<html><head><meta http-equiv="content-type" content="text/html; charset=UTF-8"><style>body { line-height: 1.5; }blockquote { margin-top: 0px; margin-bottom: 0px; margin-left: 0.5em; }body { font-size: 10.5pt; font-family: 微软雅黑; color: rgb(0, 0, 0); line-height: 1.5; }body { font-size: 10.5pt; font-family: 微软雅黑; color: rgb(0, 0, 0); line-height: 1.5; }</style></head><body>
<blockquote style="margin-top: 0px; margin-bottom: 0px; margin-left: 0.5em;"><div>Thanks! I excuted "<span style="font-size: 10.5pt; line-height: 1.5; background-color: window;">ovirt-engine-extension-aaa-ldap-setup</span><span style="font-size: 10.5pt; line-height: 1.5; background-color: window;">", but I got an error. Is there anything wrong?</span></div><div><br></div><div>[root@engine ~]# ovirt-engine-extension-aaa-ldap-setup </div><div>[ INFO ] Stage: Initializing<br>[ INFO ] Stage: Environment setup<br> Configuration files: ['/etc/ovirt-engine-extension-aaa-ldap-setup.conf.d/10-packaging.conf']<br> Log file: /tmp/ovirt-engine-extension-aaa-ldap-setup-20170608112535-jll8t2.log<br> Version: otopi-1.6.2 (otopi-1.6.2-1.el7.centos)<br>[ INFO ] Stage: Environment packages setup<br>[ INFO ] Stage: Programs detection<br>[ INFO ] Stage: Environment customization<br> Welcome to LDAP extension configuration program<br> Available LDAP implementations:<br> 1 - 389ds<br> 2 - 389ds RFC-2307 Schema<br> 3 - Active Directory<br> 4 - IBM Security Directory Server<br> 5 - IBM Security Directory Server RFC-2307 Schema<br> 6 - IPA<br> 7 - Novell eDirectory RFC-2307 Schema<br> 8 - OpenLDAP RFC-2307 Schema<br> 9 - OpenLDAP Standard Schema<br> 10 - Oracle Unified Directory RFC-2307 Schema<br> 11 - RFC-2307 Schema (Generic)<br> 12 - RHDS<br> 13 - RHDS RFC-2307 Schema<br> 14 - iPlanet<br> Please select: 3<br> Please enter Active Directory Forest name: horebdata.com<br>[ INFO ] Resolving Global Catalog SRV record for horebdata.com<br>[ INFO ] Resolving LDAP SRV record for horebdata.com<br> NOTE:<br> It is highly recommended to use secure protocol to access the LDAP server.<br> Protocol startTLS is the standard recommended method to do so.<br> Only in cases in which the startTLS is not supported, fallback to non standard ldaps protocol.<br> Use plain for test environments only.<br> Please select protocol to use (startTLS, ldaps, plain) [startTLS]: plain<br>[ INFO ] Resolving SRV record 'horebdata.com'<br>[ INFO ] Connecting to LDAP using 'ldap://win-fvdsocg3abj.horebdata.com:389'<br>[ INFO ] Connection succeeded<br> Enter search user DN (for example uid=username,dc=example,dc=com or leave empty for anonymous): <br>[ INFO ] Attempting to bind using '[Anonymous]'<br> Are you going to use Single Sign-On for Virtual Machines (Yes, No) [No]: yes<br> NOTE:<br> Profile name has to match domain name, otherwise Single Sign-On for Virtual Machines will not work.<br> Please specify profile name that will be visible to users [horebdata.com]: <br>[ INFO ] Stage: Setup validation<br> The following files are about to be overwritten:<br> /etc/ovirt-engine/extensions.d/horebdata.com-authn.properties<br> /etc/ovirt-engine/extensions.d/horebdata.com.properties<br> /etc/ovirt-engine/aaa/horebdata.com.properties<br> Continue and overwrite? (Yes, No) [No]: yes<br> NOTE:<br> It is highly recommended to test drive the configuration before applying it into engine.<br> Perform at least one Login sequence and one Search sequence.