Hello Janos,

thanks for reply. 

Attached you find the mail.log file….

The four other files are the manual ldapsearch query with filter used from mail.log.

sso-query2.rtf shows the unsuccessful query…. I think because of using proxyAddress=smtp
The maladies found in sso-query1.rtf is correct and used in query2...


{\rtf1\ansi\ansicpg1252\cocoartf1344\cocoasubrtf600
{\fonttbl\f0\fswiss\fcharset0 Helvetica;\f1\fnil\fcharset0 Monaco;}
{\colortbl;\red255\green255\blue255;\red242\green242\blue242;\red46\green46\blue88;}
\paperw11900\paperh16840\margl1440\margr1440\vieww38200\viewh21260\viewkind0
\pard\tx566\tx1133\tx1700\tx2267\tx2834\tx3401\tx3968\tx4535\tx5102\tx5669\tx6236\tx6803\pardirnatural

\f0\fs24 \cf0 login.php - query #1:\
\
\pard\tx560\tx1120\tx1680\tx2240\tx2800\tx3360\tx3920\tx4480\tx5040\tx5600\tx6160\tx6720\pardirnatural

\f1\fs28 \cf2 \cb3 \CocoaLigature0 root@mailarchiv:~# ldapsearch -h ad1.domain.local -D 'CN=piler,CN=users,DC=domain,DC=local' -b 'OU=employees,DC=domain,DC=local' -x -W '(&(objectClass=user)([email protected]))'\
Enter LDAP Password: \
# extended LDIF\
#\
# LDAPv3\
# base <OU=employees,DC=domain,DC=local> with scope subtree\
# filter: (&(objectClass=user)([email protected]))\
# requesting: ALL\
#\
\
# christian, employees, domain.local\
dn: CN=christian,OU=employees,DC=domain,DC=local\
objectClass: top\
objectClass: person\
objectClass: organizationalPerson\
objectClass: user\
cn: christian\
instanceType: 4\
whenCreated: 20130624211526.0Z\
uSNCreated: 3748\
name: christian\
objectGUID:: duQ112pEHESCxp2Mm7WADQ==\
badPwdCount: 0\
codePage: 0\
countryCode: 0\
badPasswordTime: 0\
lastLogoff: 0\
lastLogon: 0\
primaryGroupID: 513\
objectSid:: AQUAAAAAAAUVAAAAsKPt/gur9KO9OWNyUAQAAA==\
accountExpires: 9223372036854775807\
logonCount: 0\
sAMAccountName: christian\
sAMAccountType: 805306368\
userPrincipalName: [email protected]\
objectCategory: CN=Person,CN=Schema,CN=Configuration,DC=domain,DC=local\
memberOf: CN=PilerAuditors,CN=Users,DC=domain,DC=local\
userAccountControl: 66048\
mail: [email protected]\
sn: V\
givenName: Christian\
initials: CV\
displayName: Christian Vielhauer\
managedObjects: CN=MACBOOK-CV-HOME,OU=PCs,OU=employees-PCs,DC=domain,DC=local\
telephoneNumber: 29\
whenChanged: 20141201082619.0Z\
uSNChanged: 61498\
pwdLastSet: 130618959790000000\
distinguishedName: CN=christian,OU=employees,DC=domain,DC=local\
\
# search result\
search: 2\
result: 0 Success\
\
# numResponses: 2\
# numEntries: 1}
{\rtf1\ansi\ansicpg1252\cocoartf1344\cocoasubrtf600
{\fonttbl\f0\fswiss\fcharset0 Helvetica;\f1\fnil\fcharset0 Monaco;}
{\colortbl;\red255\green255\blue255;\red242\green242\blue242;\red46\green46\blue88;}
\paperw11900\paperh16840\margl1440\margr1440\vieww38200\viewh21260\viewkind0
\pard\tx566\tx1133\tx1700\tx2267\tx2834\tx3401\tx3968\tx4535\tx5102\tx5669\tx6236\tx6803\pardirnatural

\f0\fs24 \cf0 login.php - query #2:\
\
\pard\tx560\tx1120\tx1680\tx2240\tx2800\tx3360\tx3920\tx4480\tx5040\tx5600\tx6160\tx6720\pardirnatural

