Fabrice,
Thanks, works..
I needed to add the passthrought lines in the file
/usr/local/pf/conf/pf.conf.defaults

Regards


2017-10-25 15:40 GMT-02:00 Fabrice Durand <fdur...@inverse.ca>:

> You have to allow accounts.google.com in the passthrough too.
>
> Do a pfcmd configreload hard and a pfcmd service pfdns restart to force
> the update of the passthrough.
>
> Regards
>
> Fabrice
>
>
>
> Le 2017-10-25 à 13:34, Diego Lopes da Cruz a écrit :
>
> Sorry,
> I forgot the attachment...
>
>
>
> 2017-10-25 15:18 GMT-02:00 Diego Lopes da Cruz <diego.lo...@gmail.com>:
>
>> Fabrice,
>> *"you will need to remove facebook from the dns_filters.conf.default in
>> order to fix the fqdn graph.facebook.com <http://graph.facebook.com/>."*
>> *OK, works, thanks!*
>> *"Also the passthroughs for the OAuth sources are in the OAuth config
>> itself (pf side)*."
>> *OK, I found!*
>>
>> *I am having HSTS message from the browser when authenticating with
>> google (see attachment).*
>>
>> *Do I need to generate or install a certificate? *
>> *Can you solve this?*
>> *Thank you!*
>>
>>
>>
>> 2017-10-25 14:37 GMT-02:00 Fabrice Durand via PacketFence-users <
>> packetfence-users@lists.sourceforge.net>:
>>
>>> Hello Diego,
>>>
>>> you will need to remove facebook from the dns_filters.conf.default in
>>> order to fix the fqdn graph.facebook.com.
>>>
>>> Also the passthroughs for the OAuth sources are in the OAuth config
>>> itself (pf side).
>>>
>>> Regards
>>>
>>> Fabrice
>>>
>>>
>>>
>>> Le 2017-10-25 à 12:29, Diego Lopes da Cruz via PacketFence-users a
>>> écrit :
>>>
>>> Hi all,
>>> I'm testing the packetfence ZEN (Pecketfence-7.3.0-2 version) and I'm
>>> trying to use authentication via facebook or google. I have done the
>>> configuration of the API ID and secret of both, but when this in the
>>> authentication screen, the client can not reach the screen of facebook and
>>> google. On the client, the graph.facebook.com domain is being resolved
>>> to 127.0.0.1 and account.google.com for the packetfence LAN IP.
>>> I've been searching the forums and seen that I should put * .
>>> facebook.com and * .google.com domains in "accepted or freed domains"
>>> configuration.
>>> Where is this setting?
>>>
>>> thanks
>>> --
>>> Diego
>>>
>>>
>>> ------------------------------------------------------------------------------
>>> Check out the vibrant tech community on one of the world's most
>>> engaging tech sites, Slashdot.org! http://sdm.link/slashdot
>>>
>>>
>>>
>>> _______________________________________________
>>> PacketFence-users mailing 
>>> listPacketFence-users@lists.sourceforge.nethttps://lists.sourceforge.net/lists/listinfo/packetfence-users
>>>
>>>
>>> --
>>> Fabrice durandfdur...@inverse.ca ::  +1.514.447.4918 <+1%20514-447-4918> 
>>> (x135) ::  www.inverse.ca
>>> Inverse inc. :: Leaders behind SOGo (http://www.sogo.nu) and PacketFence 
>>> (http://packetfence.org)
>>>
>>>
>>> ------------------------------------------------------------
>>> ------------------
>>> Check out the vibrant tech community on one of the world's most
>>> engaging tech sites, Slashdot.org! http://sdm.link/slashdot
>>> _______________________________________________
>>> PacketFence-users mailing list
>>> PacketFence-users@lists.sourceforge.net
>>> https://lists.sourceforge.net/lists/listinfo/packetfence-users
>>>
>>>
>>
>>
>> --
>> Diego
>>
>
>
>
> --
> Diego Lopes da Cruz
> 48-9 9609-9931 (TIM) Whatsapp
> 48-9 8489-1060 (OI)
>
>
> --
> Fabrice durandfdur...@inverse.ca ::  +1.514.447.4918 <+1%20514-447-4918> 
> (x135) ::  www.inverse.ca
> Inverse inc. :: Leaders behind SOGo (http://www.sogo.nu) and PacketFence 
> (http://packetfence.org)
>
>


-- 
Diego Lopes da Cruz
48-9 9609-9931 (TIM) Whatsapp
48-9 8489-1060 (OI)
------------------------------------------------------------------------------
Check out the vibrant tech community on one of the world's most
engaging tech sites, Slashdot.org! http://sdm.link/slashdot
_______________________________________________
PacketFence-users mailing list
PacketFence-users@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/packetfence-users

Reply via email to