<div dir="ltr"><div><div>Hello Alon,<br><br></div>I have done what you have said. My new configuration files are:<br><br>/etc/ovirt-engine/extensions.d/siee-local-authn.properties:<br><br><a href="http://ovirt.engine.extension.name">ovirt.engine.extension.name</a> = siee-local-authn<br>ovirt.engine.extension.bindings.method = jbossmodule<br>ovirt.engine.extension.binding.jbossmodule.module = org.ovirt.engine-extensions.aaa.ldap<br>ovirt.engine.extension.binding.jbossmodule.class = org.ovirt.engineextensions.aaa.ldap.AuthnExtension<br>ovirt.engine.extension.provides = org.ovirt.engine.api.extensions.aaa.Authn<br><a href="http://ovirt.engine.aaa.authn.profile.name">ovirt.engine.aaa.authn.profile.name</a> = siee<br>ovirt.engine.aaa.authn.authz.plugin = siee-local-authz<br>config.profile.file.1 = aaa/siee.properties<br><br>/etc/ovirt-engine/extensions.d/siee-local-authz.properties:<br><br><a href="http://ovirt.engine.extension.name">ovirt.engine.extension.name</a> = siee-local-authz<br>ovirt.engine.extension.bindings.method = jbossmodule<br>ovirt.engine.extension.binding.jbossmodule.module = org.ovirt.engine-extensions.aaa.ldap<br>ovirt.engine.extension.binding.jbossmodule.class = org.ovirt.engineextensions.aaa.ldap.AuthzExtension<br>ovirt.engine.extension.provides = org.ovirt.engine.api.extensions.aaa.Authz<br>config.profile.file.1 = aaa/siee.properties<br><br>/etc/ovirt-engine/extensions.d/aaa/siee.properties:<br><br>include = &lt;ad.properties&gt;<br><br>#<br># Active directory domain name.<br>#<br>vars.domain = siee.local<br><br>#<br># Search user and its password.<br>#<br>vars.user = searcher@${global:vars.domain}<br>vars.password = xxxxxxx<br><br>#<br># Optional DNS servers, if enterprise<br># DNS server cannot resolve the domain srvrecord.<br>#<br>#vars.dns = dns://dc1.${global:vars.domain} dns://dc2.${global:vars.domain}<br><br>pool.default.serverset.type = srvrecord<br>pool.default.serverset.srvrecord.domain = ${global:vars.domain}<br>pool.default.auth.simple.bindDN = ${global:vars.user}<br>pool.default.auth.simple.password = ${global:vars.password}<br><br># Uncomment if using custom DNS<br>#pool.default.serverset.srvrecord.jndi-properties.java.naming.provider.url = ${global:vars.dns}<br>#pool.default.socketfactory.resolver.uRL = ${global:vars.dns}<br><br># Create keystore, import certificate chain and uncomment<br># if using ssl/tls.<br>#pool.default.ssl.startTLS = true<br>#pool.default.ssl.truststore.file = ${local:_basedir}/${global:vars.domain}.jks<br>#pool.default.ssl.truststore.password = changeit<br><br></div><div>After reconfigure my files with ovirt-engine stopped I have started ovirt-engine and I have tried to log in. The error persist,<br>&quot;<span style class="">General command validation failure.&quot; and after that I have stopped ovirt-engine again. I attach my engine.log file.<br><br></span></div><div><span style class="">Many thanks again,<br><br></span></div><div><span style class="">Juanjo.<br></span></div><div><br></div></div><div class="gmail_extra"><br><div class="gmail_quote">On Tue, Dec 2, 2014 at 3:46 PM, Alon Bar-Lev <span dir="ltr">&lt;<a href="mailto:alonbl@redhat.com" target="_blank">alonbl@redhat.com</a>&gt;</span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><span class=""><br>