\f1\fs28 \cf2 \cb3 \CocoaLigature0 root@mailarchiv:~# ldapsearch -h ad1.domain.local -D 'CN=piler,CN=users,DC=domain,DC=local' -b 'OU=employees,DC=domain,DC=local' -x -W '(|(&(objectClass=user)([email protected]))(&(objectClass=group)([email protected]))(&(objectClass=group)(member=CN=christian,OU=employees,DC=domain,DC=local)))'\
Enter LDAP Password: \
# extended LDIF\
#\
# LDAPv3\
# base <OU=employees,DC=domain,DC=local> with scope subtree\
# filter: (|(&(objectClass=user)([email protected]))(&(objectClass=group)([email protected]))(&(objectClass=group)(member=CN=christian,OU=employees,DC=domain,DC=local)))\
# requesting: ALL\
#\
\
# christian, employees, domain.local\
dn: CN=christian,OU=employees,DC=domain,DC=local\
objectClass: top\
objectClass: person\
objectClass: organizationalPerson\
objectClass: user\
cn: christian\
instanceType: 4\
whenCreated: 20130624211526.0Z\
uSNCreated: 3748\
name: christian\
objectGUID:: duQ112pEHESCxp2Mm7WADQ==\
badPwdCount: 0\
codePage: 0\
countryCode: 0\
badPasswordTime: 0\
lastLogoff: 0\
lastLogon: 0\
primaryGroupID: 513\
objectSid:: AQUAAAAAAAUVAAAAsKPt/gur9KO9OWNyUAQAAA==\
accountExpires: 9223372036854775807\
logonCount: 0\
sAMAccountName: christian\
sAMAccountType: 805306368\
userPrincipalName: [email protected]\
objectCategory: CN=Person,CN=Schema,CN=Configuration,DC=domain,DC=local\
memberOf: CN=PilerAuditors,CN=Users,DC=domain,DC=local\
userAccountControl: 66048\
mail: [email protected]\
sn: V\
givenName: Christian\
initials: CV\
displayName: Christian\
managedObjects: CN=MACBOOK-CV-HOME,OU=PCs,OU=employees-PCs,DC=domain,DC=local\
telephoneNumber: 29\
whenChanged: 20141201082619.0Z\
uSNChanged: 61498\
pwdLastSet: 130618959790000000\
distinguishedName: CN=christian,OU=employees,DC=domain,DC=local\
\
# search result\
search: 2\
result: 0 Success\
\
# numResponses: 2\
# numEntries: 1}
{\rtf1\ansi\ansicpg1252\cocoartf1344\cocoasubrtf600
{\fonttbl\f0\fnil\fcharset0 Monaco;}
{\colortbl;\red255\green255\blue255;\red242\green242\blue242;\red46\green46\blue88;}
\paperw11900\paperh16840\margl1440\margr1440\vieww38200\viewh10140\viewkind0
\pard\tx560\tx1120\tx1680\tx2240\tx2800\tx3360\tx3920\tx4480\tx5040\tx5600\tx6160\tx6720\pardirnatural

\f0\fs28 \cf2 \cb3 \CocoaLigature0 # login with login.php\
\
Jan 12 15:28:15 mailarchiv piler-webui[13147]: ldap query: base dn='OU=employees,dc=domain,dc=local', filter='(&(objectClass=user)([email protected]))', attr='', 1 hits\
Jan 12 15:28:15 mailarchiv piler-webui[13147]: ldap auth against 'ad1.domain.local', dn: 'CN=christian,OU=employees,DC=domain,DC=local', result: 1\
Jan 12 15:28:15 mailarchiv piler-webui[13147]: ldap query: base dn='OU=employees,dc=domain,dc=local', filter='(|(&(objectClass=user)([email protected]))(&(objectClass=group)([email protected]))(&(objectClass=group)(member=CN=christian,OU=employees,DC=domain,DC=local)))', attr='', 1 hits\
Jan 12 15:28:15 mailarchiv piler-webui[13147]: checking ldap entry dn: CN=christian,OU=employees,DC=domain,DC=local, cn: christian\
Jan 12 15:28:15 mailarchiv piler-webui[13147]: checking entry #2: [email protected]\
Jan 12 15:28:15 mailarchiv piler-webui[13147]: [email protected], event='logged in'\
\
\
# click on red search button without search parameters\
Jan 12 15:28:31 mailarchiv piler-webui[11644]: sphinx query: 'SELECT id FROM main1,dailydelta1,delta1 WHERE        MATCH(' (@from christianXdomainXcom | @to christianXdomainXcom) ') ORDER BY `sent` DESC LIMIT 0,1000 OPTION max_matches=1000' in 0.03 s, 1000 hits, 27097 total found\
\
\
\
\
# login with sso.php\
\
Jan 12 15:22:50 mailarchiv piler-webui[11645]: sso login: christian\
Jan 12 15:22:50 mailarchiv piler-webui[11645]: ldap query: base dn='OU=employees,dc=domain,dc=local', filter='(&(objectClass=user)(samaccountname=christian))', attr='', 1 hits\
Jan 12 15:22:50 mailarchiv piler-webui[11645]: ldap query: base dn='OU=employees,dc=domain,dc=local', filter='(|(&(objectClass=user)(proxyAddresses=smtp:[email protected]))(&(objectClass=group)([email protected]))(&(objectClass=group)(member=CN=christian,OU=employees,DC=domain,DC=local)))', attr='', 0 hits\
\
# click on red search button without search parameters\
Jan 12 15:27:46 mailarchiv piler-webui[13145]: sphinx query: 'SELECT id FROM main1,dailydelta1,delta1 WHERE        MATCH(' (@from  | @to ) ') ORDER BY `sent` DESC LIMIT 0,1000 OPTION max_matches=1000' in 0.00 s, 0 hits, 0 total found\
\
}
{\rtf1\ansi\ansicpg1252\cocoartf1344\cocoasubrtf600
{\fonttbl\f0\fswiss\fcharset0 Helvetica;\f1\fnil\fcharset0 Monaco;}
{\colortbl;\red255\green255\blue255;\red242\green242\blue242;\red46\green46\blue88;}
\paperw11900\paperh16840\margl1440\margr1440\vieww38200\viewh21260\viewkind0
\pard\tx566\tx1133\tx1700\tx2267\tx2834\tx3401\tx3968\tx4535\tx5102\tx5669\tx6236\tx6803\pardirnatural

