Re: [PacketFence-users] [Packetfence] AD authentication with FreeRadius: "reading winbind reply failed!"

2018-03-12 Thread Jimmy Claes via PacketFence-users
The result
[cid:image001.png@01D3B7BA.5CF645C0]
Regards
Jimmy
Van: Fabrice Durand via PacketFence-users 
[mailto:packetfence-users@lists.sourceforge.net]
Verzonden: vrijdag 9 maart 2018 14:54
Aan: packetfence-users@lists.sourceforge.net
CC: Fabrice Durand <fdur...@inverse.ca>
Onderwerp: Re: [PacketFence-users] [Packetfence] AD authentication with 
FreeRadius: "reading winbind reply failed!"


do a: ps -edf|grep radius
and paste me the result.

Regards
Fabrice
Le 2018-03-09 à 08:46, Jimmy Claes via PacketFence-users a écrit :
Hello Fabrice

Packetfence radius server is running:
[cid:image002.png@01D3B7BA.5CF645C0]

Regards
Jimmy

Van: Fabrice Durand via PacketFence-users 
[mailto:packetfence-users@lists.sourceforge.net]
Verzonden: vrijdag 9 maart 2018 14:35
Aan: 
packetfence-users@lists.sourceforge.net<mailto:packetfence-users@lists.sourceforge.net>
CC: Fabrice Durand <fdur...@inverse.ca><mailto:fdur...@inverse.ca>
Onderwerp: Re: [PacketFence-users] [Packetfence] AD authentication with 
FreeRadius: "reading winbind reply failed!"


Hello Jimmy,

you are not running the radius packetfence server , it's why it's not working.

Go in /usr/local/pf/ and do ./bin/pfcmd service radiusd start

Regards

Fabrice



Le 2018-03-09 à 02:07, Jimmy Claes via PacketFence-users a écrit :
Hello Fabrice

I ran the command u said, but there was no output at all. I ran raddebug -f 
var/run/radiusd.sock -t 3000 > raddebug.log and this file was completely empty 
after it completed running.

Regards
Jimmy

Van: Fabrice Durand via PacketFence-users 
[mailto:packetfence-users@lists.sourceforge.net]
Verzonden: donderdag 8 maart 2018 14:29
Aan: 
packetfence-users@lists.sourceforge.net<mailto:packetfence-users@lists.sourceforge.net>
CC: Fabrice Durand <fdur...@inverse.ca><mailto:fdur...@inverse.ca>
Onderwerp: Re: [PacketFence-users] [Packetfence] AD authentication with 
FreeRadius: "reading winbind reply failed!"


cd /usr/local/pf

raddebug -f var/run/radiusd.sock -t 3000

Le 2018-03-08 à 02:57, Jimmy Claes via PacketFence-users a écrit :
Hello Fabrice

When I run the command it says that file does not exist, neither does the 
directory '/etc/raddb/':
[imap://fdur...@mail.inverse.ca:143/fetch%3EUID%3E/PacketFence%20Users%20List%3E24241?header=quotebody=1.1.2=image001.png]

Regards
Jimmy

Van: Fabrice Durand via PacketFence-users 
[mailto:packetfence-users@lists.sourceforge.net]
Verzonden: woensdag 7 maart 2018 23:09
Aan: 
packetfence-users@lists.sourceforge.net<mailto:packetfence-users@lists.sourceforge.net>
CC: Fabrice Durand <fdur...@inverse.ca><mailto:fdur...@inverse.ca>
Onderwerp: Re: [PacketFence-users] [Packetfence] AD authentication with 
FreeRadius: "reading winbind reply failed!"


Ok can you send me a complete radius request ? (raddebug -f 
var/run/radiusd.sock -t 3000)

Regards

Fabrice



Le 2018-03-07 à 02:04, Jimmy Claes via PacketFence-users a écrit :
Hello Fabrice

Realms are already created and associated with the AD.
[imap://fdur...@mail.inverse.ca:143/fetch%3EUID%3E/PacketFence%20Users%20List%3E24241?header=quotebody=1.1.3=image002.png]


Regards
Jimmy

Van: Durand fabrice via PacketFence-users 
[mailto:packetfence-users@lists.sourceforge.net]
Verzonden: woensdag 7 maart 2018 3:26
Aan: 
packetfence-users@lists.sourceforge.net<mailto:packetfence-users@lists.sourceforge.net>
CC: Durand fabrice <fdur...@inverse.ca><mailto:fdur...@inverse.ca>
Onderwerp: Re: [PacketFence-users] [Packetfence] AD authentication with 
FreeRadius: "reading winbind reply failed!"


