<div dir="ltr"><div><br></div>below are the three files which I have modified.<br><div><br><br>[root@cstlb2 extensions.d]# cat profile1-authn.properties <br><a href="http://ovirt.engine.extension.name">ovirt.engine.extension.name</a> = cloudspin-authn<br>ovirt.engine.extension.bindings.method = jbossmodule<br>ovirt.engine.extension.binding.jbossmodule.module = org.ovirt.engine-extensions.aaa.ldap<br>ovirt.engine.extension.binding.jbossmodule.class = org.ovirt.engineextensions.aaa.ldap.AuthnExtension<br>ovirt.engine.extension.provides = org.ovirt.engine.api.extensions.aaa.Authn<br><a href="http://ovirt.engine.aaa.authn.profile.name">ovirt.engine.aaa.authn.profile.name</a> = cloudspin<br>ovirt.engine.aaa.authn.authz.plugin = cloudspin-auth<br>config.profile.file.1 = /etc/ovirt-engine/aaa/ldap1.properties<br><br><br>[root@cstlb2 extensions.d]# ls<br>profile1-authn.properties  profile1-authz.properties<br>[root@cstlb2 extensions.d]# cat profile1-authz.properties <br><a href="http://ovirt.engine.extension.name">ovirt.engine.extension.name</a> = cloudspin-authz<br>ovirt.engine.extension.bindings.method = jbossmodule<br>ovirt.engine.extension.binding.jbossmodule.module = org.ovirt.engine-extensions.aaa.ldap<br>ovirt.engine.extension.binding.jbossmodule.class = org.ovirt.engineextensions.aaa.ldap.AuthzExtension<br>ovirt.engine.extension.provides = org.ovirt.engine.api.extensions.aaa.Authz<br>config.profile.file.1 = /etc/ovirt-engine/aaa/ldap1.properties<br>[root@cstlb2 extensions.d]# <br><br><br><br>[root@cstlb2 aaa]# pwd<br>/etc/ovirt-engine/aaa<br>[root@cstlb2 aaa]# ls<br>ldap1.properties<br>[root@cstlb2 aaa]# cat ldap1.properties <br>#<br># Select one<br>#<br>include = &lt;openldap.properties&gt;<br>#include = &lt;389ds.properties&gt;<br>#include = &lt;rhds.properties&gt;<br>#include = &lt;ipa.properties&gt;<br>#include = &lt;iplanet.properties&gt;<br>#include = &lt;rfc2307.properties&gt;<br>#include = &lt;rfc2307-openldap.properties&gt;<br><br>#<br># Server<br>#<br>vars.server = <a href="http://my.abc.net">my.abc.net</a> <br><br>#<br># Search user and its password.<br>#<br>vars.user = uid=search,cn=nbudoor,cn=Departments,cn=Corporate,cn=Bangalore,cn=users,dc=nbudoor,dc=net<br>vars.password = company<br><br>pool.default.serverset.single.server = ${global:vars.server}<br>pool.default.auth.simple.bindDN = ${global:vars.user}<br>pool.default.auth.simple.password = ${global:vars.password}<br><br># Create keystore, import certificate chain and uncomment<br># if using ssl/tls.<br>#pool.default.ssl.startTLS = true<br>#pool.default.ssl.truststore.file = ${local:_basedir}/${global:vars.server}.jks<br>#pool.default.ssl.truststore.password = changeit<br>[root@cstlb2 aaa]# <br><br><br><br><br><br></div></div><div class="gmail_extra"><br><div class="gmail_quote">On Tue, Sep 22, 2015 at 8:07 PM, Alon Bar-Lev <span dir="ltr">&lt;<a href="mailto:alonbl@redhat.com" target="_blank">alonbl@redhat.com</a>&gt;</span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><span class=""><br>