<br>
----- Original Message -----<br>
&gt; From: &quot;Juan Jose&quot; &lt;<a href="mailto:jj197005@gmail.com">jj197005@gmail.com</a>&gt;<br>
&gt; To: &quot;Alon Bar-Lev&quot; &lt;<a href="mailto:alonbl@redhat.com">alonbl@redhat.com</a>&gt;<br>
&gt; Cc: &quot;Ondra Machacek&quot; &lt;<a href="mailto:omachace@redhat.com">omachace@redhat.com</a>&gt;, &quot;Yair Zaslavsky&quot; &lt;<a href="mailto:yzaslavs@redhat.com">yzaslavs@redhat.com</a>&gt;, <a href="mailto:users@ovirt.org">users@ovirt.org</a><br>
</span><span class="">&gt; Sent: Tuesday, December 2, 2014 3:48:54 PM<br>
&gt; Subject: Re: [ovirt-users] Adding domain to oVirt to 3.5 issue<br>
&gt;<br>
&gt; Hello Alon and everybody,<br>
&gt;<br>
</span><span class="">&gt; I have installed package ovirt-engine-extension-aaa-ldap and configure my<br>
&gt; files as the documentation says. The files are:<br>
&gt;<br>
&gt; /etc/ovirt-engine/extensions.d/siee.local-authn.properties:<br>
&gt;<br>
&gt; <a href="http://ovirt.engine.extension.name" target="_blank">ovirt.engine.extension.name</a> = siee.local-authn<br>
&gt; ovirt.engine.extension.bindings.method = jbossmodule<br>
&gt; ovirt.engine.extension.binding.jbossmodule.module =<br>
&gt; org.ovirt.engine-extensions.aaa.ldap<br>
&gt; ovirt.engine.extension.binding.jbossmodule.class =<br>
&gt; org.ovirt.engineextensions.aaa.ldap.AuthnExtension<br>
&gt; ovirt.engine.extension.provides = org.ovirt.engine.api.extensions.aaa.Authn<br>
&gt; <a href="http://ovirt.engine.aaa.authn.profile.name" target="_blank">ovirt.engine.aaa.authn.profile.name</a> = siee.local<br>
&gt; ovirt.engine.aaa.authn.authz.plugin = siee.local-authz<br>
&gt; config.profile.file.1 = aaa/siee.local.properties<br>
<br>
</span>please use absolute file name for 3.5.0 relative will be available in 3.5.1<br>
<span class=""><br>
&gt;<br>
&gt; /etc/ovirt-engine/extensions.d/siee.local-authz.properties:<br>
&gt;<br>
&gt; <a href="http://ovirt.engine.extension.name" target="_blank">ovirt.engine.extension.name</a> = siee.local-authz<br>
&gt; ovirt.engine.extension.bindings.method = jbossmodule<br>
&gt; ovirt.engine.extension.binding.jbossmodule.module =<br>
&gt; org.ovirt.engine-extensions.aaa.ldap<br>
&gt; ovirt.engine.extension.binding.jbossmodule.class =<br>
&gt; org.ovirt.engineextensions.aaa.ldap.AuthzExtension<br>
&gt; ovirt.engine.extension.provides = org.ovirt.engine.api.extensions.aaa.Authz<br>
&gt; config.profile.file.1 = aaa/siee.local.properties<br>
<br>
</span>please use absolute file name for 3.5.0 relative will be available in 3.5.1<br>
<span class=""><br>
<br>
&gt;<br>
&gt; /etc/ovirt-engine/extensions.d/aaa/siee.local.properties:<br>
&gt;<br>
&gt; include = &lt;ad.properties&gt;<br>
