<div dir="ltr"><div>Big thanks for your help, but still the same:<br><br>#<br># Active directory domain name.<br>#<br>vars.domain = <a href="http://mydomain.com">mydomain.com</a><br><br>#<br># Search user and its password.<br>#<br>vars.user = admin@${global:vars.domain}<br>vars.password = *****<br><br>#<br># Optional DNS servers, if enterprise<br># DNS server cannot resolve the domain srvrecord.<br>#<br>vars.dns = dns://srvdc03.${global:vars.domain} dns://srvdc04.${global:vars.domain}<br><br>pool.default.serverset.type = srvrecord<br>pool.default.serverset.srvrecord.domain = ${global:vars.domain}<br>pool.default.auth.simple.bindDN = ${global:vars.user}<br>pool.default.auth.simple.password = ${global:vars.password}<br><br># Uncomment if using custom DNS<br>pool.default.serverset.srvrecord.jndi-properties.java.naming.provider.url = ${global:vars.dns}<br>pool.default.socketfactory.resolver.uRL = ${global:vars.dns}<br><br><br><br> [ovirt-engine-extension-aaa-ldap.authz::BRU_AIR-authz] Cannot initialize LDAP framework, deferring initialization. Error: No DNS SRV records were found with record name &#39;_gc._tcp.brussels.airport&#39;.<br><br></div>And I can&#39;t put &#39;_gc._<a href="http://tcp.mydomain.com">tcp.mydomain.com</a> in the dns... Isn&#39;t there another way it just resolves the dns servers I gave him?<br><div><br></div></div><div class="gmail_extra"><br><div class="gmail_quote">2015-01-29 13:02 GMT+01:00 Alon Bar-Lev <span dir="ltr">&lt;<a href="mailto:alonbl@redhat.com" target="_blank">alonbl@redhat.com</a>&gt;</span>:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><span class=""><br>
<br>
----- Original Message -----<br>
&gt; From: &quot;Ondra Machacek&quot; &lt;<a href="mailto:omachace@redhat.com">omachace@redhat.com</a>&gt;<br>
&gt; To: &quot;Koen Vanoppen&quot; &lt;<a href="mailto:vanoppen.koen@gmail.com">vanoppen.koen@gmail.com</a>&gt;, <a href="mailto:users@ovirt.org">users@ovirt.org</a><br>
&gt; Sent: Thursday, January 29, 2015 1:49:00 PM<br>
&gt; Subject: Re: [ovirt-users] AAA<br>
&gt;<br>
&gt;<br>
&gt; On 01/29/2015 12:30 PM, Koen Vanoppen wrote:<br>
&gt; &gt; No, I don&#39;t. and I wouldn&#39;t know how he got to this name...<br>
&gt;<br>
&gt; Well, then you have to, if you want to use &#39;pool.default.serverset.type<br>
&gt; = srvrecord&#39;.<br>
&gt;<br>
&gt; It just need to know where your global catalog is running, since it&#39;s<br>
&gt; needed for new provider.<br>
&gt;<br>
&gt; It searches for global catalog like this:<br>
&gt; dig @${vars.dns} -t SRV _gc._tcp.${vars.domain}<br>
&gt;<br>
&gt; So you need to have this SRV record in DNS, if you want to use srvrecord<br>
&gt; serverset type. Or you don&#39;t have to if you use single server type.<br>
<br>
</span>active directory will not work without access to global catalog.<br>
please set one or more of the domain controllers as dns server, for example:<br>
<br>
vars.dns = dns://dc1.${global:vars.domain} dns://dc2.${global:vars.domain}<br>
<br>
please also uncomment/add these lines to make vars.dns effective.<br>
<br>
pool.default.serverset.srvrecord.jndi-properties.java.naming.provider.url = ${global:vars.dns}<br>
pool.default.socketfactory.resolver.uRL = ${global:vars.dns}<br>
<br>
Thanks!<br>
<div class="HOEnZb"><div class="h5"><br>
&gt;<br>
&gt; &gt;<br>
&gt; &gt; Thanks for the reply!<br>
&gt; &gt;<br>
&gt; &gt; 2015-01-29 11:53 GMT+01:00 Ondra Machacek &lt;<a href="mailto:omachace@redhat.com">omachace@redhat.com</a><br>
&gt; &gt; &lt;mailto:<a href="mailto:omachace@redhat.com">omachace@redhat.com</a>&gt;&gt;:<br>
&gt; &gt;<br>
&gt; &gt;     On 01/29/2015 11:41 AM, Koen Vanoppen wrote:<br>
&gt; &gt;<br>
