<div dir="ltr">Hello Martin,<div><br></div><div>Thanks that does help, I didn't know about this project. I will try this approach first. Seems like it will be better integrated with FreeIPA and in general more maintainable than PWM.</div></div><div class="gmail_extra"><br><div class="gmail_quote">On 21 April 2016 at 09:59, Martin Kosek <span dir="ltr"><<a href="mailto:mkosek@redhat.com" target="_blank">mkosek@redhat.com</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><span class="">On 04/20/2016 05:23 PM, Tiemen Ruiten wrote:<br>
> Hello,<br>
><br>
> I'm trying to set up a self-service page for a new IPA domain and I'm trying to<br>
> use PWM for that.<br>
><br>
> When I try to bind to FreeIPA from within PWM, with the configured "LDAP Proxy<br>
> User", I get the following error:<br>
><br>
> error connecting to ldap server 'ldaps://<a href="http://polonium.ipa.rdmedia.com:636" rel="noreferrer" target="_blank">polonium.ipa.rdmedia.com:636</a><br>
</span>> <<a href="http://polonium.ipa.rdmedia.com:636" rel="noreferrer" target="_blank">http://polonium.ipa.rdmedia.com:636</a>>': unable to create connection: unable to<br>
<span class="">> bind to ldaps://<a href="http://polonium.ipa.rdmedia.com:636" rel="noreferrer" target="_blank">polonium.ipa.rdmedia.com:636</a><br>
</span>> <<a href="http://polonium.ipa.rdmedia.com:636" rel="noreferrer" target="_blank">http://polonium.ipa.rdmedia.com:636</a>> as<br>
<span class="">> cn=svcpwmproxy,cn=groups,cn=accounts,dc=ipa,dc=rdmedia,dc=com reason: [LDAP:<br>
> error code 48 - Inappropriate Authentication]<br>
><br>
> In /var/log/krb5kdc.log I see:<br>
><br>
</span>> Apr 20 17:12:29 <a href="http://polonium.ipa.rdmedia.com" rel="noreferrer" target="_blank">polonium.ipa.rdmedia.com</a> <<a href="http://polonium.ipa.rdmedia.com" rel="noreferrer" target="_blank">http://polonium.ipa.rdmedia.com</a>><br>
<span class="">> krb5kdc[25760](info): AS_REQ (6 etypes {18 17 16 23 25 26}) 192.168.50.33<br>
</span>> <<a href="http://192.168.50.33" rel="noreferrer" target="_blank">http://192.168.50.33</a>>: NEEDED_PREAUTH:<br>
> host/<a href="mailto:protactinium.ipa.rdmedia.com@IPA.RDMEDIA.COM">protactinium.ipa.rdmedia.com@IPA.RDMEDIA.COM</a><br>
> <mailto:<a href="mailto:protactinium.ipa.rdmedia.com@IPA.RDMEDIA.COM">protactinium.ipa.rdmedia.com@IPA.RDMEDIA.COM</a>> for<br>
> krbtgt/<a href="mailto:IPA.RDMEDIA.COM@IPA.RDMEDIA.COM">IPA.RDMEDIA.COM@IPA.RDMEDIA.COM</a> <mailto:<a href="mailto:IPA.RDMEDIA.COM@IPA.RDMEDIA.COM">IPA.RDMEDIA.COM@IPA.RDMEDIA.COM</a>>,<br>
> Additional pre-authentication required<br>
> Apr 20 17:12:29 <a href="http://polonium.ipa.rdmedia.com" rel="noreferrer" target="_blank">polonium.ipa.rdmedia.com</a> <<a href="http://polonium.ipa.rdmedia.com" rel="noreferrer" target="_blank">http://polonium.ipa.rdmedia.com</a>><br>
<span class="">> krb5kdc[25760](info): closing down fd 12<br>
</span>> Apr 20 17:12:29 <a href="http://polonium.ipa.rdmedia.com" rel="noreferrer" target="_blank">polonium.ipa.rdmedia.com</a> <<a href="http://polonium.ipa.rdmedia.com" rel="noreferrer" target="_blank">http://polonium.ipa.rdmedia.com</a>><br>
<span class="">> krb5kdc[25760](info): AS_REQ (6 etypes {18 17 16 23 25 26}) 192.168.50.33<br>
