--=_88f329a8-7b89-4d76-9087-ff4f0ae05113
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: 7bit
Hello Ondra,
I tried increase logging and command fail
"outcome" => "failed",
"failure-description" => "WFLYCTL0216: Management resource '[
(\"subsystem\" => \"logging\"),
(\"logger\" => \"org.ovirt.engine.core.sso\")
]' not found",
"rolled-back" => true
}
Slava,
From: "Ondra Machacek" <omachace(a)redhat.com>
To: "Slava Bendersky" <volga629(a)networklab.ca>
Cc: "users" <users(a)ovirt.org>
Sent: Thursday, February 9, 2017 2:31:16 PM
Subject: Re: [ovirt-users] FreeIPA with ovirt 4.1
Can you please enable DEBUG log of the SSO package and try login and
then share the logs, please?
You can enable the debug log as following (use admin@internal password):
/usr/share/ovirt-engine-wildfly/bin/jboss-cli.sh
--controller=127.0.0.1:8706 --connect --user=admin@internal
"/subsystem=logging/logger=org.ovirt.engine.core.sso:add" &&
/usr/share/ovirt-engine-wildfly/bin/jboss-cli.sh
--controller=127.0.0.1:8706 --connect --user=admin@internal
"/subsystem=logging/logger=org.ovirt.engine.core.sso:write-attribute(name=level,value=DEBUG)"
After tests you can disable it later as follows:
$ /usr/share/ovirt-engine-wildfly/bin/jboss-cli.sh
--controller=127.0.0.1:8706 --connect --user=admin@internal
"/subsystem=logging/logger=org.ovirt.engine.core.sso:remove"
On Thu, Feb 9, 2017 at 3:08 PM, Slava Bendersky <volga629(a)networklab.ca> wrote:
Hello Everyone,
Anything else possible to check ?
Slava.
________________________________
From: "Slava Bendersky" <volga629(a)networklab.ca>
To: "Ondra Machacek" <omachace(a)redhat.com>
Cc: "users" <users(a)ovirt.org>
Sent: Saturday, February 4, 2017 2:27:31 PM
Subject: Re: [ovirt-users] FreeIPA with ovirt 4.1
Hello Ondra,
Log is empty
[root@vhe00 ~]# ls -la /var/log/httpd/ssl_error_log
-rw-r--r--. 1 root root 0 Feb 2 04:45 /var/log/httpd/ssl_error_log
Slava.
________________________________
From: "Ondra Machacek" <omachace(a)redhat.com>
To: "Slava Bendersky" <volga629(a)networklab.ca>
Cc: "users" <users(a)ovirt.org>, "Ravi" <rnori(a)redhat.com>
Sent: Saturday, February 4, 2017 10:35:31 AM
Subject: Re: [ovirt-users] FreeIPA with ovirt 4.1
On Feb 4, 2017 1:21 AM, "Slava Bendersky" <volga629(a)networklab.ca> wrote:
Hello Everyone,
Having trouble implement FreeIPA authentication with GSSAPI SSO and ovirt
4.1. I ran setup and it finished OK then it wrote the files bellow. Next I
log to web admin with internal user and added FeeIPA user as SuperUser role.
Also I added under System FreeIPA group authorized to login on any attempt
to login with FreeIPA credentials getting message
2017-02-04 00:03:08,464Z ERROR
[org.ovirt.engine.core.sso.servlets.InteractiveAuthServlet] (default task-6)
[] Internal Server Error: Unsupported command
2017-02-04 00:03:08,464Z ERROR [org.ovirt.engine.core.sso.utils.SsoUtils]
(default task-6) [] Unsupported command
2017-02-04 00:03:08,659Z ERROR
[org.ovirt.engine.core.aaa.servlet.SsoPostLoginServlet] (default task-3) []
server_error: Unsupported command
Ravi, do you know what this can cause?
Also when in extensions.d directory contain the following files. If I remove
mydomain.lan-authn.properties then in web ui FreeIPA domain not showing up
in drop down list. Any http don't have influence on this.
That is correct behavior, we dont show profiles, which uses http for authn.