&gt; &gt;         Can somebody help me setting up AAA for ovirt 3.5.1?<br>
&gt; &gt;<br>
&gt; &gt;         I&#39;m getting this now:<br>
&gt; &gt;<br>
&gt; &gt;         2015-01-29 11:35:36,889 WARN<br>
&gt; &gt;         [org.ovirt.engineextensions.__aaa.ldap.AuthzExtension] (MSC<br>
&gt; &gt;         service thread<br>
&gt; &gt;         1-1) [ovirt-engine-extension-aaa-__ldap.authz::BRU_AIR-authz]<br>
&gt; &gt;         Cannot<br>
&gt; &gt;         initialize LDAP framework, deferring initialization. Error: An<br>
&gt; &gt;         error<br>
&gt; &gt;         occurred while attempting to query DNS in order to retrieve SRV<br>
&gt; &gt;         records<br>
&gt; &gt;         with name &#39;_gc._tcp.brussels.airport&#39;:<br>
&gt; &gt;         javax.naming.__NameNotFoundException: DNS name not found<br>
&gt; &gt;         [response code<br>
&gt; &gt;         3]; remaining name &#39;_gc._tcp.brussels.airport&#39;<br>
&gt; &gt;<br>
&gt; &gt;<br>
&gt; &gt;     Do you have this &#39;_gc._tcp.brussels.airport&#39; SRV record in DNS ?<br>
&gt; &gt;<br>
&gt; &gt;<br>
&gt; &gt;         my 3 configs:<br>
&gt; &gt;         _*BRU_AIR-authn.properties*_<br>
&gt; &gt;         <a href="http://ovirt.engine.extension.name" target="_blank">ovirt.engine.extension.name</a> &lt;<a href="http://ovirt.engine.extension.name" target="_blank">http://ovirt.engine.extension.name</a>&gt;<br>
&gt; &gt;         &lt;<a href="http://ovirt.engine." target="_blank">http://ovirt.engine.</a>__<a href="http://extension.name" target="_blank">extension.name</a><br>
&gt; &gt;         &lt;<a href="http://ovirt.engine.extension.name" target="_blank">http://ovirt.engine.extension.name</a>&gt;&gt; =<br>
&gt; &gt;         BRU_AIR-authn<br>
&gt; &gt;         ovirt.engine.extension.__bindings.method = jbossmodule<br>
&gt; &gt;         ovirt.engine.extension.__binding.jbossmodule.module =<br>
&gt; &gt;         org.ovirt.engine-extensions.__aaa.ldap<br>
&gt; &gt;         ovirt.engine.extension.__binding.jbossmodule.class =<br>
&gt; &gt;         org.ovirt.engineextensions.__aaa.ldap.AuthnExtension<br>
&gt; &gt;         ovirt.engine.extension.__provides =<br>
&gt; &gt;         org.ovirt.engine.api.__extensions.aaa.Authn<br>
&gt; &gt;         ovirt.engine.aaa.authn.__<a href="http://profile.name" target="_blank">profile.name</a><br>
&gt; &gt;         &lt;<a href="http://ovirt.engine.aaa.authn.profile.name" target="_blank">http://ovirt.engine.aaa.authn.profile.name</a>&gt;<br>
&gt; &gt;         &lt;<a href="http://ovirt.engine.aaa." target="_blank">http://ovirt.engine.aaa.</a>__<a href="http://authn.profile.name" target="_blank">authn.profile.name</a><br>
&gt; &gt;         &lt;<a href="http://ovirt.engine.aaa.authn.profile.name" target="_blank">http://ovirt.engine.aaa.authn.profile.name</a>&gt;&gt; = BRU-AIR<br>
&gt; &gt;         ovirt.engine.aaa.authn.authz.__plugin = BRU_AIR-authz<br>
&gt; &gt;         config.profile.file.1 = /etc/ovirt-engine/aaa/BRU_AIR.__properties<br>
&gt; &gt;<br>
&gt; &gt;         _*BRU_AIR-authz.properties*_<br>
&gt; &gt;         <a href="http://ovirt.engine.extension.name" target="_blank">ovirt.engine.extension.name</a> &lt;<a href="http://ovirt.engine.extension.name" target="_blank">http://ovirt.engine.extension.name</a>&gt;<br>
&gt; &gt;         &lt;<a href="http://ovirt.engine." target="_blank">http://ovirt.engine.</a>__<a href="http://extension.name" target="_blank">extension.name</a><br>
&gt; &gt;         &lt;<a href="http://ovirt.engine.extension.name" target="_blank">http://ovirt.engine.extension.name</a>&gt;&gt; =<br>
&gt; &gt;         BRU_AIR-authz<br>
&gt; &gt;         ovirt.engine.extension.__bindings.method = jbossmodule<br>
