ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    NextCloud with FreeIPA

    IT Discussion
    freeipa ldap openldap linux nextcloud owncloud
    3
    16
    5.3k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • AlyRagabA
      AlyRagab
      last edited by scottalanmiller

      Hi All,
      I have NextCloud 12 and FreeIPA and i have a problem in the integration between NextCloud and FreeIPA,
      i have followed what is stated in the NextCloud Documentation regarding this integration but the problem is that the NextCloud can not connect to LDAP Server,
      i got the Error in the Logging of the NextCloud : " Configuration Error (prefix s01): login filter does not contain %uid place holder. "

      I have wrote the BaseDN as below :

      dc=server,dc=local

      UserDN as below :

      uid=admin,cn=admins,dc=server,dc=local

      Note :
      i can test the connection normally using telnet utility for the FreeIPA using the port number " 389 " and connection is successfully initiated.

      1 Reply Last reply Reply Quote 1
      • AlyRagabA
        AlyRagab
        last edited by

        Is there any advice ?

        1 Reply Last reply Reply Quote 0
        • scottalanmillerS
          scottalanmiller
          last edited by

          Sounds like FreeIPA does not have the format that NextCloud expects.

          AlyRagabA 1 Reply Last reply Reply Quote 0
          • scottalanmillerS
            scottalanmiller
            last edited by

            Someone else had this issue:

            ...I have already solved it. I had problem in firewall rule between DC (Domain controller) and Nextcloud server (I installed the certificate to /etc/openldap/certs from DC, or you may disable verification of certificate, just add "TLS_REQCERT never"). I had allowed only those ports (TCP 135, TCP 389, TPC 636, ICMP). So, l made firewall rule that allow all traffic (all TCP/UPD and ICMP) then I use "Detect Base DN". And it began to work ! I was able load groups, users etc... So the detection procedure using some high TCP ( > 1024). Then I went back default firewall rule and it still works.

            https://help.nextcloud.com/uploads/default/optimized/2X/f/f6ae10ced8d0230ce92a9db1240a45045b69ec27_1_690x185.JPG

            1 Reply Last reply Reply Quote 2
            • AlyRagabA
              AlyRagab @scottalanmiller
              last edited by

              @scottalanmiller said in NextCloud with FreeIPA:

              Sounds like FreeIPA does not have the format that NextCloud expects.

              it is supposed to be the same format of the OpenLDAP

              1 Reply Last reply Reply Quote 0
              • AlyRagabA
                AlyRagab
                last edited by AlyRagab

                the two systems are installed in docker and i have exposed all required ports , and there is no problem of any connection for any port

                1 Reply Last reply Reply Quote 0
                • scottalanmillerS
                  scottalanmiller
                  last edited by

                  When you used telnet to test the connection, was that from the NextCloud host?

                  AlyRagabA 1 Reply Last reply Reply Quote 0
                  • AlyRagabA
                    AlyRagab @scottalanmiller
                    last edited by AlyRagab

                    @scottalanmiller said in NextCloud with FreeIPA:

                    When you used telnet to test the connection, was that from the NextCloud host?

                    Yes , and it was connected on port 389

                    travisdh1T 1 Reply Last reply Reply Quote 0
                    • travisdh1T
                      travisdh1 @AlyRagab
                      last edited by

                      @AlyRagab said in NextCloud with FreeIPA:

                      @scottalanmiller said in NextCloud with FreeIPA:

                      When you used telnet to test the connection, was that from the NextCloud host?

                      Yes , and it was connected on port 389

                      Good old 389 Server, may it rest in piece. (Used to be RedHat's LDAP server for those that don't know.)

                      AlyRagabA 1 Reply Last reply Reply Quote 0
                      • AlyRagabA
                        AlyRagab @travisdh1
                        last edited by

                        @travisdh1 said in NextCloud with FreeIPA:

                        @AlyRagab said in NextCloud with FreeIPA:

                        @scottalanmiller said in NextCloud with FreeIPA:

                        When you used telnet to test the connection, was that from the NextCloud host?

                        Yes , and it was connected on port 389

                        Good old 389 Server, may it rest in piece. (Used to be RedHat's LDAP server for those that don't know.)

                        You mean " Red Hat Identity Management " which includes " OpenLDAP 389 , Kerberos Authentication , NTP and DNS "
                        and the same with FreeIPA , it has all these components.

                        travisdh1T 1 Reply Last reply Reply Quote 0
                        • travisdh1T
                          travisdh1 @AlyRagab
                          last edited by

                          @AlyRagab said in NextCloud with FreeIPA:

                          @travisdh1 said in NextCloud with FreeIPA:

                          @AlyRagab said in NextCloud with FreeIPA:

                          @scottalanmiller said in NextCloud with FreeIPA:

                          When you used telnet to test the connection, was that from the NextCloud host?

                          Yes , and it was connected on port 389

                          Good old 389 Server, may it rest in piece. (Used to be RedHat's LDAP server for those that don't know.)

                          You mean " Red Hat Identity Management " which includes " OpenLDAP 389 , Kerberos Authentication , NTP and DNS "
                          and the same with FreeIPA , it has all these components.

                          I thought they had dropped the 389 name, huh.

                          1 Reply Last reply Reply Quote 1
                          • AlyRagabA
                            AlyRagab
                            last edited by

                            Finally , i have solved the problem 🙂
                            this URL has made my day
                            NextCloud with FreeIPA

                            scottalanmillerS 2 Replies Last reply Reply Quote 3
                            • scottalanmillerS
                              scottalanmiller @AlyRagab
                              last edited by

                              @AlyRagab Hey, you have a new avatar.

                              1 Reply Last reply Reply Quote 1
                              • scottalanmillerS
                                scottalanmiller @AlyRagab
                                last edited by

                                @AlyRagab said in NextCloud with FreeIPA:

                                Finally , i have solved the problem 🙂
                                this URL has made my day
                                NextCloud with FreeIPA

                                Well that is a really handy site.

                                1 Reply Last reply Reply Quote 1
                                • AlyRagabA
                                  AlyRagab
                                  last edited by

                                  @scottalanmiller Thanks a lot May you Categorize this thread so that it will be reference to anyone else 🙂

                                  1 Reply Last reply Reply Quote 0
                                  • scottalanmillerS
                                    scottalanmiller
                                    last edited by

                                    Done

                                    1 Reply Last reply Reply Quote 1
                                    • 1 / 1
                                    • First post
                                      Last post