<br>
----- Original Message -----<br>
&gt; From: &quot;Budur Nagaraju&quot; &lt;<a href="mailto:nbudoor@gmail.com">nbudoor@gmail.com</a>&gt;<br>
&gt; To: &quot;Alon Bar-Lev&quot; &lt;<a href="mailto:alonbl@redhat.com">alonbl@redhat.com</a>&gt;<br>
&gt; Cc: <a href="mailto:users@ovirt.org">users@ovirt.org</a><br>
</span><span class="">&gt; Sent: Tuesday, September 22, 2015 5:35:16 PM<br>
&gt; Subject: Re: [ovirt-users] LDAP Authentication<br>
&gt;<br>
</span><span class="">&gt; its too complicated ,you have any script or video ?<br>
<br>
</span>in 3.6 we have a setup script.<br>
for now:<br>
<br>
cp -r /usr/share/ovirt-engine/examples/simple/. /etc/ovirt-engine/<br>
<br>
this is written in the README.<br>
<br>
then customize files at /etc/ovirt-engine/extnesions.d/* /etc/ovirt-engine/aaa/* to match your setup<br>
<div class="HOEnZb"><div class="h5"><br>
&gt;<br>
&gt;<br>
&gt; On Tue, Sep 22, 2015 at 8:00 PM, Alon Bar-Lev &lt;<a href="mailto:alonbl@redhat.com">alonbl@redhat.com</a>&gt; wrote:<br>
&gt;<br>
&gt; &gt;<br>
&gt; &gt;<br>
&gt; &gt; ----- Original Message -----<br>
&gt; &gt; &gt; From: &quot;Budur Nagaraju&quot; &lt;<a href="mailto:nbudoor@gmail.com">nbudoor@gmail.com</a>&gt;<br>
&gt; &gt; &gt; To: &quot;Alon Bar-Lev&quot; &lt;<a href="mailto:alonbl@redhat.com">alonbl@redhat.com</a>&gt;<br>
&gt; &gt; &gt; Cc: <a href="mailto:users@ovirt.org">users@ovirt.org</a><br>
&gt; &gt; &gt; Sent: Tuesday, September 22, 2015 5:24:36 PM<br>
&gt; &gt; &gt; Subject: Re: [ovirt-users] LDAP Authentication<br>
&gt; &gt; &gt;<br>
&gt; &gt; &gt; HI Alon,<br>
&gt; &gt; &gt;<br>
&gt; &gt; &gt; Below is the configuration which I have done ,but unable to search the<br>
&gt; &gt; &gt; users in UI<br>
&gt; &gt; &gt; can you pls help me ?<br>
&gt; &gt;<br>
&gt; &gt; you need three files, see the<br>
&gt; &gt; /usr/share/ovirt-engine-extension-aaa-ldap/examples/simple<br>
&gt; &gt;<br>
&gt; &gt; &gt;<br>
&gt; &gt; &gt;<br>
&gt; &gt; &gt; [root@cstlb2 aaa]# cat ldap1.properties<br>
&gt; &gt; &gt; #<br>
&gt; &gt; &gt; # Select one<br>
&gt; &gt; &gt; #<br>
&gt; &gt; &gt; include = &lt;openldap.properties&gt;<br>
&gt; &gt; &gt; #include = &lt;389ds.properties&gt;<br>
&gt; &gt; &gt; #include = &lt;rhds.properties&gt;<br>
&gt; &gt; &gt; #include = &lt;ipa.properties&gt;<br>
&gt; &gt; &gt; #include = &lt;iplanet.properties&gt;<br>
&gt; &gt; &gt; #include = &lt;rfc2307.properties&gt;<br>
&gt; &gt; &gt; #include = &lt;rfc2307-openldap.properties&gt;<br>