[root@vhe00 extensions.d]# pwd
/etc/ovirt-engine/extensions.d
[root@vhe00 extensions.d]# ls
mydomain.lan-authn.properties mydomain.lan-http-authn.properties
mydomain.lan.properties internal-authz.properties
mydomain.lan-authz.properties mydomain.lan-http-mapping.properties
internal-authn.properties
[root@vhe00 extensions.d]#
If possible clarify how it should be and what is possible issue.
Can you please take a look to /var/log/httpd/ssl_error_log if any errors
there?
Slava.
_______________________________________________
Users mailing list
Users(a)ovirt.org
http://lists.ovirt.org/mailman/listinfo/users
_______________________________________________
Users mailing list
Users(a)ovirt.org
http://lists.ovirt.org/mailman/listinfo/users
--=_88f329a8-7b89-4d76-9087-ff4f0ae05113
Content-Type: text/html; charset=utf-8
Content-Transfer-Encoding: quoted-printable
<html><body><div style=3D"font-family: lucida console,sans-serif;
font-size=
: 12pt; color: #000000"><div>Hello Ondra,</div><div>I tried
increase loggin=
g and command fail</div><div><br
data-mce-bogus=3D"1"></div><div><div> =
; "outcome" =3D>
"failed",</div><div> "failure-descr=
iption" =3D> "WFLYCTL0216: Management resource
'[</div><div>  =
; (\"subsystem\" =3D>
\"logging\"),</div><div> (\"logger\"
=
=3D> \"org.ovirt.engine.core.sso\")</div><div>]' not
found",</div><div>&=
nbsp; "rolled-back" =3D>
true</div><div>}</div></div><div><br></d=
iv><div><br
data-mce-bogus=3D"1"></div><div>Slava,</div><div><br></div><hr
=
id=3D"zwchr" data-marker=3D"__DIVIDER__"><div
data-marker=3D"__HEADERS__"><=
b>From: </b>"Ondra Machacek"
&lt;omachace(a)redhat.com&gt;<br><b>To: </b>"Sla=
va Bendersky" &lt;volga629(a)networklab.ca&gt;<br><b>Cc:
</b>"users" <user=
s(a)ovirt.org&gt;<br><b>Sent: </b>Thursday, February 9, 2017 2:31:16
PM<br><b=
Subject: </b>Re: [ovirt-users] FreeIPA with ovirt
4.1<br></div><br><div da=
ta-marker=3D"__QUOTED_TEXT__">Can you please enable DEBUG log of the
SSO pa=
ckage and try login and<br>then share the logs, please?<br><br>You can
enab=
le the debug log as following (use admin@internal password):<br><br>/usr/sh=
are/ovirt-engine-wildfly/bin/jboss-cli.sh<br>--controller=3D127.0.0.1:8706 =
--connect --user=3Dadmin(a)internal<br>"/subsystem=3Dlogging/logger=3Dorg.ovi=
rt.engine.core.sso:add"
&&<br>/usr/share/ovirt-engine-wildfly/bin/j=
boss-cli.sh<br>--controller=3D127.0.0.1:8706 --connect --user=3Dadmin@inter=
nal<br>"/subsystem=3Dlogging/logger=3Dorg.ovirt.engine.core.sso:write-attri=
bute(name=3Dlevel,value=3DDEBUG)"<br><br>After tests you can disable it
lat=
er as follows:<br><br> $
/usr/share/ovirt-engine-wildfly/bin/jboss-cli=
.sh<br>--controller=3D127.0.0.1:8706 --connect
--user=3Dadmin@internal<br>"=
/subsystem=3Dlogging/logger=3Dorg.ovirt.engine.core.sso:remove"<br><br>On
T=
hu, Feb 9, 2017 at 3:08 PM, Slava Bendersky &lt;volga629(a)networklab.ca&gt; =
wrote:<br>> Hello Everyone,<br>> Anything else possible to check
?<br=
><br>> Slava.<br>><br>>
________________________________<br>&g=
t; From: "Slava
Bendersky" &lt;volga629(a)networklab.ca&gt;<br>&gt; To: "Ondr=
a Machacek" &lt;omachace(a)redhat.com&gt;<br>&gt; Cc:
