On Fri, Aug 23, 2013 at 3:09 PM, Janos SUTO <[email protected]> wrote: > > On 2013-08-23 23:55, Stephen Ingram wrote: > > No SSO enabled (I assume it's disabled by default), just trying to >> > > yes > > > use LDAP right now. It works for the users and they are regular users >> when they login, however, there is no fallback to local users so I can >> login as admin@local. There is no error, it just forwards to the >> http://.../search.php URL, but still showing the login screen. No >> errors in Web server log or anywhere else that I can find. Once I turn >> off LDAP auth, I can login again as admin@local. Strange. >> > > hmm, there's a file model/user/auth.php, and it tries ldap auth (if > enabled), > then imap auth (likewise), then finally local auth always. > > So to debug it, could you put some similar line into this file? > > syslog(LOG_INFO, "we are here, $username"); > > syslog(LOG_INFO, "we are there, $username"); > > and please make sure that ENABLE_SYSLOG is set to 1.
Not sure how this is happening, but it looks like admin@local is authenticating as true against LDAP and then pushes to the search.php page, however, since there is really no user the page doesn't render correctly and the login page is still displayed. There is no email address anywhere in the directory like that (admin@local) so I'm not sure how that is happening. Here is the log excerpt: Aug 23 22:47:14 ip-10-252-86-219 piler-webui[17315]: ldap query: base dn='dc=4test,dc=net', filter='(|(&(objectClass=mailRecipient)(mail=admin@local ))(&(objectClass=zimbraDistributionList)(zimbraMailForwardingAddress=admin@local)))', attr='', 0 hits Aug 23 22:47:14 ip-10-252-86-219 piler-webui[17315]: ldap auth against ' ldap1.4test.net', dn: '', result: 1 <--this indicates success, no? Aug 23 22:47:14 ip-10-252-86-219 piler-webui[17315]: we are ldap ok, admin@local <--this is the snippet I added I tried a known user and used the wrong password and the code correctly indicates that the login failed. The WebUI also indicates this with the red "Invalid password" notice. Since the admin@local user successfully authenticates against LDAP, I'm guessing the system never tries the local DB. Interestingly, if I try the IMAP auth and turn off LDAP auth, everything works as it should. Steve
