kainemil
06/02/2023, 2:21 AMAUTH_METHOD=ldap
LDAP_SERVER=ldaps://ldapsserver:6360
LDAP_BASE_DN=ou=people,dc=domain,dc=tld
LDAP_DN=uid=admin,ou=people,dc=domain,dc=tld
LDAP_PASS=password
LDAP_USER_FILTER=(&(uid=${user}))
LDAP_VERSION=3
LDAP_ID_ATTRIBUTE=uid
LDAP_EMAIL_ATTRIBUTE=mail
LDAP_DISPLAY_NAME_ATTRIBUTE=cn
LLDAP ldaps settings:
[ldaps_options]
enabled=true
port=6360
cert_file="/data/ldap/cert1.pem"
key_file="/data/ldap/privkey1.pem"
I can see in the logs that it does load those settings and I am setting 6360:6360 in my docker-compose.yml
any ideas?nitnelave
06/02/2023, 2:22 AMnitnelave
06/02/2023, 2:22 AMnitnelave
06/02/2023, 2:22 AMkainemil
06/02/2023, 2:23 AMnitnelave
06/02/2023, 2:23 AMnitnelave
06/02/2023, 2:23 AMkainemil
06/02/2023, 2:24 AMkainemil
06/02/2023, 2:24 AMErrorException
ldap_bind(): Unable to bind to server: Can't contact LDAP server
kainemil
06/02/2023, 2:26 AMkainemil
06/02/2023, 2:26 AMnitnelave
06/02/2023, 2:27 AMkainemil
06/02/2023, 2:29 AM2023-06-02T02:22:50.676559535+00:00 DEBUG โโ ๐ [debug]: | response: SearchResultEntry(LdapSearchResultEntry { dn: "", attributes: [LdapPartialAttribute { atype: "objectClass", vals: [[116, 111, 112]] }, LdapPartialAttribute { atype: "vendorName", vals: [[76, 76, 68, 65, 80]] }, LdapPartialAttribute { atype: "vendorVersion", vals: [[108, 108, 100, 97, 112, 95, 48, 46, 52, 46, 51]] }, LdapPartialAttribute { atype: "supportedLDAPVersion", vals: [[51]] }, LdapPartialAttribute { atype: "supportedExtension", vals: [[49, 46, 51, 46, 54, 46, 49, 46, 52, 46, 49, 46, 52, 50, 48, 51, 46, 49, 46, 49, 49, 46, 49]] }, LdapPartialAttribute { atype: "supportedControl", vals: [] }, LdapPartialAttribute { atype: "supportedFeatures", vals: [[49, 46, 51, 46, 54, 46, 49, 46, 52, 46, 49, 46, 52, 50, 48, 51, 46, 49, 46, 53, 46, 49]] }, LdapPartialAttribute { atype: "defaultNamingContext", vals: [[100, 99, 61, 112, 111, 116, 97, 116, 111, 115, 97, 108, 97, 100, 44, 100, 99, 61, 112, 97, 114, 116, 121]] }, LdapPartialAttribute { atype: "namingContexts", vals: [[100, 99, 61, 112, 111, 116, 97, 116, 111, 115, 97, 108, 97, 100, 44, 100, 99, 61, 112, 97, 114, 116, 121]] }, LdapPartialAttribute { atype: "isGlobalCatalogReady", vals: [[102, 97, 108, 115, 101]] }] })
2023-06-02T02:26:43.247462922+00:00 WARN ๐ง [warn]: Sending fatal alert BadRecordMac | log.target: "rustls::conn" | log.module_path: "rustls::conn" | log.file: "/__w/lldap/lldap/${GITHUB_WORKSPACE}/.cargo/registry/src/github.com-1ecc6299db9ec823/rustls-0.20.8/src/conn.rs" | log.line: 1332
2023-06-02T02:26:43.247592492+00:00 ERROR ๐จ [error]: [LDAPS] Service Error: cannot decrypt peer's message
nitnelave
06/02/2023, 2:31 AMnitnelave
06/02/2023, 2:32 AMkainemil
06/02/2023, 2:32 AMnitnelave
06/02/2023, 2:32 AMnitnelave
06/02/2023, 2:33 AMnitnelave
06/02/2023, 2:33 AMkainemil
06/02/2023, 2:35 AMnitnelave
06/02/2023, 2:36 AMnitnelave
06/02/2023, 2:36 AMkainemil
06/02/2023, 2:36 AMnitnelave
06/02/2023, 2:37 AMldaps://ldapserver:6360
then the cert should be for ldapserver
(no .domain.tld)nitnelave
06/02/2023, 2:37 AMnitnelave
06/02/2023, 2:38 AMkainemil
06/02/2023, 2:43 AMnitnelave
06/02/2023, 2:44 AMldapserver
? Are they running on the same host?nitnelave
06/02/2023, 2:45 AMping ldapserver
?)kainemil
06/02/2023, 2:46 AMkainemil
06/02/2023, 2:46 AMkainemil
06/02/2023, 2:49 AMkainemil
06/02/2023, 2:49 AMkainemil
06/02/2023, 2:50 AMnitnelave
06/02/2023, 2:50 AMnitnelave
06/02/2023, 2:50 AMnitnelave
06/02/2023, 2:50 AMnitnelave