<br> Select test sequence to execute (Done, Abort, Login, Search) [Abort]: login<br> Enter user name: horebdata<br> Enter user password: <br>[ INFO ] Executing login sequence...<br> Login output:<br> 2017-06-08 11:26:09,446+08 INFO ========================================================================<br> 2017-06-08 11:26:09,463+08 INFO ============================ Initialization ============================<br> 2017-06-08 11:26:09,463+08 INFO ========================================================================<br> 2017-06-08 11:26:09,475+08 INFO Loading extension 'horebdata.com-authn'<br> 2017-06-08 11:26:09,517+08 INFO Extension 'horebdata.com-authn' loaded<br> 2017-06-08 11:26:09,522+08 INFO Loading extension 'horebdata.com'<br> 2017-06-08 11:26:09,530+08 INFO Extension 'horebdata.com' loaded<br> 2017-06-08 11:26:09,531+08 INFO Initializing extension 'horebdata.com-authn'<br> 2017-06-08 11:26:09,532+08 INFO [ovirt-engine-extension-aaa-ldap.authn::horebdata.com-authn] Creating LDAP pool 'authz'<br> 2017-06-08 11:26:09,620+08 INFO [ovirt-engine-extension-aaa-ldap.authn::horebdata.com-authn] LDAP pool 'authz' information: vendor='null' version='null'<br> 2017-06-08 11:26:09,621+08 INFO [ovirt-engine-extension-aaa-ldap.authn::horebdata.com-authn] Creating LDAP pool 'authn'<br> 2017-06-08 11:26:09,636+08 INFO [ovirt-engine-extension-aaa-ldap.authn::horebdata.com-authn] LDAP pool 'authn' information: vendor='null' version='null'<br> 2017-06-08 11:26:09,649+08 WARNING [ovirt-engine-extension-aaa-ldap.authn::horebdata.com-authn] Cannot initialize LDAP framework, deferring initialization. Error: Unexpected comma or semicolon found at the end of the DN string.<br> 2017-06-08 11:26:09,650+08 INFO Extension 'horebdata.com-authn' initialized<br> 2017-06-08 11:26:09,650+08 INFO Initializing extension 'horebdata.com'<br> 2017-06-08 11:26:09,651+08 INFO [ovirt-engine-extension-aaa-ldap.authz::horebdata.com] Creating LDAP pool 'authz'<br> 2017-06-08 11:26:09,679+08 INFO [ovirt-engine-extension-aaa-ldap.authz::horebdata.com] LDAP pool 'authz' information: vendor='null' version='null'<br> 2017-06-08 11:26:09,679+08 INFO [ovirt-engine-extension-aaa-ldap.authz::horebdata.com] Creating LDAP pool 'gc'<br> 2017-06-08 11:26:09,694+08 INFO [ovirt-engine-extension-aaa-ldap.authz::horebdata.com] LDAP pool 'gc' information: vendor='null' version='null'<br> 2017-06-08 11:26:09,697+08 WARNING [ovirt-engine-extension-aaa-ldap.authz::horebdata.com] Cannot initialize LDAP framework, deferring initialization. Error: Unexpected comma or semicolon found at the end of the DN string.<br> 2017-06-08 11:26:09,697+08 INFO Extension 'horebdata.com' initialized<br> 2017-06-08 11:26:09,697+08 INFO Start of enabled extensions list<br> 2017-06-08 11:26:09,697+08 INFO Instance name: 'horebdata.com', Extension name: 'ovirt-engine-extension-aaa-ldap.authz', Version: '1.3.1', Notes: 'Display name: ovirt-engine-extension-aaa-ldap-1.3.1-1.el7.centos', License: 'ASL 2.0', Home: 'http://www.ovirt.org', Author 'The oVirt Project', Build interface Version: '0', File: '/tmp/tmpHfBhQf/extensions.d/horebdata.com.properties', Initialized: 'true'<br> 2017-06-08 11:26:09,698+08 INFO Instance name: 'horebdata.com-authn', Extension name: 'ovirt-engine-extension-aaa-ldap.authn', Version: '1.3.1', Notes: 'Display name: ovirt-engine-extension-aaa-ldap-1.3.1-1.el7.centos', License: 'ASL 