Hello Jimmy,

create the realms associated to your domain, like you have a user like ACME\bob 
and b...@acme.com<mailto:b...@acme.com> then create the 2 realms and associate 
them to your AD.

Regards

Fabrice



Le 2018-03-06 à 07:14, Jimmy Claes via PacketFence-users a écrit :
I've been trying to figure out this problem for days, whenever I try to 
authenticate a user on Windows, I get the following error while the login is 
correct:
[imap://fdur...@mail.inverse.ca:143/fetch%3EUID%3E/PacketFence%20Users%20List%3E24241?header=quotebody=1.1.4=image003.png]

'wbinfo -p' fails aswell:
[imap://fdur...@mail.inverse.ca:143/fetch%3EUID%3E/PacketFence%20Users%20List%3E24241?header=quotebody=1.1.5=image004.png]

Winbind service is running:
[imap://fdur...@mail.inverse.ca:143/fetch%3EUID%3E/PacketFence%20Users%20List%3E24241?header=quotebody=1.1.6=image005.png]

Freeradius service is running:
[imap://fdur...@mail.inverse.ca:143/fetch%3EUID%3E/PacketFence%20Users%20List%3E24241?header=quotebody=1.1.7=image006.png]

The permissions on winbindd_privileged are properly set:
[imap://fdur...@mail.inverse.ca:143/fetch%3EUID%3E/PacketFence%20Users%20List%3E24241?header=quotebody=1.1.8=image007.png]

Result of running 'freeradius -X' attached.









---

Re: [PacketFence-users] [Packetfence] AD authentication with FreeRadius: "reading winbind reply failed!"

2018-03-09 Thread Jimmy Claes via PacketFence-users
Hello Fabrice

Packetfence radius server is running:
[cid:image001.png@01D3B7B5.5D482890]

Regards
Jimmy

Van: Fabrice Durand via PacketFence-users 
[mailto:packetfence-users@lists.sourceforge.net]
Verzonden: vrijdag 9 maart 2018 14:35
Aan: packetfence-users@lists.sourceforge.net
CC: Fabrice Durand <fdur...@inverse.ca>
Onderwerp: Re: [PacketFence-users] [Packetfence] AD authentication with 
FreeRadius: "reading winbind reply failed!"


Hello Jimmy,

you are not running the radius packetfence server , it's why it's not working.

Go in /usr/local/pf/ and do ./bin/pfcmd service radiusd start

Regards

Fabrice



Le 2018-03-09 à 02:07, Jimmy Claes via PacketFence-users a écrit :
Hello Fabrice

I ran the command u said, but there was no output at all. I ran raddebug -f 
var/run/radiusd.sock -t 3000 > raddebug.log and this file was completely empty 
after it completed running.

Regards
Jimmy

Van: Fabrice Durand via PacketFence-users 
[mailto:packetfence-users@lists.sourceforge.net]
Verzonden: donderdag 8 maart 2018 14:29
Aan: 
packetfence-users@lists.sourceforge.net<mailto:packetfence-users@lists.sourceforge.net>
CC: Fabrice Durand <fdur...@inverse.ca><mailto:fdur...@inverse.ca>
Onderwerp: Re: [PacketFence-users] [Packetfence] AD authentication with 
FreeRadius: "reading winbind reply failed!"


cd /usr/local/pf

raddebug -f var/run/radiusd.sock -t 3000

Le 2018-03-08 à 02:57, Jimmy Claes via PacketFence-users a écrit :
Hello Fabrice

When I run the command it says that file does not exist, neither does the 
directory '/etc/raddb/':
[imap://fdur...@mail.inverse.ca:143/fetch%3EUID%3E/PacketFence%20Users%20List%3E24241?header=quotebody=1.1.2=image001.png]

Regards
Jimmy

Van: Fabrice Durand via PacketFence-users 
[mailto:packetfence-users@lists.sourceforge.net]
Verzonden: woensdag 7 maart 2018 23:09
Aan: 
packetfence-users@lists.sourceforge.net<mailto:packetfence-users@lists.sourceforge.net>
CC: Fabrice Durand <fdur...@inverse.ca><mailto:fdur...@inverse.ca>
Onderwerp: Re: [PacketFence-users] [Packetfence] AD authentication with 
FreeRadius: "reading winbind reply failed!"