06/02/2023, 2:50 AMnitnelave
06/02/2023, 2:51 AMkainemil
06/02/2023, 2:52 AMkainemil
06/02/2023, 2:53 AMkainemil
06/02/2023, 2:57 AMBASE dc=domain,dc=tld
URI ldaps://ldap.domain.tld:6360
kainemil
06/02/2023, 2:57 AMldap_sasl_interactive_bind_s: Can't contact LDAP server (-1)
additional info: (unknown error code)
nitnelave
06/02/2023, 2:57 AMnitnelave
06/02/2023, 2:58 AMldapsearch -x -H ldaps://fqdn -b "dc=example,dc=com"
kainemil
06/02/2023, 2:59 AMldap_sasl_bind(SIMPLE): Can't contact LDAP server (-1)
kainemil
06/02/2023, 3:00 AMnitnelave
06/02/2023, 3:01 AMnitnelave
06/02/2023, 3:01 AMkainemil
06/02/2023, 3:01 AMldap_bind: Naming violation (64)
additional info: Missing DN value
nitnelave
06/02/2023, 3:01 AMnitnelave
06/02/2023, 3:01 AMnitnelave
06/02/2023, 3:02 AMldapsearch
over ldaps?kainemil
06/02/2023, 3:04 AM2023-06-02T03:02:59.677333779+00:00 INFO HTTP request [ 8.27ยตs | 100.00% ]
2023-06-02T03:02:59.677335539+00:00 INFO โโ ๏ฝ [info]: | uri: /health
2023-06-02T03:03:51.298231170+00:00 ERROR ๐จ [error]: [LDAPS] Service Error: while handling incoming messages: while receiving LDAP op: unexpected end of file
nitnelave
06/02/2023, 3:04 AMnitnelave
06/02/2023, 3:05 AMkainemil
06/02/2023, 3:08 AMnitnelave
06/02/2023, 3:10 AMtcpdump port 6360
kainemil
06/02/2023, 3:11 AMnitnelave
06/02/2023, 3:11 AMnitnelave
06/02/2023, 3:12 AMldapsearch
with localhostnitnelave
06/02/2023, 3:13 AMkainemil
06/02/2023, 3:14 AMnitnelave
06/02/2023, 3:15 AMnitnelave
06/02/2023, 3:15 AMkainemil
06/02/2023, 3:19 AMnitnelave
06/02/2023, 3:26 AMnitnelave
06/02/2023, 3:26 AMkainemil
06/02/2023, 3:27 AMnitnelave
06/02/2023, 3:37 AMnitnelave
06/02/2023, 3:38 AMapk add tcpdump
kainemil
06/02/2023, 3:38 AMkainemil
06/02/2023, 3:38 AMnitnelave
06/02/2023, 3:39 AMkainemil
06/02/2023, 3:40 AMkainemil
06/02/2023, 3:43 AMnitnelave
06/02/2023, 3:44 AM-w capture.pcap
(for writing the packets to a file) and send me the resulting capture file?nitnelave
06/02/2023, 3:45 AMldapsearch ... ldaps://ldapserver:6360
?)kainemil
06/02/2023, 3:46 AMkainemil
06/02/2023, 3:52 AMnitnelave
06/02/2023, 3:58 AMnitnelave
06/02/2023, 3:58 AMkainemil
06/02/2023, 3:59 AMnitnelave
06/02/2023, 3:59 AMnitnelave
06/02/2023, 4:03 AMkainemil
06/02/2023, 4:04 AMnitnelave
06/02/2023, 4:06 AMnitnelave
06/02/2023, 4:06 AMnitnelave
06/02/2023, 4:07 AM-debian
to the image tag, e.g. lldap/lldap:latest-debian
)kainemil
06/02/2023, 4:09 AMkainemil
06/02/2023, 4:13 AMkainemil
06/02/2023, 4:20 AMkainemil
06/02/2023, 4:20 AMkainemil
06/02/2023, 4:21 AMkainemil
06/02/2023, 4:21 AMkainemil
06/02/2023, 4:22 AMnitnelave
06/02/2023, 4:22 AMnitnelave
06/02/2023, 4:23 AMkainemil
06/02/2023, 4:23 AMnitnelave
06/02/2023, 4:24 AMnitnelave
06/02/2023, 4:24 AMkainemil
06/02/2023, 4:24 AMkainemil
06/02/2023, 4:25 AMkainemil
06/02/2023, 4:25 AMkainemil
06/02/2023, 4:26 AMkainemil
06/02/2023, 4:26 AMnitnelave
06/02/2023, 4:31 AMnitnelave
06/02/2023, 4:31 AMnitnelave
06/02/2023, 4:32 AMkainemil
06/02/2023, 4:32 AMnitnelave
06/02/2023, 4:33 AMnitnelave
06/02/2023, 4:33 AMkainemil
06/02/2023, 4:34 AMnitnelave
06/02/2023, 4:34 AMnitnelave
06/02/2023, 4:34 AMnitnelave
06/02/2023, 4:34 AMnitnelave
06/02/2023, 4:35 AMkainemil
06/02/2023, 4:35 AMnitnelave
06/02/2023, 4:35 AMnitnelave
06/02/2023, 4:35 AMnitnelave
06/02/2023, 4:36 AMkainemil
06/02/2023, 4:36 AMnitnelave
06/02/2023, 4:37 AMkainemil
06/02/2023, 4:37 AMkainemil
06/02/2023, 4:37 AMnitnelave
06/02/2023, 4:37 AMkainemil
06/02/2023, 4:37 AM