Re: [Lam-public] Local Copy of AD Forests

2024-03-21 Thread Roland Gruber
Team m...@ztisolutions.com<mailto:m...@ztisolutions.com> (301)509-7592 (cell) [cid:9f752961-1d5e-4e9c-a743-10c61a2ba214] From: Roland Gruber Sent: Thursday, March 21, 2024 2:38 AM To: Mark Sigsbee ; lam-public@lists.sourceforge.net Subject: Re: [Lam-

Re: [Lam-public] Local Copy of AD Forests

2024-03-21 Thread Roland Gruber
m<mailto:m...@ztisolutions.com> (301)509-7592 (cell) [cid:11ffa6ef-57a0-4260-8b6d-8bc96f25c5e0] ________ From: Roland Gruber Sent: Wednesday, March 20, 2024 2:36 PM To: lam-public@lists.sourceforge.net Subject: Re: [Lam-public] Local Copy of AD Forests Hi Mark, LAM is a GU

Re: [Lam-public] Local Copy of AD Forests

2024-03-20 Thread Roland Gruber
Hi Mark, LAM is a GUI to manage LDAP entries. The place where these are stored is totally up to the LDAP server. If you need to sync data between LDAP servers then you will also need an additional tool. Best regards Roland Am 20.03.24 um 13:31 schrieb Mark Sigsbee: Design: 1. Ubuntu

Re: [Lam-public] Blank Screen when accessing LAM

2024-03-19 Thread Roland Gruber
Hi Mark, do you get any messages in Apache's error log file? What is your PHP version? At least 8.0.2 is required. Best regards Roland Am 19.03.24 um 16:40 schrieb Mark Sigsbee: Followed installation from your directions. On host server: 1. I get the Apache landing page with no issues.

[Lam-public] LDAP Account Manager 8.7 with PHP 8.3 compatibility and passwordless SSO login for self service

2024-03-16 Thread Roland Gruber
ight: Copyright (C) 2003 - 2024: Roland Gruber LAM is published under the GNU General Public License. The complete list of licenses can be found in the copyright file. ___ Lam-public mailing list Lam-public@lists.sourceforge.net https://lists.sourceforge

Re: [Lam-public] unable to install LAM Pro to Ubuntu 22.04

2024-03-15 Thread Roland Gruber
Hi Randy, can you try to download and install php-psr-log 1.1.4 from here? https://packages.debian.org/bookworm/all/php-psr-log/download Debian and Ubuntu ship different major versions of it but an external dependency just supports the 1.x one. This will be resolved with LAM 8.8 in June (we

Re: [Lam-public] self service password

2024-03-08 Thread Roland Gruber
Hi Nicolas, please note that this mailinglist is in English. ;-) If the automated translation is right then you want to sync your Samba password. For this go to tab Page layout and add the field Samba 3: Sync Samba NT password with Unix password. This will change the Samba 3 password on a

[Lam-public] LDAP Account Manager 8.7.RC1 with PHP 8.3 compatibility and passwordless SSO login for self service

2024-02-29 Thread Roland Gruber
Authors & Copyright: Copyright (C) 2003 - 2024: Roland Gruber LAM is published under the GNU General Public License. The complete list of licenses can be found in the copyright file. ___ Lam-public mailing list Lam-public@lists.sourceforge.net h

Re: [Lam-public] User name duplication

2024-02-23 Thread Roland Gruber
Hi Ger, can you provide the list of active user modules that you have selected in your server profile? Best regards Roland Am 21.02.24 um 19:54 schrieb Roland Gruber: Hi Ger, there should be a message but it is only displayed if you press any button (except "Save") on the e

Re: [Lam-public] User name duplication

2024-02-21 Thread Roland Gruber
Hi Ger, there should be a message but it is only displayed if you press any button (except "Save") on the edit screen. I will check if this can be solved in a different way. Best regards Roland Am 21.02.24 um 13:20 schrieb Gerard Hooton: Hi, When adding a new user, I note that if there

Re: [Lam-public] 8.5->8.6 upgrade

2024-01-07 Thread Roland Gruber
Hi Giuseppe, you can use the packages from Debian Stable: http://ftp.de.debian.org/debian/pool/main/p/php-voku-portable-ascii/php-voku-portable-ascii_2.0.1-1_all.deb http://ftp.de.debian.org/debian/pool/main/p/php-psr-log/php-psr-log_1.1.4-2_all.deb This should do the trick. Best regards