&gt; &gt;         ovirt.engine.extension.__binding.jbossmodule.module =<br>
&gt; &gt;         org.ovirt.engine-extensions.__aaa.ldap<br>
&gt; &gt;         ovirt.engine.extension.__binding.jbossmodule.class =<br>
&gt; &gt;         org.ovirt.engineextensions.__aaa.ldap.AuthzExtension<br>
&gt; &gt;         ovirt.engine.extension.__provides =<br>
&gt; &gt;         org.ovirt.engine.api.__extensions.aaa.Authz<br>
&gt; &gt;         config.profile.file.1 = /etc/ovirt-engine/aaa/BRU_AIR.__properties<br>
&gt; &gt;<br>
&gt; &gt;         _*BRU_AIR.properties*_<br>
&gt; &gt;         include = &lt;ad.properties&gt;<br>
&gt; &gt;<br>
&gt; &gt;         #<br>
&gt; &gt;         # Active directory domain name.<br>
&gt; &gt;         #<br>
&gt; &gt;         vars.domain = <a href="http://mydomain.com" target="_blank">mydomain.com</a> &lt;<a href="http://mydomain.com" target="_blank">http://mydomain.com</a>&gt;<br>
&gt; &gt;         &lt;<a href="http://mydomain.com" target="_blank">http://mydomain.com</a>&gt;<br>
&gt; &gt;<br>
&gt; &gt;         #<br>
&gt; &gt;         # Search user and its password.<br>
&gt; &gt;         #<br>
&gt; &gt;         vars.user = admin@${global:vars.domain}<br>
&gt; &gt;         vars.password = ***********<br>
&gt; &gt;<br>
&gt; &gt;         #<br>
&gt; &gt;         # Optional DNS servers, if enterprise<br>
&gt; &gt;         # DNS server cannot resolve the domain srvrecord.<br>
&gt; &gt;         #<br>
&gt; &gt;         vars.dns = dns://<a href="http://dc01.mydomain.com" target="_blank">dc01.mydomain.com</a> &lt;<a href="http://dc01.mydomain.com" target="_blank">http://dc01.mydomain.com</a>&gt;<br>
&gt; &gt;         &lt;<a href="http://dc01.mydomain.com" target="_blank">http://dc01.mydomain.com</a>&gt;<br>
&gt; &gt;<br>
&gt; &gt;         pool.default.serverset.type = srvrecord<br>
&gt; &gt;         pool.default.serverset.__srvrecord.domain = ${global:vars.domain}<br>
&gt; &gt;         pool.default.auth.simple.__bindDN = ${global:vars.user}<br>
&gt; &gt;         pool.default.auth.simple.__password = ${global:vars.password<br>
&gt; &gt;<br>
&gt; &gt;         In the GUI for adding user I get this:<br>
&gt; &gt;<br>
&gt; &gt;         An error occurred while attempting to query DNS in order to<br>
&gt; &gt;         retrieve SRV<br>
&gt; &gt;         records with name &#39;_gc__tcp_brussels_airport&#39;:<br>
&gt; &gt;         javax_naming___NameNotFoundException: DNS name not found<br>
&gt; &gt;         [response code<br>
&gt; &gt;         3]; remaining name &#39;_gc__tcp_brussels_airport&#39;<br>
&gt; &gt;<br>
&gt; &gt;         Any ideas? I ran out...<br>
&gt; &gt;<br>
&gt; &gt;         Kind regards,<br>
&gt; &gt;<br>
&gt; &gt;         Koen<br>
&gt; &gt;<br>
&gt; &gt;<br>
&gt; &gt;         _________________________________________________<br>
&gt; &gt;         Users mailing list<br>
&gt; &gt;         <a href="mailto:Users@ovirt.org">Users@ovirt.org</a> &lt;mailto:<a href="mailto:Users@ovirt.org">Users@ovirt.org</a>&gt;<br>
&gt; &gt;         <a href="http://lists.ovirt.org/__mailman/listinfo/users" target="_blank">http://lists.ovirt.org/__mailman/listinfo/users</a><br>
&gt; &gt;         &lt;<a href="http://lists.ovirt.org/mailman/listinfo/users" target="_blank">http://lists.ovirt.org/mailman/listinfo/users</a>&gt;<br>
&gt; &gt;<br>
&gt; &gt;<br>
</div></div><div class="HOEnZb"><div class="h5">&gt; _______________________________________________<br>
&gt; Users mailing list<br>
&gt; <a href="mailto:Users@ovirt.org">Users@ovirt.org</a><br>
&gt; <a href="http://lists.ovirt.org/mailman/listinfo/users" target="_blank">http://lists.ovirt.org/mailman/listinfo/users</a><br>
&gt;<br>
</div></div></blockquote></div><br></div>