Hello,

In my current job, we use CAS to authenticate users for different 
applications. It uses an openldap backend to search for users. 

We have a need for a functionality that require the use of 
slapo-translucent proxy. I have this part working with basic openldap tools 
but not with CAS. During the authentication phase with CAS users a 
rejected. When debugging what happens, I can see that there is no dn 
returned with the search operation before binding attempt. If I do the same 
search operation with lpadsearch client, I have the output I expect. 

A CAS request produces these logs:
Client -> Proxy 
Jan 14 10:26:36 ldap-sudo slapd[8845]: conn=1017 fd=13 ACCEPT from 
IP=10.93.64.180:57109 (IP=0.0.0.0:389)
Jan 14 10:26:36 ldap-sudo slapd[8845]: conn=1017 op=0 BIND 
dn="uid=cas-auth,ou=si,ou=access,dc=domain,dc=com" method=128
Jan 14 10:26:36 ldap-sudo slapd[8845]: conn=1017 op=0 BIND 
dn="uid=cas-auth,ou=si,ou=access,dc=domain,dc=com" mech=SIMPLE ssf=0
Jan 14 10:26:36 ldap-sudo slapd[8845]: conn=1017 op=0 RESULT tag=97 err=0 
text=
Jan 14 10:26:36 ldap-sudo slapd[8845]: conn=1017 op=1 SRCH 
base="ou=People,dc=domain,dc=com" scope=2 deref=3 filter="(uid=myuser)"
Jan 14 10:26:36 ldap-sudo slapd[8845]: conn=1017 op=1 SRCH attr=1.1
Jan 14 10:26:36 ldap-sudo slapd[8845]: conn=1017 op=1 SEARCH RESULT tag=101 
err=0 nentries=0 text=
Jan 14 10:27:00 ldap-sudo slapd[8845]: conn=1017 fd=13 closed (connection 
lost)

Proxy -> Slave
Jan 14 10:26:36 ldap-data slapd[6491]: conn=1747 fd=13 ACCEPT from 
IP=10.93.64.207:35881 (IP=0.0.0.0:389)
Jan 14 10:26:36 ldap-data slapd[6491]: conn=1747 op=0 [IP=10.93.64.180 
USERNAME=uid=cas-auth,ou=si,ou=access,dc=domain,dc=com] BIND 
dn="uid=cas-auth,ou=si,ou=access,dc=domain,dc=com" method=128
Jan 14 10:26:36 ldap-data slapd[6491]: conn=1747 op=0 [IP=10.93.64.180 
USERNAME=uid=cas-auth,ou=si,ou=access,dc=domain,dc=com] BIND 
dn="uid=cas-auth,ou=SI,ou=Access,dc=domain,dc=com" mech=SIMPLE ssf=0
Jan 14 10:26:36 ldap-data slapd[6491]: conn=1747 op=0 [IP=10.93.64.180 
USERNAME=uid=cas-auth,ou=si,ou=access,dc=domain,dc=com] RESULT tag=97 err=0 
text=
Jan 14 10:27:00 ldap-data slapd[6491]: conn=1747 op=1 UNBIND
Jan 14 10:27:00 ldap-data slapd[6491]: conn=1747 fd=13 closed

While the same request with ldapsearch from the same host produces this: 
Client -> Proxy 
Jan 14 10:39:42 ldap-sudo slapd[8845]: conn=1019 fd=13 ACCEPT from 
IP=10.93.64.180:57730 (IP=0.0.0.0:389)
Jan 14 10:39:42 ldap-sudo slapd[8845]: conn=1019 op=0 BIND 
dn="uid=cas-auth,ou=SI,ou=access,dc=domain,dc=com" method=128
Jan 14 10:39:42 ldap-sudo slapd[8845]: conn=1019 op=0 BIND 
dn="uid=cas-auth,ou=SI,ou=access,dc=domain,dc=com" mech=SIMPLE ssf=0
Jan 14 10:39:42 ldap-sudo slapd[8845]: conn=1019 op=0 RESULT tag=97 err=0 
text=
Jan 14 10:39:42 ldap-sudo slapd[8845]: conn=1019 op=1 SRCH 
base="ou=people,dc=domain,dc=com" scope=2 deref=3 filter="(uid=myuser)"
Jan 14 10:39:42 ldap-sudo slapd[8845]: conn=1019 op=1 SRCH attr=1.1
Jan 14 10:39:42 ldap-sudo slapd[8845]: conn=1019 op=1 SEARCH RESULT tag=101 
err=0 nentries=1 text=
Jan 14 10:39:42 ldap-sudo slapd[8845]: conn=1019 op=2 UNBIND
Jan 14 10:39:42 ldap-sudo slapd[8845]: conn=1019 fd=13 closed

Proxy -> Slave
Jan 14 10:39:42 ldap-data slapd[6491]: conn=1759 fd=25 ACCEPT from 
IP=10.93.64.207:37513 (IP=0.0.0.0:389)
Jan 14 10:39:42 ldap-data slapd[6491]: conn=1759 op=0 [IP=10.93.64.180 
USERNAME=uid=cas-auth,ou=SI,ou=access,dc=domain,dc=com] BIND 
dn="uid=cas-auth,ou=SI,ou=access,dc=domain,dc=com" method=128
Jan 14 10:39:42 ldap-data slapd[6491]: conn=1759 op=0 [IP=10.93.64.180 
USERNAME=uid=cas-auth,ou=SI,ou=access,dc=domain,dc=com] BIND 
dn="uid=cas-auth,ou=SI,ou=Access,dc=domain,dc=com" mech=SIMPLE ssf=0
Jan 14 10:39:42 ldap-data slapd[6491]: conn=1759 op=0 [IP=10.93.64.180 
USERNAME=uid=cas-auth,ou=SI,ou=access,dc=domain,dc=com] RESULT tag=97 err=0 
text=
Jan 14 10:39:42 ldap-data slapd[6491]: conn=1759 op=1 [IP=10.93.64.180 
USERNAME=uid=cas-auth,ou=SI,ou=access,dc=domain,dc=com] SRCH 
base="ou=people,dc=domain,dc=com" scope=2 deref=3 filter="(uid=myuser)"
Jan 14 10:39:42 ldap-data slapd[6491]: conn=1759 op=1 [IP=10.93.64.180 
USERNAME=uid=cas-auth,ou=SI,ou=access,dc=domain,dc=com] SRCH attr=* +
Jan 14 10:39:42 ldap-data slapd[6491]: conn=1759 op=1 [IP=10.93.64.180 
USERNAME=uid=cas-auth,ou=SI,ou=access,dc=domain,dc=com] SEARCH RESULT 
tag=101 err=0 nentries=1 text=
Jan 14 10:39:42 ldap-data slapd[6491]: conn=1759 op=2 UNBIND
Jan 14 10:39:42 ldap-data slapd[6491]: conn=1759 fd=25 closed

Does any one have used this type of configuration and had success with 
results? Maybe there is something I have missed. I also asked on the 
openldap lists but with no responses for the moment. 
https://www.mail-archive.com/[email protected]/msg19402.html

Any help is welcome. Thanks

-- 
You received this message because you are subscribed to the Google Groups "CAS 
Community" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
Visit this group at https://groups.google.com/a/apereo.org/group/cas-user/.

Reply via email to