[Lam-public] LDAP Account Manager 8.6 with new "Request access" module for self service and Docker update

2023-12-18 Thread Roland Gruber
2023: Roland Gruber LAM is published under the GNU General Public License. The complete list of licenses can be found in the copyright file. ___ Lam-public mailing list Lam-public@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/lam-public

[Lam-public] LDAP Account Manager 8.6.RC1 with new "Request access" module for self service and Docker update

2023-12-05 Thread Roland Gruber
/lamcms/liveDemo Authors & Copyright: Copyright (C) 2003 - 2023: Roland Gruber LAM is published under the GNU General Public License. The complete list of licenses can be found in the copyright file. ___ Lam-public mailing list Lam-pu

Re: [Lam-public] Is there a way to automate account creation via file upload?

2023-11-19 Thread Roland Gruber
Hi Larry, you can create users via file upload: https://www.ldap-account-manager.org/static/doc/manual/ch05s03.html However, this requires the manual selection of the file. If you need something fully automated then LAM's file upload does not support this out-of-the-box. Best regards

[Lam-public] LDAP Account Manager 8.5 with accessibility improvements and better multi edit tool

2023-09-29 Thread Roland Gruber
for organizational units * schema browser * tree view * 2FA support Demo installation: You can try our demo installation online. https://www.ldap-account-manager.org/lamcms/liveDemo Authors & Copyright: Copyright (C) 2003 - 2023: Roland Gruber LAM is published under the GNU General Pu

[Lam-public] LDAP Account Manager 8.5.RC1 with accessibility improvements and better multi edit tool

2023-09-08 Thread Roland Gruber
2003 - 2023: Roland Gruber LAM is published under the GNU General Public License. The complete list of licenses can be found in the copyright file. ___ Lam-public mailing list Lam-public@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo

Re: [Lam-public] Schema test - The object class customtypes is not supported by your LDAP server.

2023-08-24 Thread Roland Gruber
- From: Roland Gruber Sent: Thursday, August 24, 2023 14:08 To: lam-public@lists.sourceforge.net Subject: Re: [Lam-public] Schema test - The object class customtypes is not supported by your LDAP server. Hi Byungkook, are you sure that you have an object class "customtypes" registered in

Re: [Lam-public] Schema test - The object class customtypes is not supported by your LDAP server.

2023-08-24 Thread Roland Gruber
Hi Byungkook, are you sure that you have an object class "customtypes" registered in your LDAP server schema? Please recheck the module settings in server profile. If you only want to manage attributes without an object class then leave the field blank. Best regards Roland Am 22.08.23 um

Re: [Lam-public] No user in LAM -> Accounts -> Users

2023-08-24 Thread Roland Gruber
Hi Byungkook, I guess this is because LAM runs out of memory. Please check your php.ini for the setting "memory_limit" and set it to 512M or even 1024M. Then restart Apache. Best regards Roland Am 24.08.23 um 15:19 schrieb Byungkook Kim: Hello, LAM PRO 8.4 @(#) $OpenLDAP: slapd

Re: [Lam-public] Not seeing configured questions on self service registration page

2023-08-01 Thread Roland Gruber
Please see https://github.com/LDAPAccountManager/lam/issues/243 Am 01.08.23 um 18:38 schrieb Tealey, Fred:   i am not seeing the self service configured question on the self service registration page. I can see them in the admin page and configure them for a user and also see them by

Re: [Lam-public] 8.3 to 8.4 update issue [Fixed]

2023-07-27 Thread Roland Gruber
Hi Gerard, exactly, always uninstall the old package first. Otherwise, the system tries to install two versions in parallel. Best regards Roland Am 27. Juli 2023 12:40:56 MESZ schrieb Gerard Hooton : >I just used rpm to uninstall 8.3 and install 8.4 >That fixed my issue. > > > >“The network

Re: [Lam-public] blank home directory

2023-07-19 Thread Roland Gruber
Hi Sepp, I was not able to reproduce this issue. Did you add the template value in the profile called "default"? If yes, please provide a screenshot of your active user modules in the server profile. Best regards Roland Am 19.07.23 um 01:28 schrieb Sepp Schembera: It is happening every