Ok can you send me a complete radius request ? (raddebug -f 
var/run/radiusd.sock -t 3000)

Regards

Fabrice



Le 2018-03-07 à 02:04, Jimmy Claes via PacketFence-users a écrit :
Hello Fabrice

Realms are already created and associated with the AD.
[imap://fdur...@mail.inverse.ca:143/fetch%3EUID%3E/PacketFence%20Users%20List%3E24241?header=quotebody=1.1.3=image002.png]


Regards
Jimmy

Van: Durand fabrice via PacketFence-users 
[mailto:packetfence-users@lists.sourceforge.net]
Verzonden: woensdag 7 maart 2018 3:26
Aan: 
packetfence-users@lists.sourceforge.net<mailto:packetfence-users@lists.sourceforge.net>
CC: Durand fabrice <fdur...@inverse.ca><mailto:fdur...@inverse.ca>
Onderwerp: Re: [PacketFence-users] [Packetfence] AD authentication with 
FreeRadius: "reading winbind reply failed!"


Hello Jimmy,

create the realms associated to your domain, like you have a user like ACME\bob 
and b...@acme.com<mailto:b...@acme.com> then create the 2 realms and associate 
them to your AD.

Regards

Fabrice



Le 2018-03-06 à 07:14, Jimmy Claes via PacketFence-users a écrit :
I've been trying to figure out this problem for days, whenever I try to 
authenticate a user on Windows, I get the following error while the login is 
correct:
[imap://fdur...@mail.inverse.ca:143/fetch%3EUID%3E/PacketFence%20Users%20List%3E24241?header=quotebody=1.1.4=image003.png]

'wbinfo -p' fails aswell:
[imap://fdur...@mail.inverse.ca:143/fetch%3EUID%3E/PacketFence%20Users%20List%3E24241?header=quotebody=1.1.5=image004.png]

Winbind service is running:
[imap://fdur...@mail.inverse.ca:143/fetch%3EUID%3E/PacketFence%20Users%20List%3E24241?header=quotebody=1.1.6=image005.png]

Freeradius service is running:
[imap://fdur...@mail.inverse.ca:143/fetch%3EUID%3E/PacketFence%20Users%20List%3E24241?header=quotebody=1.1.7=image006.png]

The permissions on winbindd_privileged are properly set:
[imap://fdur...@mail.inverse.ca:143/fetch%3EUID%3E/PacketFence%20Users%20List%3E24241?header=quotebody=1.1.8=image007.png]

Result of running 'freeradius -X' attached.








--

Check out the vibrant tech community on one of the world's most

engaging tech sites, Slashdot.org! http://sdm.link/slashdot







___

PacketFence-users mailing list

PacketFence-users@lists.sourceforge.net<mailto:PacketFence-users@lists.sourceforge.net>

https://lists.sourceforge.net/lists/listinfo/packetfence-users







--

Check out the vibrant tech community on one of the world's most

engaging tech sites, Slashdot.org! http://sdm.link/slashdot






___

PacketFence

Re: [PacketFence-users] [Packetfence] AD authentication with FreeRadius: "reading winbind reply failed!"

2018-03-09 Thread Jimmy Claes via PacketFence-users
Hello Fabrice

I ran the command u said, but there was no output at all. I ran raddebug -f 
var/run/radiusd.sock -t 3000 > raddebug.log and this file was completely empty 
after it completed running.