\f0\fs24 \cf0 sso.php - query #1:\
\
\pard\tx560\tx1120\tx1680\tx2240\tx2800\tx3360\tx3920\tx4480\tx5040\tx5600\tx6160\tx6720\pardirnatural

\f1\fs28 \cf2 \cb3 \CocoaLigature0 root@mailarchiv:~# ldapsearch -h ad1.domain.local -D 'CN=piler,CN=users,DC=domain,DC=local' -b 'OU=employees,DC=domain,DC=local' -x -W '(&(objectClass=user)(samaccountname=christian))'\
Enter LDAP Password: \
# extended LDIF\
#\
# LDAPv3\
# base <OU=employees,DC=domain,DC=local> with scope subtree\
# filter: (&(objectClass=user)(samaccountname=christian))\
# requesting: ALL\
#\
\
# christian, employees, domain.local\
dn: CN=christian,OU=employees,DC=domain,DC=local\
objectClass: top\
objectClass: person\
objectClass: organizationalPerson\
objectClass: user\
cn: christian\
instanceType: 4\
whenCreated: 20130624211526.0Z\
uSNCreated: 3748\
name: christian\
objectGUID:: duQ112pEHESCxp2Mm7WADQ==\
badPwdCount: 0\
codePage: 0\
countryCode: 0\
badPasswordTime: 0\
lastLogoff: 0\
lastLogon: 0\
primaryGroupID: 513\
objectSid:: AQUAAAAAAAUVAAAAsKPt/gur9KO9OWNyUAQAAA==\
accountExpires: 9223372036854775807\
logonCount: 0\
sAMAccountName: christian\
sAMAccountType: 805306368\
userPrincipalName: [email protected]\
objectCategory: CN=Person,CN=Schema,CN=Configuration,DC=domain,DC=local\
memberOf: CN=PilerAuditors,CN=Users,DC=domain,DC=local\
userAccountControl: 66048\
mail: [email protected]\
sn: V\
givenName: Christian\
initials: CV\
displayName: Christian Vielhauer\
managedObjects: CN=MACBOOK-CV-HOME,OU=PCs,OU=employees-PCs,DC=domain,DC=local\
telephoneNumber: 29\
whenChanged: 20141201082619.0Z\
uSNChanged: 61498\
pwdLastSet: 130618959790000000\
distinguishedName: CN=christian,OU=employees,DC=domain,DC=local\
\
# search result\
search: 2\
result: 0 Success\
\
# numResponses: 2\
# numEntries: 1
\f0\fs24 \cf0 \cb1 \CocoaLigature1 \
}
{\rtf1\ansi\ansicpg1252\cocoartf1344\cocoasubrtf600
{\fonttbl\f0\fswiss\fcharset0 Helvetica;\f1\fnil\fcharset0 Monaco;}
{\colortbl;\red255\green255\blue255;\red242\green242\blue242;\red46\green46\blue88;}
\paperw11900\paperh16840\margl1440\margr1440\vieww38200\viewh21260\viewkind0
\pard\tx566\tx1133\tx1700\tx2267\tx2834\tx3401\tx3968\tx4535\tx5102\tx5669\tx6236\tx6803\pardirnatural

\f0\fs24 \cf0 sso.php - query #2:\
\
\pard\tx560\tx1120\tx1680\tx2240\tx2800\tx3360\tx3920\tx4480\tx5040\tx5600\tx6160\tx6720\pardirnatural