&gt;<br>
&gt; #<br>
&gt; # Active directory domain name.<br>
&gt; #<br>
&gt; vars.domain = siee.local<br>
&gt;<br>
&gt; #<br>
&gt; # Search user and its password.<br>
&gt; #<br>
&gt; vars.user = juanjo@${global:vars.domain}<br>
&gt; vars.password = xxxxxxxx<br>
<br>
</span>this should be dedicate user for search not your private user.<br>
<div><div class="h5"><br>
&gt;<br>
&gt; #<br>
&gt; # Optional DNS servers, if enterprise<br>
&gt; # DNS server cannot resolve the domain srvrecord.<br>
&gt; #<br>
&gt; #vars.dns = dns://dc1.${global:vars.domain} dns://dc2.${global:vars.domain}<br>
&gt;<br>
&gt; pool.default.serverset.type = srvrecord<br>
&gt; pool.default.serverset.srvrecord.domain = ${global:vars.domain}<br>
&gt; pool.default.auth.simple.bindDN = ${global:vars.user}<br>
&gt; pool.default.auth.simple.password = ${global:vars.password}<br>
&gt;<br>
&gt; # Uncomment if using custom DNS<br>
&gt; #pool.default.serverset.srvrecord.jndi-properties.java.naming.provider.url<br>
&gt; = ${global:vars.dns}<br>
&gt; #pool.default.socketfactory.resolver.uRL = ${global:vars.dns}<br>
&gt;<br>
&gt; # Create keystore, import certificate chain and uncomment<br>
&gt; # if using ssl/tls.<br>
&gt; #pool.default.ssl.startTLS = true<br>
&gt; #pool.default.ssl.truststore.file =<br>
&gt; ${local:_basedir}/${global:vars.domain}.jks<br>
&gt; #pool.default.ssl.truststore.password = changeit<br>
&gt;<br>
&gt; And after this configuration I restart ovirt-engine service. When I try to<br>
&gt; login in administrator portal I can see the error &quot;The user name or<br>
&gt; password is incorrect.&quot;. In /var/log/ovirt-engine/engine.log I have the<br>
&gt; errors:<br>
&gt;<br>
&gt; 2014-12-02 14:02:21,983 ERROR<br>
&gt; [org.ovirt.engine.core.dal.dbbroker.auditloghandling.AuditLogDirector]<br>
&gt; (ajp--127.0.0.1-8702-8) Correlation ID: null, Call Stack: null, Custom<br>
&gt; Event ID: -1, Message: User juanjo cannot login, please verify the username<br>
&gt; and password.<br>
&gt; 2014-12-02 14:02:21,991 ERROR<br>
&gt; [org.ovirt.engine.core.dal.dbbroker.auditloghandling.AuditLogDirector]<br>
&gt; (ajp--127.0.0.1-8702-8) Correlation ID: null, Call Stack: null, Custom<br>
&gt; Event ID: -1, Message: User juanjo failed to log in.<br>
&gt;<br>
&gt; I&#39;m using correct user and password becuase I can login in a Windows client<br>
&gt; machine which is inside siee.local domain with this user and its correct<br>
&gt; password.<br>
&gt;<br>
&gt; What do you think it could be the problem?<br>
&gt;<br>
&gt; If you need more information or I have to configure any other parameters,<br>
&gt; please tell me.<br>
<br>
</div></div>please attach full engine.log, more correctly, stop engine, remove engine.log start engine, try to login and send log.<br>
please make sure you select the &quot;siee.local&quot; domain in dropdown of login screen.<br>
<br>
when I get the engine.log I will be able to understand who to progress.<br>
<br>
thanks!<br>
<div class="HOEnZb"><div class="h5"><br>