Regards
Jimmy

Van: Fabrice Durand via PacketFence-users 
[mailto:packetfence-users@lists.sourceforge.net]
Verzonden: donderdag 8 maart 2018 14:29
Aan: packetfence-users@lists.sourceforge.net
CC: Fabrice Durand <fdur...@inverse.ca>
Onderwerp: Re: [PacketFence-users] [Packetfence] AD authentication with 
FreeRadius: "reading winbind reply failed!"


cd /usr/local/pf

raddebug -f var/run/radiusd.sock -t 3000

Le 2018-03-08 à 02:57, Jimmy Claes via PacketFence-users a écrit :
Hello Fabrice

When I run the command it says that file does not exist, neither does the 
directory '/etc/raddb/':
[imap://fdur...@mail.inverse.ca:143/fetch%3EUID%3E/PacketFence%20Users%20List%3E24241?header=quotebody=1.1.2=image001.png]

Regards
Jimmy

Van: Fabrice Durand via PacketFence-users 
[mailto:packetfence-users@lists.sourceforge.net]
Verzonden: woensdag 7 maart 2018 23:09
Aan: 
packetfence-users@lists.sourceforge.net<mailto:packetfence-users@lists.sourceforge.net>
CC: Fabrice Durand <fdur...@inverse.ca><mailto:fdur...@inverse.ca>
Onderwerp: Re: [PacketFence-users] [Packetfence] AD authentication with 
FreeRadius: "reading winbind reply failed!"


Ok can you send me a complete radius request ? (raddebug -f 
var/run/radiusd.sock -t 3000)

Regards

Fabrice



Le 2018-03-07 à 02:04, Jimmy Claes via PacketFence-users a écrit :
Hello Fabrice

Realms are already created and associated with the AD.
[imap://fdur...@mail.inverse.ca:143/fetch%3EUID%3E/PacketFence%20Users%20List%3E24241?header=quotebody=1.1.3=image002.png]


Regards
Jimmy

Van: Durand fabrice via PacketFence-users 
[mailto:packetfence-users@lists.sourceforge.net]
Verzonden: woensdag 7 maart 2018 3:26
Aan: 
packetfence-users@lists.sourceforge.net<mailto:packetfence-users@lists.sourceforge.net>
CC: Durand fabrice <fdur...@inverse.ca><mailto:fdur...@inverse.ca>
Onderwerp: Re: [PacketFence-users] [Packetfence] AD authentication with 
FreeRadius: "reading winbind reply failed!"


Hello Jimmy,

create the realms associated to your domain, like you have a user like ACME\bob 
and b...@acme.com<mailto:b...@acme.com> then create the 2 realms and associate 
them to your AD.

Regards

Fabrice



Le 2018-03-06 à 07:14, Jimmy Claes via PacketFence-users a écrit :
I've been trying to figure out this problem for days, whenever I try to 
authenticate a user on Windows, I get the following error while the login is 
correct:
[imap://fdur...@mail.inverse.ca:143/fetch%3EUID%3E/PacketFence%20Users%20List%3E24241?header=quotebody=1.1.4=image003.png]

'wbinfo -p' fails aswell:
[imap://fdur...@mail.inverse.ca:143/fetch%3EUID%3E/PacketFence%20Users%20List%3E24241?header=quotebody=1.1.5=image004.png]

Winbind service is running:
[imap://fdur...@mail.inverse.ca:143/fetch%3EUID%3E/PacketFence%20Users%20List%3E24241?header=quotebody=1.1.6=image005.png]

Freeradius service is running:
[imap://fdur...@mail.inverse.ca:143/fetch%3EUID%3E/PacketFence%20Users%20List%3E24241?header=quotebody=1.1.7=image006.png]

The permissions on winbindd_privileged are properly set:
[imap://fdur...@mail.inverse.ca:143/fetch%3EUID%3E/PacketFence%20Users%20List%3E24241?header=quotebody=1.1.8=image007.png]

Result of running 'freeradius -X' attached.