\f1\fs28 \cf2 \cb3 \CocoaLigature0 root@mailarchiv:~# ldapsearch -h ad1.domain.local -D 'CN=piler,CN=users,DC=domain,DC=local' -b 'OU=employees,DC=domain,DC=local' -x -W '(|(&(objectClass=user)(proxyAddresses=smtp:[email protected]))(&(objectClass=group)([email protected]))(&(objectClass=group)(member=CN=christian,OU=employees,DC=domain,DC=local)))'\
Enter LDAP Password: \
# extended LDIF\
#\
# LDAPv3\
# base <OU=employees,DC=domain,DC=local> with scope subtree\
# filter: (|(&(objectClass=user)(proxyAddresses=smtp:[email protected]))(&(objectClass=group)([email protected]))(&(objectClass=group)(member=CN=christian,OU=employees,DC=domain,DC=local)))\
# requesting: ALL\
#\
\
# search result\
search: 2\
result: 0 Success\
\
# numResponses: 1}





Am 12.01.2015 um 10:59 schrieb Janos SUTO <[email protected]>:


Hello Chris,

I think the ldap query the piler gui uses in case of an SSO login
is not correct, that's why it can't find your email addresses.

Can you show me the ldap query from your maillog, and the result if
you issue it manually using ldapsearch?

Janos

On 2015-01-11 17:32, Christian Vielhauer wrote:
Hi
eventually this helps more than my long description 😃
with following config:
$config['ENABLE_IMAP_AUTH'] = 0;
$config['ENABLE_SSO_LOGIN'] = 1;
$config['ENABLE_LDAP_AUTH'] = 1;
When I login via SSO with DOMAINchristian and my pw
I become logged in but I am not able to search through my archived mails
In user-settings my maladies is NOT listed
apache2/piler-error.log:
[Sun Jan 11 17:24:43 2015] [error] [client 10.27.8.5] PHP Warning:
PDOStatement::execute(): SQLSTATE[HY093]: Invalid parameter number: no
parameters were bound in
/var/www/mailarchiv.domain.com/system/database/mysql.php [1] on line
46, referer: https://mailarchiv.domain.com/logout.php [2]
When I login with same settings via login.php with
[email protected] and my pw
I become logged in and I can search through my archived mails
In user-settings my maladies is listed correctly
Am 11.01.2015 um 15:13 schrieb Christian Vielhauer <[email protected]>:
Hello Janos,
now piler is upgrades from 0.1.25-rc2 to 1.1.0 and all mails are reindex because of new sphinx installation, too.
Because I now using a domain (samba4) in my test lab I want to try so instead of plain imap-login.
With sogo/openchange it works great, so I thought using parameters as used for sogo.
So far everything works.
I can login using sso.php, but I can’t see my maladies in username->settings and I am not able to search my archive because the empty mailaddress field.
I can login using sso.php with DOMAINchristian
—> then in username->settings->email address: <None found>
I can login using sso.php with [email protected]
—> then in username->settings->email address: <None found>
I cannot login using login.php with [email protected] or with DOMAINchristian
—> thats ok because i have to enter my correct emailaddress [email protected]
I can login using login.php with [email protected] <<<<< thats my emailaddress
—> then in username->settings->email address: <[email protected]>
And I am able to search for mails.
My config-site.php:
$config['ENABLE_IMAP_AUTH'] = 0;
$config['ENABLE_SSO_LOGIN'] = 1;
$config['ENABLE_LDAP_AUTH'] = 1;
$config['LDAP_HOST'] = 'ad1.domain.local';
$config['LDAP_BASE_DN'] = 'OU=employees,dc=domain,dc=local';
$config['LDAP_HELPER_DN'] = 'CN=piler,CN=users,DC=domain,DC=local';
$config['LDAP_HELPER_PASSWORD'] = 'xxxxxxxx';
$config['LDAP_MAIL_ATTR'] = 'mail';
I think my problem is the different username for domain then the emailaddress.
So I try ldapsearch for my emailaddress:
ldapsearch -h ad1.domain.local -D 'CN=piler,CN=users,DC=domain,DC=local' -b ‚OU=employees,DC=domain,DC=local' -x -W '(&(objectClass=user)([email protected]))'
….
userPrincipalName: [email protected]
sAMAccountName: christian
mail: [email protected]
givenName: Christian

So I need to map the ‚mail‘-attribute to the Emailaddress-filed in Username->settings.
Hope you understand what’s going wrong in my case.
Why the mail-attribute is not bind to emailaddress after login.
Chris
Links:
------
[1] http://mailarchiv.domain.com/system/database/mysql.php
[2] https://mailarchiv.domain.com/logout.php

Reply via email to