2.0', Home: 'http://www.ovirt.org', Author 'The oVirt Project', Build interface Version: '0', File: '/tmp/tmpHfBhQf/extensions.d/horebdata.com-authn.properties', Initialized: 'true'<br> 2017-06-08 11:26:09,698+08 INFO End of enabled extensions list<br> 2017-06-08 11:26:09,698+08 INFO ========================================================================<br> 2017-06-08 11:26:09,698+08 INFO ============================== Execution ===============================<br> 2017-06-08 11:26:09,698+08 INFO ========================================================================<br> 2017-06-08 11:26:09,698+08 INFO Iteration: 0<br> 2017-06-08 11:26:09,699+08 INFO Profile='horebdata.com' authn='horebdata.com-authn' authz='horebdata.com' mapping='null'<br> 2017-06-08 11:26:09,699+08 INFO API: -->Authn.InvokeCommands.AUTHENTICATE_CREDENTIALS profile='horebdata.com' user='horebdata'<br> 2017-06-08 11:26:09,702+08 WARNING [ovirt-engine-extension-aaa-ldap.authn::horebdata.com-authn] Cannot initialize LDAP framework, deferring initialization. Error: Unexpected comma or semicolon found at the end of the DN string.<br> 2017-06-08 11:26:09,703+08 SEVERE Unexpected comma or semicolon found at the end of the DN string.<br>[ ERROR ] Login sequence failed<br> Please investigate details of the failure (search for lines containing SEVERE log level).<br> Select test sequence to execute (Done, Abort, Login, Search) [Abort]: </div><div> </div><div style="border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0cm 0cm 0cm"><div style="PADDING-RIGHT: 8px; PADDING-LEFT: 8px; FONT-SIZE: 12px;FONT-FAMILY:tahoma;COLOR:#000000; BACKGROUND: #efefef; PADDING-BOTTOM: 8px; PADDING-TOP: 8px"><div><b>From:</b> <a href="mailto:omachace@redhat.com">Ondra Machacek</a></div><div><b>Date:</b> 2017-06-07 14:47</div><div><b>To:</b> <a href="mailto:qinglong.dong@horebdata.cn">qinglong.dong@horebdata.cn</a></div><div><b>CC:</b> <a href="mailto:users@ovirt.org">users</a></div><div><b>Subject:</b> Re: [ovirt-users] active directory</div></div></div><div><div>Or you can try the migration tool:</div>
<div> </div>
<div> https://github.com/oVirt/ovirt-engine-kerbldap-migration</div>
<div> </div>
<div>Check the README, there are instructions how to procceed.</div>
<div> </div>
<div>On Wed, Jun 7, 2017 at 8:33 AM, Latchezar Filtchev <Latcho@aubg.bg> wrote:</div>
<div>> This can help you:</div>
<div>></div>
<div>></div>
<div>></div>
<div>> http://lists.ovirt.org/pipermail/users/2016-September/042937.html</div>
<div>></div>
<div>></div>
<div>></div>
<div>> Best,</div>
<div>></div>
<div>> Latcho</div>
<div>></div>
<div>></div>
<div>></div>
<div>></div>
<div>></div>
<div>> From: users-bounces@ovirt.org [mailto:users-bounces@ovirt.org] On Behalf Of</div>
<div>> qinglong.dong@horebdata.cn</div>
<div>> Sent: Wednesday, June 07, 2017 4:57 AM</div>
<div>> To: users</div>
<div>> Subject: [ovirt-users] active directory</div>
<div>></div>
<div>></div>
<div>></div>
<div>> Hi all,</div>
<div>></div>
<div>> I used "engine-manage-domains" to add AD to ovirt in earlier</div>
<div>> version. What should I do in ovirt 4.1? Hope someone can help. Thanks!</div>
<div>></div>
<div>></div>
<div>> _______________________________________________</div>
<div>> Users mailing list</div>
<div>> Users@ovirt.org</div>
<div>> http://lists.ovirt.org/mailman/listinfo/users</div>
<div>></div>
<div> </div>
</div></blockquote>
</body></html>