dn: “”, text: “”

^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2023-07-12 16:40 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2023-07-12 13:53 [PVE-User] PBS3 - can't add LDAP realm, same settings work fine with PVE7 Jan Vlach
2023-07-12 14:28 ` Stefan Sterz
2023-07-12 16:33   ` Jan Vlach
2023-07-12 16:40   ` Jan Vlach

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.
Service provided by Proxmox Server Solutions GmbH | Privacy | Legal