</span>> <<a href="http://192.168.50.33" rel="noreferrer" target="_blank">http://192.168.50.33</a>>: ISSUE: authtime 1461165149, etypes {rep=18 tkt=18<br>
> ses=18}, host/<a href="mailto:protactinium.ipa.rdmedia.com@IPA.RDMEDIA.COM">protactinium.ipa.rdmedia.com@IPA.RDMEDIA.COM</a><br>
> <mailto:<a href="mailto:protactinium.ipa.rdmedia.com@IPA.RDMEDIA.COM">protactinium.ipa.rdmedia.com@IPA.RDMEDIA.COM</a>> for<br>
> krbtgt/<a href="mailto:IPA.RDMEDIA.COM@IPA.RDMEDIA.COM">IPA.RDMEDIA.COM@IPA.RDMEDIA.COM</a> <mailto:<a href="mailto:IPA.RDMEDIA.COM@IPA.RDMEDIA.COM">IPA.RDMEDIA.COM@IPA.RDMEDIA.COM</a>><br>
> Apr 20 17:12:29 <a href="http://polonium.ipa.rdmedia.com" rel="noreferrer" target="_blank">polonium.ipa.rdmedia.com</a> <<a href="http://polonium.ipa.rdmedia.com" rel="noreferrer" target="_blank">http://polonium.ipa.rdmedia.com</a>><br>
<span class="">> krb5kdc[25760](info): closing down fd 12<br>
</span>> Apr 20 17:12:29 <a href="http://polonium.ipa.rdmedia.com" rel="noreferrer" target="_blank">polonium.ipa.rdmedia.com</a> <<a href="http://polonium.ipa.rdmedia.com" rel="noreferrer" target="_blank">http://polonium.ipa.rdmedia.com</a>><br>
<span class="">> krb5kdc[25760](info): TGS_REQ (6 etypes {18 17 16 23 25 26}) 192.168.50.33<br>
</span>> <<a href="http://192.168.50.33" rel="noreferrer" target="_blank">http://192.168.50.33</a>>: ISSUE: authtime 1461165149, etypes {rep=18 tkt=18<br>
> ses=18}, host/<a href="mailto:protactinium.ipa.rdmedia.com@IPA.RDMEDIA.COM">protactinium.ipa.rdmedia.com@IPA.RDMEDIA.COM</a><br>
> <mailto:<a href="mailto:protactinium.ipa.rdmedia.com@IPA.RDMEDIA.COM">protactinium.ipa.rdmedia.com@IPA.RDMEDIA.COM</a>> for<br>
> ldap/<a href="mailto:polonium.ipa.rdmedia.com@IPA.RDMEDIA.COM">polonium.ipa.rdmedia.com@IPA.RDMEDIA.COM</a><br>
> <mailto:<a href="mailto:polonium.ipa.rdmedia.com@IPA.RDMEDIA.COM">polonium.ipa.rdmedia.com@IPA.RDMEDIA.COM</a>><br>
> Apr 20 17:12:29 <a href="http://polonium.ipa.rdmedia.com" rel="noreferrer" target="_blank">polonium.ipa.rdmedia.com</a> <<a href="http://polonium.ipa.rdmedia.com" rel="noreferrer" target="_blank">http://polonium.ipa.rdmedia.com</a>><br>
<span class="">> krb5kdc[25760](info): closing down fd 12<br>
><br>
> What is going on? What can I do to debug this more?<br>
><br>
><br>
> --<br>
> Tiemen Ruiten<br>
> Systems Engineer<br>
> R&D Media<br>
<br>
</span>Hello Tiemen,<br>
<br>
Just for the record, in FreeIPA we have been also working on our own version of<br>
the Community Portal that could be useful for the registration and is already<br>
well integrated with FreeIPA:<br>
<br>
<a href="https://github.com/freeipa/freeipa-community-portal" rel="noreferrer" target="_blank">https://github.com/freeipa/freeipa-community-portal</a><br>
<a href="http://freeipa-community-portal.readthedocs.org/en/latest/" rel="noreferrer" target="_blank">http://freeipa-community-portal.readthedocs.org/en/latest/</a><br>
<br>
CCing Christian who currently owns the project.<br>
<br>
HTH,<br>
Martin<br>
</blockquote></div><br><br clear="all"><div><br></div>-- <br><div class="gmail_signature"><div dir="ltr">Tiemen Ruiten<br>Systems Engineer<br>R&D Media<br></div></div>
</div>