<br>
&gt;<br>
&gt; Many thanks in advanced,<br>
&gt;<br>
&gt; Juanjo.<br>
&gt;<br>
&gt;<br>
&gt;<br>
&gt; On Wed, Nov 26, 2014 at 3:19 PM, Alon Bar-Lev &lt;<a href="mailto:alonbl@redhat.com">alonbl@redhat.com</a>&gt; wrote:<br>
&gt;<br>
&gt; &gt;<br>
&gt; &gt;<br>
&gt; &gt; ----- Original Message -----<br>
&gt; &gt; &gt; From: &quot;Juan Jose&quot; &lt;<a href="mailto:jj197005@gmail.com">jj197005@gmail.com</a>&gt;<br>
&gt; &gt; &gt; To: &quot;Alon Bar-Lev&quot; &lt;<a href="mailto:alonbl@redhat.com">alonbl@redhat.com</a>&gt;<br>
&gt; &gt; &gt; Cc: &quot;Ondra Machacek&quot; &lt;<a href="mailto:omachace@redhat.com">omachace@redhat.com</a>&gt;, &quot;Yair Zaslavsky&quot; &lt;<br>
&gt; &gt; <a href="mailto:yzaslavs@redhat.com">yzaslavs@redhat.com</a>&gt;, <a href="mailto:users@ovirt.org">users@ovirt.org</a><br>
&gt; &gt; &gt; Sent: Wednesday, November 26, 2014 3:04:14 PM<br>
&gt; &gt; &gt; Subject: Re: [ovirt-users] Adding domain to oVirt to 3.5 issue<br>
&gt; &gt; &gt;<br>
&gt; &gt; &gt; Hello Alon and everybody,<br>
&gt; &gt; &gt;<br>
&gt; &gt; &gt; Check in my ovirt-engine machine for ovirt-engine-aaa-ldap package and it<br>
&gt; &gt; &gt; is not available:<br>
&gt; &gt; &gt;<br>
&gt; &gt; &gt; yum list &quot;ovirt-engine*&quot;<br>
&gt; &gt; &gt; Loaded plugins: fastestmirror, refresh-packagekit, security, versionlock<br>
&gt; &gt; &gt; Loading mirror speeds from cached hostfile<br>
&gt; &gt; &gt;  * base: <a href="http://ftp.udl.es" target="_blank">ftp.udl.es</a><br>
&gt; &gt; &gt;  * epel: <a href="http://mirror.uv.es" target="_blank">mirror.uv.es</a><br>
&gt; &gt; &gt;  * extras: <a href="http://ftp.udl.es" target="_blank">ftp.udl.es</a><br>
&gt; &gt; &gt;  * ovirt-3.5: <a href="http://ftp.nluug.nl" target="_blank">ftp.nluug.nl</a><br>
&gt; &gt; &gt;  * ovirt-3.5-epel: <a href="http://mirror.uv.es" target="_blank">mirror.uv.es</a><br>
&gt; &gt; &gt;  * ovirt-3.5-jpackage-6.0-generic: <a href="http://mirror.ibcp.fr" target="_blank">mirror.ibcp.fr</a><br>
&gt; &gt; &gt;  * ovirt-epel: <a href="http://mirror.uv.es" target="_blank">mirror.uv.es</a><br>
&gt; &gt; &gt;  * ovirt-jpackage-6.0-generic: <a href="http://mirror.ibcp.fr" target="_blank">mirror.ibcp.fr</a><br>
&gt; &gt; &gt;  * updates: <a href="http://ftp.udl.es" target="_blank">ftp.udl.es</a><br>
&gt; &gt; &gt; Installed Packages<br>
&gt; &gt; &gt; ovirt-engine.noarch<br>
&gt; &gt; &gt; 3.5.0.1-1.el6                         @ovirt-3.5<br>
&gt; &gt; &gt; ovirt-engine-backend.noarch<br>
&gt; &gt; &gt; 3.5.0.1-1.el6                         @ovirt-3.5<br>
&gt; &gt; &gt; ovirt-engine-cli.noarch<br>
&gt; &gt; &gt; 3.3.0.6-1.el6                         @ovirt-3.3.3<br>
&gt; &gt; &gt; ovirt-engine-dbscripts.noarch<br>
&gt; &gt; &gt; 3.5.0.1-1.el6                         @ovirt-3.5<br>
&gt; &gt; &gt; ovirt-engine-extensions-api-impl.noarch<br>
&gt; &gt; &gt; 3.5.0.1-1.el6                         @ovirt-3.5<br>
&gt; &gt; &gt; ovirt-engine-jboss-as.x86_64<br>