--

Check out the vibrant tech community on one of the world's most

engaging tech sites, Slashdot.org! http://sdm.link/slashdot






___

PacketFence-users mailing list

PacketFence-users@lists.sourceforge.net<mailto:PacketFence-users@lists.sourceforge.net>

https://lists.sourceforge.net/lists/listinfo/packetfence-users






--

Check out the vibrant tech community on one of the world's most

engaging tech sites, Slashdot.org! http://sdm.link/slashdot





___

PacketFence-users mailing list

PacketFence-users@lists.sourceforge.net<mailto:PacketFence-users@lists.sourceforge.net>

https://lists.sourceforge.net/lists/listinfo/packetfence-users




--

Fabrice Durand

fdur...@inverse.ca<mailto:fdur...@inverse.ca> ::  +1.514.447.4918 (x135) ::  
www.inverse.ca<http://www.inverse.ca>

Inverse inc. :: Leaders behind SOGo (http://www.sogo.nu) and PacketFence 
(http://packetfence.org)




--

Check out the vibrant tech community on one of the world's most

engaging tech sites, Slashdot.org! http://sdm.link/slashdot




___

PacketFence-users mailing list

PacketFence-users@lists.sourceforge.net<mailto:PacketFence-users@

Re: [PacketFence-users] [Packetfence] AD authentication with FreeRadius: "reading winbind reply failed!"

2018-03-08 Thread Jimmy Claes via PacketFence-users
Hello Fabrice

When I run the command it says that file does not exist, neither does the 
directory '/etc/raddb/':
[cid:image001.png@01D3B6BB.0AEBC700]

Regards
Jimmy

Van: Fabrice Durand via PacketFence-users 
[mailto:packetfence-users@lists.sourceforge.net]
Verzonden: woensdag 7 maart 2018 23:09
Aan: packetfence-users@lists.sourceforge.net
CC: Fabrice Durand <fdur...@inverse.ca>
Onderwerp: Re: [PacketFence-users] [Packetfence] AD authentication with 
FreeRadius: "reading winbind reply failed!"


Ok can you send me a complete radius request ? (raddebug -f 
var/run/radiusd.sock -t 3000)

Regards

Fabrice



Le 2018-03-07 à 02:04, Jimmy Claes via PacketFence-users a écrit :
Hello Fabrice

Realms are already created and associated with the AD.
[cid:image002.png@01D3B6BB.0AEBC700]


Regards
Jimmy

Van: Durand fabrice via PacketFence-users 
[mailto:packetfence-users@lists.sourceforge.net]
Verzonden: woensdag 7 maart 2018 3:26
Aan: 
packetfence-users@lists.sourceforge.net<mailto:packetfence-users@lists.sourceforge.net>
CC: Durand fabrice <fdur...@inverse.ca><mailto:fdur...@inverse.ca>
Onderwerp: Re: [PacketFence-users] [Packetfence] AD authentication with 
FreeRadius: "reading winbind reply failed!"


Hello Jimmy,

create the realms associated to your domain, like you have a user like ACME\bob 
and b...@acme.com<mailto:b...@acme.com> then create the 2 realms and associate 
them to your AD.

Regards

Fabrice



Le 2018-03-06 à 07:14, Jimmy Claes via PacketFence-users a écrit :
I've been trying to figure out this problem for days, whenever I try to 
authenticate a user on Windows, I get the following error while the login is 
correct:
[cid:image003.png@01D3B6BB.0AEBC700]

'wbinfo -p' fails aswell:
[cid:image004.png@01D3B6BB.0AEBC700]

Winbind service is running:
[cid:image005.png@01D3B6BB.0AEBC700]

Freeradius service is running:
[cid:image006.png@01D3B6BB.0AEBC700]

The permissions on winbindd_privileged are properly set:
[cid:image007.png@01D3B6BB.0AEBC700]

Result of running 'freeradius -X' attached.






--

Check out the vibrant tech community on one of the world's most

engaging tech sites, Slashdot.org! http://sdm.link/slashdot





___

PacketFence-users mailing list

PacketFence-users@lists.sourceforge.net<mailto:PacketFence-users@lists.sourceforge.net>

https://lists.sourceforge.net/lists/listinfo/packetfence-users





--

Check out the vibrant tech community on one of the world's most

engaging tech sites, Slashdot.org! http://sdm.link/slashdot




___

PacketFence-users mailing list

PacketFence-users@lists.sourceforge.net<mailto:PacketFence-users@lists.sourceforge.net>

https://lists.sourceforge.net/lists/listinfo/packetfence-users



--

Fabrice Durand

fdur...@inverse.ca<mailto:fdur...@inverse.ca> ::  +1.514.447.4918 (x135) ::  
www.inverse.ca<http://www.inverse.ca>