"users" <users@ovirt=
.org><br>> Sent: Saturday, February 4, 2017 2:27:31
PM<br>><br>>=
; Subject: Re: [ovirt-users] FreeIPA with ovirt 4.1<br>><br>>
Hello O=
ndra,<br>> Log is empty<br>><br>> [root@vhe00 ~]#
ls -la /va=
r/log/httpd/ssl_error_log<br>> -rw-r--r--. 1 root root 0 Feb 2
04:=
45 /var/log/httpd/ssl_error_log<br>><br>>
Slava.<br>><br>> ____=
____________________________<br>> From: "Ondra Machacek"
<omachace@re=
dhat.com><br>> To: "Slava Bendersky"
&lt;volga629(a)networklab.ca&gt;<b=
r>> Cc: "users" &lt;users(a)ovirt.org&gt;, "Ravi"
&lt;rnori(a)redhat.com&gt;=
<br>> Sent: Saturday, February 4, 2017 10:35:31 AM<br>> Subject:
Re: =
[ovirt-users] FreeIPA with ovirt
4.1<br>><br>><br>><br>> On Feb=
4, 2017 1:21 AM, "Slava Bendersky" &lt;volga629(a)networklab.ca&gt;
wrote:<b=
r>><br>> Hello Everyone,<br>> Having trouble implement
FreeI=
PA authentication with GSSAPI SSO and ovirt<br>> 4.1. I ran setup
=
and it finished OK then it wrote the files bellow. Next I<br>> log to we=
b admin with internal user and added FeeIPA user as SuperUser role.<br>>=
Also I added under System FreeIPA group authorized to login on any attempt=
<br>> to login with FreeIPA credentials getting
message<br>><br>><=
br>> 2017-02-04 00:03:08,464Z ERROR<br>>
[org.ovirt.engine.core.sso.s=
ervlets.InteractiveAuthServlet] (default task-6)<br>> [] Internal Server=
Error: Unsupported command<br>> 2017-02-04 00:03:08,464Z ERROR [org.ovi=
rt.engine.core.sso.utils.SsoUtils]<br>> (default task-6) [] Unsupported =
command<br>> 2017-02-04 00:03:08,659Z ERROR<br>>
[org.ovirt.engine.co=
re.aaa.servlet.SsoPostLoginServlet] (default task-3) []<br>> server_erro=
r: Unsupported command<br>><br>><br>> Ravi, do you
know what this =
can cause?<br>><br>><br>><br>> Also
when in extensions.d direct=
ory contain the following files. If I remove<br>> mydomain.lan-authn.pro=
perties then in web ui FreeIPA domain not showing up<br>> in drop down l=
ist. Any http don't have influence on
this.<br>><br>><br>> That is=
correct behavior, we dont show profiles, which uses http for authn.<br>>=
;<br>><br>> [root@vhe00 extensions.d]# pwd<br>>
/etc/ovirt-engine/=
extensions.d<br>><br>> [root@vhe00 extensions.d]#
ls<br>> mydomain=
.lan-authn.properties mydomain.lan-http-authn.properties<br>> mydomain.l=
an.properties internal-authz.properties<br>>
mydomai=
n.lan-authz.properties mydomain.lan-http-mapping.properties<br>> interna=
l-authn.properties<br>> [root@vhe00
extensions.d]#<br>><br>><br>&g=
t; If possible clarify how it should be and what is possible issue.<br>>=
<br>><br>> Can you please take a look to
/var/log/httpd/ssl_error_log=
if any errors<br>>
there?<br>><br>><br>><br>><br>>
Slava=
.<br>><br>>
_______________________________________________<br>> U=
sers mailing list<br>> Users(a)ovirt.org<br>&gt;
http://lists.ovirt.org/ma=
ilman/listinfo/users<br>><br>><br>><br>>
______________________=
_________________________<br>> Users mailing list<br>>
Users(a)ovirt.or=
g<br>>
http://lists.ovirt.org/mailman/listinfo/users<br></div></d...
dy></html>
--=_88f329a8-7b89-4d76-9087-ff4f0ae05113--