&gt; &gt; &gt; 7.1.1-1.el6                           @ovirt-3.5<br>
&gt; &gt; &gt; ovirt-engine-lib.noarch<br>
&gt; &gt; &gt; 3.5.0.1-1.el6                         @ovirt-3.5<br>
&gt; &gt; &gt; ovirt-engine-restapi.noarch<br>
&gt; &gt; &gt; 3.5.0.1-1.el6                         @ovirt-3.5<br>
&gt; &gt; &gt; ovirt-engine-sdk-python.noarch<br>
&gt; &gt; &gt; 3.5.0.8-1.el6                         @ovirt-3.5<br>
&gt; &gt; &gt; ovirt-engine-setup.noarch<br>
&gt; &gt; &gt; 3.5.0.1-1.el6                         @ovirt-3.5<br>
&gt; &gt; &gt; ovirt-engine-setup-base.noarch<br>
&gt; &gt; &gt; 3.5.0.1-1.el6                         @ovirt-3.5<br>
&gt; &gt; &gt; ovirt-engine-setup-plugin-ovirt-engine.noarch<br>
&gt; &gt; &gt; 3.5.0.1-1.el6                         @ovirt-3.5<br>
&gt; &gt; &gt; ovirt-engine-setup-plugin-ovirt-engine-common.noarch<br>
&gt; &gt; &gt; 3.5.0.1-1.el6                         @ovirt-3.5<br>
&gt; &gt; &gt; ovirt-engine-setup-plugin-websocket-proxy.noarch<br>
&gt; &gt; &gt; 3.5.0.1-1.el6                         @ovirt-3.5<br>
&gt; &gt; &gt; ovirt-engine-tools.noarch<br>
&gt; &gt; &gt; 3.5.0.1-1.el6                         @ovirt-3.5<br>
&gt; &gt; &gt; ovirt-engine-userportal.noarch<br>
&gt; &gt; &gt; 3.5.0.1-1.el6                         @ovirt-3.5<br>
&gt; &gt; &gt; ovirt-engine-webadmin-portal.noarch<br>
&gt; &gt; &gt; 3.5.0.1-1.el6                         @ovirt-3.5<br>
&gt; &gt; &gt; ovirt-engine-websocket-proxy.noarch<br>
&gt; &gt; &gt; 3.5.0.1-1.el6                         @ovirt-3.5<br>
&gt; &gt; &gt; Available Packages<br>
&gt; &gt; &gt; ovirt-engine-cli.noarch<br>
&gt; &gt; &gt; 3.5.0.5-1.el6                         ovirt-3.5<br>
&gt; &gt; &gt; ovirt-engine-dwh.noarch<br>
&gt; &gt; &gt; 3.5.0-1.el6                           ovirt-3.5<br>
&gt; &gt; &gt; ovirt-engine-dwh-setup.noarch<br>
&gt; &gt; &gt; 3.5.0-1.el6                           ovirt-3.5<br>
&gt; &gt; &gt; ovirt-engine-extensions-api-impl-javadoc.noarch<br>
&gt; &gt; &gt; 3.5.0.1-1.el6                         ovirt-3.5<br>
&gt; &gt; &gt; ovirt-engine-reports.noarch<br>
&gt; &gt; &gt; 3.5.1-0.1.el6                         ovirt-3.5<br>
&gt; &gt; &gt; ovirt-engine-reports-setup.noarch<br>
&gt; &gt; &gt; 3.5.1-0.1.el6                         ovirt-3.5<br>
&gt; &gt; &gt; ovirt-engine-sdk-java.noarch<br>
&gt; &gt; &gt; 3.5.0.5-1.el6                         ovirt-3.5<br>
&gt; &gt; &gt; ovirt-engine-sdk-java-javadoc.noarch<br>
&gt; &gt; &gt; 3.5.0.5-1.el6                         ovirt-3.5<br>
&gt; &gt; &gt; ovirt-engine-setup-plugin-allinone.noarch<br>
&gt; &gt; &gt;<br>
&gt; &gt; &gt; How can I get this package?<br>
&gt; &gt;<br>
&gt; &gt;<br>
&gt; &gt; Thanks for trying!<br>
&gt; &gt;<br>
&gt; &gt; Package is available at ovirt-3.5-snapshot[1].<br>
&gt; &gt;<br>
&gt; &gt; [1] <a href="http://resources.ovirt.org/pub/ovirt-3.5-snapshot/" target="_blank">http://resources.ovirt.org/pub/ovirt-3.5-snapshot/</a><br>
&gt; &gt;<br>
&gt;<br>
</div></div></blockquote></div><br></div>