Inverse inc. :: Leaders behind SOGo (http://www.sogo.nu) and PacketFence 
(http://packetfence.org)
--
Check out the vibrant tech community on one of the world's most
engaging tech sites, Slashdot.org! http://sdm.link/slashdot___
PacketFence-users mailing list
PacketFence-users@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/packetfence-users


Re: [PacketFence-users] [Packetfence] AD authentication with FreeRadius: "reading winbind reply failed!"

2018-03-07 Thread Jimmy Claes via PacketFence-users
Hello Eugene

By the following "it all works if I use only the default realm and link it to 
the AD domain." You mean that if u set your sources to the default realm, 
assigning AD to the default realm and have no other realms configured, 
authenticating with AD works?
Would u mind sharing the configuration u have that works with default realm?
Short term, it might just suffice for us.

Regards
Jimmy

Van: E.P. via PacketFence-users [mailto:packetfence-users@lists.sourceforge.net]
Verzonden: woensdag 7 maart 2018 4:33
Aan: packetfence-users@lists.sourceforge.net
CC: E.P. <ype...@gmail.com>
Onderwerp: Re: [PacketFence-users] [Packetfence] AD authentication with 
FreeRadius: "reading winbind reply failed!"

Hi Jimmy and Fabrice,
I would like to report the same experience. I have a realm (OPTIONS-AD-REALM) 
and it is associated with the AD domain (optionsad), i.e.

[OPTIONS-AD-REALM]
domain=optionsad
options=strip

I had similar problems with winbind, same errors in the output of RADIUS debug. 
Moreover, my attempt to test authentication from the command line was 
successful:

[root@PacketFence-ZEN bin]# ./pftest authentication it.tech X

Authenticating against OPTIONS-AD-SOURCE
  Authentication SUCCEEDED against OPTIONS-AD-SOURCE (Authentication 
successful.)
  Matched against OPTIONS-AD-SOURCE for 'authentication' rules
set_role : Staff
set_unreg_date : 2019-12-31

Go figure what's wrong, permissions, bugs or a lack of understanding from my 
side as what I see as the result of ntlm_auth query drives me mad:

[root@PacketFence-ZEN bin]# ntlm_auth --request-nt-key --domain=optionsad 
--username=it.tech
Password:
could not obtain winbind separator!
Reading winbind reply failed! (0x01)
:  (0x0)

So, here I would like Fabrice comment on this, specifically bearing in mind 
that it all works if I use only the default realm and link it to the AD domain.
What's the point of having named realms ?
Moreover, if I test my authentication source with the authentication realm 
pointing to default the test fails. If I remove it then the test goes through ?
What's the point of having the realm here, Fabrice ?
Moreover, if I use FQDN for the host that acts as the windows domain controller 
my test also fails but if I use the IP address it is all good.
I know and I swear that PF can resolve the name normally.
There are more questions that I'd like to ask strongly believing there's faulty 
code or missing documentation or a combination of both.

Eugene

From: Durand fabrice via PacketFence-users 
[mailto:packetfence-users@lists.sourceforge.net]

Sent: Tuesday, March 06, 2018 6:26 PM
To: 
packetfence-users@lists.sourceforge.net<mailto:packetfence-users@lists.sourceforge.net>
Cc: Durand fabrice <fdur...@inverse.ca<mailto:fdur...@inverse.ca>>
Subject: Re: [PacketFence-users] [Packetfence] AD authentication with 
FreeRadius: "reading winbind reply failed!"


Hello Jimmy,

create the realms associated to your domain, like you have a user like ACME\bob 
and b...@acme.com<mailto:b...@acme.com> then create the 2 realms and associate 
them to your AD.