&gt; &gt; &gt;<br>
&gt; &gt; &gt; #<br>
&gt; &gt; &gt; # Server<br>
&gt; &gt; &gt; #<br>
&gt; &gt; &gt; vars.server = <a href="http://my.abc.net" rel="noreferrer" target="_blank">my.abc.net</a><br>
&gt; &gt; &gt;<br>
&gt; &gt; &gt; #<br>
&gt; &gt; &gt; # Search user and its password.<br>
&gt; &gt; &gt; #<br>
&gt; &gt; &gt; vars.user =<br>
&gt; &gt; &gt;<br>
&gt; &gt; uid=search,cn=nbudoor,cn=Departments,cn=Corporate,cn=Bangalore,cn=users,dc=abc,dc=net<br>
&gt; &gt; &gt; vars.password = company1<br>
&gt; &gt; &gt;<br>
&gt; &gt; &gt; pool.default.serverset.single.server = ${global:vars.server}<br>
&gt; &gt; &gt; pool.default.auth.simple.bindDN = ${global:vars.user}<br>
&gt; &gt; &gt; pool.default.auth.simple.password = ${global:vars.password}<br>
&gt; &gt; &gt;<br>
&gt; &gt; &gt; # Create keystore, import certificate chain and uncomment<br>
&gt; &gt; &gt; # if using ssl/tls.<br>
&gt; &gt; &gt; #pool.default.ssl.startTLS = true<br>
&gt; &gt; &gt; #pool.default.ssl.truststore.file =<br>
&gt; &gt; &gt; ${local:_basedir}/${global:vars.server}.jks<br>
&gt; &gt; &gt; #pool.default.ssl.truststore.password = changeit<br>
&gt; &gt; &gt; [root@cstlb2 aaa]#<br>
&gt; &gt; &gt;<br>
&gt; &gt; &gt;<br>
&gt; &gt; &gt;<br>
&gt; &gt; &gt; On Tue, Sep 22, 2015 at 7:25 PM, Alon Bar-Lev &lt;<a href="mailto:alonbl@redhat.com">alonbl@redhat.com</a>&gt; wrote:<br>
&gt; &gt; &gt;<br>
&gt; &gt; &gt; &gt;<br>
&gt; &gt; &gt; &gt;<br>
&gt; &gt; &gt; &gt; ----- Original Message -----<br>
&gt; &gt; &gt; &gt; &gt; From: &quot;Budur Nagaraju&quot; &lt;<a href="mailto:nbudoor@gmail.com">nbudoor@gmail.com</a>&gt;<br>
&gt; &gt; &gt; &gt; &gt; To: <a href="mailto:users@ovirt.org">users@ovirt.org</a><br>
&gt; &gt; &gt; &gt; &gt; Sent: Tuesday, September 22, 2015 4:34:46 PM<br>
&gt; &gt; &gt; &gt; &gt; Subject: [ovirt-users] LDAP Authentication<br>
&gt; &gt; &gt; &gt; &gt;<br>
&gt; &gt; &gt; &gt; &gt; HI All,<br>
&gt; &gt; &gt; &gt; &gt;<br>
&gt; &gt; &gt; &gt; &gt; Can someone help me in configuring LDAP authentication for Ovirt ?<br>
&gt; &gt; &gt; &gt;<br>
&gt; &gt; &gt; &gt; Please review:<br>
&gt; &gt; &gt; &gt; <a href="http://www.ovirt.org/Features/AAA" rel="noreferrer" target="_blank">http://www.ovirt.org/Features/AAA</a><br>
&gt; &gt; &gt; &gt;<br>
&gt; &gt; &gt; &gt;<br>
&gt; &gt; <a href="https://gerrit.ovirt.org/gitweb?p=ovirt-engine-extension-aaa-ldap.git;a=blob;f=README;hb=ovirt-engine-extension-aaa-ldap-1.0" rel="noreferrer" target="_blank">https://gerrit.ovirt.org/gitweb?p=ovirt-engine-extension-aaa-ldap.git;a=blob;f=README;hb=ovirt-engine-extension-aaa-ldap-1.0</a><br>
&gt; &gt; &gt; &gt;<br>
&gt; &gt; &gt;<br>
&gt; &gt;<br>
&gt;<br>
</div></div></blockquote></div><br></div>