<html><body><div style="font-family: lucida console,sans-serif; font-size: 12pt; color: #000000"><div>Hello Ondra,</div><div>I tried increase logging and command fail</div><div><br data-mce-bogus="1"></div><div><div> "outcome" => "failed",</div><div> "failure-description" => "WFLYCTL0216: Management resource '[</div><div> (\"subsystem\" => \"logging\"),</div><div> (\"logger\" => \"org.ovirt.engine.core.sso\")</div><div>]' not found",</div><div> "rolled-back" => true</div><div>}</div></div><div><br></div><div><br data-mce-bogus="1"></div><div>Slava,</div><div><br></div><hr id="zwchr" data-marker="__DIVIDER__"><div data-marker="__HEADERS__"><b>From: </b>"Ondra Machacek" <omachace@redhat.com><br><b>To: </b>"Slava Bendersky" <volga629@networklab.ca><br><b>Cc: </b>"users" <users@ovirt.org><br><b>Sent: </b>Thursday, February 9, 2017 2:31:16 PM<br><b>Subject: </b>Re: [ovirt-users] FreeIPA with ovirt 4.1<br></div><br><div data-marker="__QUOTED_TEXT__">Can you please enable DEBUG log of the SSO package and try login and<br>then share the logs, please?<br><br>You can enable the debug log as following (use admin@internal password):<br><br>/usr/share/ovirt-engine-wildfly/bin/jboss-cli.sh<br>--controller=127.0.0.1:8706 --connect --user=admin@internal<br>"/subsystem=logging/logger=org.ovirt.engine.core.sso:add" &&<br>/usr/share/ovirt-engine-wildfly/bin/jboss-cli.sh<br>--controller=127.0.0.1:8706 --connect --user=admin@internal<br>"/subsystem=logging/logger=org.ovirt.engine.core.sso:write-attribute(name=level,value=DEBUG)"<br><br>After tests you can disable it later as follows:<br><br> $ /usr/share/ovirt-engine-wildfly/bin/jboss-cli.sh<br>--controller=127.0.0.1:8706 --connect --user=admin@internal<br>"/subsystem=logging/logger=org.ovirt.engine.core.sso:remove"<br><br>On Thu, Feb 9, 2017 at 3:08 PM, Slava Bendersky <volga629@networklab.ca> wrote:<br>> Hello Everyone,<br>> Anything else possible to check ?<br>><br>> Slava.<br>><br>> ________________________________<br>> From: "Slava Bendersky" <volga629@networklab.ca><br>> To: "Ondra Machacek" <omachace@redhat.com><br>> Cc: "users" <users@ovirt.org><br>> Sent: Saturday, February 4, 2017 2:27:31 PM<br>><br>> Subject: Re: [ovirt-users] FreeIPA with ovirt 4.1<br>><br>> Hello Ondra,<br>> Log is empty<br>><br>> [root@vhe00 ~]# ls -la /var/log/httpd/ssl_error_log<br>> -rw-r--r--. 1 root root 0 Feb 2 04:45 /var/log/httpd/ssl_error_log<br>><br>> Slava.<br>><br>> ________________________________<br>> From: "Ondra Machacek" <omachace@redhat.com><br>> To: "Slava Bendersky" <volga629@networklab.ca><br>> Cc: "users" <users@ovirt.org>, "Ravi" <rnori@redhat.com><br>> Sent: Saturday, February 4, 2017 10:35:31 AM<br>> Subject: Re: [ovirt-users] FreeIPA with ovirt 4.1<br>><br>><br>><br>> On Feb 4, 2017 1:21 AM, "Slava Bendersky" <volga629@networklab.ca> wrote:<br>><br>> Hello Everyone,<br>> Having trouble implement FreeIPA authentication with GSSAPI SSO and ovirt<br>> 4.1. I ran setup and it finished OK then it wrote the files bellow. Next I<br>> log to web admin with internal user and added FeeIPA user as SuperUser role.<br>> Also I added under System FreeIPA group authorized to login on any attempt<br>> to login with FreeIPA credentials getting message<br>><br>><br>> 2017-02-04 00:03:08,464Z ERROR<br>> [org.ovirt.engine.core.sso.servlets.InteractiveAuthServlet] (default task-6)<br>> [] Internal Server Error: Unsupported command<br>> 2017-02-04 00:03:08,464Z ERROR [org.ovirt.engine.core.sso.utils.SsoUtils]<br>> (default task-6) [] Unsupported command<br>> 2017-02-04 00:03:08,659Z ERROR<br>> [org.ovirt.engine.core.aaa.servlet.SsoPostLoginServlet] (default task-3) []<br>> server_error: Unsupported command<br>><br>><br>> Ravi, do you know what this can cause?<br>><br>><br>><br>> Also when in extensions.d directory contain the following files. If I remove<br>> mydomain.lan-authn.properties then in web ui FreeIPA domain not showing up<br>> in drop down list. Any http don't have influence on this.<br>><br>><br>> That is correct behavior, we dont show profiles, which uses http for authn.<br>><br>><br>> [root@vhe00 extensions.d]# pwd<br>> /etc/ovirt-engine/extensions.d<br>><br>> [root@vhe00 extensions.d]# ls<br>> mydomain.lan-authn.properties mydomain.lan-http-authn.properties<br>> mydomain.lan.properties internal-authz.properties<br>> mydomain.lan-authz.properties mydomain.lan-http-mapping.properties<br>> internal-authn.properties<br>> [root@vhe00 extensions.d]#<br>><br>><br>> If possible clarify how it should be and what is possible issue.<br>><br>><br>> Can you please take a look to /var/log/httpd/ssl_error_log if any errors<br>> there?<br>><br>><br>><br>><br>> Slava.<br>><br>> _______________________________________________<br>> Users mailing list<br>> Users@ovirt.org<br>> http://lists.ovirt.org/mailman/listinfo/users<br>><br>><br>><br>> _______________________________________________<br>> Users mailing list<br>> Users@ovirt.org<br>> http://lists.ovirt.org/mailman/listinfo/users<br></div></div></body></html>