Regards

Fabrice



Le 2018-03-06 à 07:14, Jimmy Claes via PacketFence-users a écrit :
I've been trying to figure out this problem for days, whenever I try to 
authenticate a user on Windows, I get the following error while the login is 
correct:
[cid:image001.png@01D3B580.3713C440]

'wbinfo -p' fails aswell:
[cid:image002.png@01D3B580.3713C440]

Winbind service is running:
[cid:image003.png@01D3B580.3713C440]

Freeradius service is running:
[cid:image004.png@01D3B580.3713C440]

The permissions on winbindd_privileged are properly set:
[cid:image005.png@01D3B580.3713C440]

Result of running 'freeradius -X' attached.




--

Check out the vibrant tech community on one of the world's most

engaging tech sites, Slashdot.org! http://sdm.link/slashdot



___

PacketFence-users mailing list

PacketFence-users@lists.sourceforge.net<mailto:PacketFence-users@lists.sourceforge.net>

https://lists.sourceforge.net/lists/listinfo/packetfence-users

--
Check out the vibrant tech community on one of the world's most
engaging tech sites, Slashdot.org! http://sdm.link/slashdot___
PacketFence-users mailing list
PacketFence-users@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/packetfence-users


Re: [PacketFence-users] [Packetfence] AD authentication with FreeRadius: "reading winbind reply failed!"

2018-03-07 Thread Jimmy Claes via PacketFence-users
Hello Fabrice

Realms are already created and associated with the AD.
[cid:image001.png@01D3B5EA.EF409C40]


Regards
Jimmy

Van: Durand fabrice via PacketFence-users 
[mailto:packetfence-users@lists.sourceforge.net]
Verzonden: woensdag 7 maart 2018 3:26
Aan: packetfence-users@lists.sourceforge.net
CC: Durand fabrice <fdur...@inverse.ca>
Onderwerp: Re: [PacketFence-users] [Packetfence] AD authentication with 
FreeRadius: "reading winbind reply failed!"


Hello Jimmy,

create the realms associated to your domain, like you have a user like ACME\bob 
and b...@acme.com<mailto:b...@acme.com> then create the 2 realms and associate 
them to your AD.

Regards

Fabrice



Le 2018-03-06 à 07:14, Jimmy Claes via PacketFence-users a écrit :
I've been trying to figure out this problem for days, whenever I try to 
authenticate a user on Windows, I get the following error while the login is 
correct:
[cid:image002.png@01D3B5EA.EF409C40]

'wbinfo -p' fails aswell:
[cid:image003.png@01D3B5EA.EF409C40]

Winbind service is running:
[cid:image004.png@01D3B5EA.EF409C40]

Freeradius service is running:
[cid:image005.png@01D3B5EA.EF409C40]

The permissions on winbindd_privileged are properly set:
[cid:image006.png@01D3B5EA.EF409C40]

Result of running 'freeradius -X' attached.





--

Check out the vibrant tech community on one of the world's most

engaging tech sites, Slashdot.org! http://sdm.link/slashdot




___

PacketFence-users mailing list

PacketFence-users@lists.sourceforge.net<mailto:PacketFence-users@lists.sourceforge.net>

https://lists.sourceforge.net/lists/listinfo/packetfence-users

--
Check out the vibrant tech community on one of the world's most
engaging tech sites, Slashdot.org! http://sdm.link/slashdot___
PacketFence-users mailing list
PacketFence-users@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/packetfence-users


[PacketFence-users] [Packetfence] AD authentication with FreeRadius: "reading winbind reply failed!"

2018-03-06 Thread Jimmy Claes via PacketFence-users
I've been trying to figure out this problem for days, whenever I try to 
authenticate a user on Windows, I get the following error while the login is 
correct:
[cid:image001.png@01D3B54D.1667FFA0]

'wbinfo -p' fails aswell:
[cid:image002.png@01D3B54D.1667FFA0]

Winbind service is running:
[cid:image003.png@01D3B54D.1667FFA0]

Freeradius service is running:
[cid:image004.png@01D3B54D.1667FFA0]

The permissions on winbindd_privileged are properly set:
[cid:image005.png@01D3B54D.1667FFA0]

Result of running 'freeradius -X' attached.



freeradius_debug.log
Description: freeradius_debug.log
--
Check out the vibrant tech community on one of the world's most
engaging tech sites, Slashdot.org! http://sdm.link/slashdot___
PacketFence-users mailing list
PacketFence-users@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/packetfence-users