Re: [Lam-public] FW: HOME DIRECTORY IS BLANK

2023-07-18 Thread Roland Gruber
pp-schembera/ <https://www.linkedin.com/in/josef-sepp-schembera/> *From:*Roland Gruber *Sent:* Monday, July 17, 2023 3:35 AM *To:* lam-public@lists.sourceforge.net; Sepp Schembera *Subject:* Re: [Lam-public] HOME DIRECTORY IS BLANK Hi Sepp, do you want to configure a predefined val

Re: [Lam-public] Fwd: [ProvideSupport.com #388654] LDAP INTEGRATION INTO VIROLA (licensed)

2023-07-18 Thread Roland Gruber
Hi Sepp, unfortunately, this type of template is not possible to specify. Best regards Roland Am 18.07.23 um 16:31 schrieb Sepp Schembera: Is it possible to generate a username template for " username@mercury.local" So that @mercury.local is added to it automatically? So you enter xyz and

Re: [Lam-public] HOME DIRECTORY IS BLANK

2023-07-16 Thread Roland Gruber
Hi Sepp, do you want to configure a predefined value for the home directory setting? This can be done in profile editor: https://www.ldap-account-manager.org/static/doc/manual/ch05.html#a_accountProfile Best regards Roland Am 16. Juli 2023 03:11:49 MESZ schrieb Sepp Schembera : >When I

Re: [Lam-public] adding MariaDB

2023-07-16 Thread Roland Gruber
Hi Sepp, there is no specific way. MariaDB should use an UTF encoding. Apart from this no special settings are required. Best regards Roland Am 15. Juli 2023 04:59:39 MESZ schrieb Sepp Schembera : >Which is the best recommended way to add MariaDB to OpenLDAP & LAM PRO? > >Thanks > >Sepp > >

Re: [Lam-public] Network Device Authentication in LAM

2023-07-12 Thread Roland Gruber
Hi Carlos, do you need any specific object class or attributes? Maybe these modules help you? https://www.ldap-account-manager.org/static/doc/manual/ch04s04.html#idm3190 https://www.ldap-account-manager.org/static/doc/manual/ch04s04.html#idm3205 Best regards Roland Am 12.07.23 um 13:33

Re: [Lam-public] Custom Field Type LDAP Date not mapping correctly to Windows Active Directory Generalized Time field

2023-06-25 Thread Roland Gruber
ralized time? Thanks and regards, Colin -Ursprüngliche Nachricht- Von: Roland Gruber Gesendet: Samstag, 24. Juni 2023 20:20 An: lam-public@lists.sourceforge.net Betreff: Re: [Lam-public] Custom Field Type LDAP Date not mapping correctly to Windows Active Directory Generalized Time fiel

Re: [Lam-public] Custom Field Type LDAP Date not mapping correctly to Windows Active Directory Generalized Time field

2023-06-24 Thread Roland Gruber
Hi Colin, I think this is because AD uses a different date format. LAM expects "1994041300Z" while you need "1994041300.0Z". The solution would be to use a text field with date type validation. But looks like the "Z" is causing issues. Will dig deeper and provide feedback the next few

Re: [Lam-public] LAM - Warning cannot change directory to home/xx/user no such file or directory

2023-06-11 Thread Roland Gruber
Hi Alper, you mean you get this error when you login via terminal and run "su" to root then? LAM does not run any commands during "su". Maybe you added lamdaemon by mistake to .bashrc or something similar? Best regards Roland Am 10.06.23 um 20:18 schrieb Alper Aykut: I can create a Ldap

Re: [Lam-public] LDAP/FreeRadius configuration and integration throught LAM Module

2023-06-06 Thread Roland Gruber
Hi Carlos, I can help you with the LAM part. First, activate the FreeRadius user module as described here: https://www.ldap-account-manager.org/static/doc/manual/ch04s02.html#idm2605 When you now edit a user and add the FreeRadius extension then take a look at the question marks next to the

[Lam-public] LDAP Account Manager 8.4 with Docker on Mac and Duo universal prompt support

2023-06-06 Thread Roland Gruber
for organizational units * schema browser * tree view * 2FA support Demo installation: You can try our demo installation online. https://www.ldap-account-manager.org/lamcms/liveDemo Authors & Copyright: Copyright (C) 2003 - 2023: Roland Gruber LAM is published under the GNU General Public Lic

Re: [Lam-public] Bulk change homeDirectory for multiple users

2023-06-01 Thread Roland Gruber
Hi Larry, you can try the file upload with overwrite option. Reduce the columns in the CSV to a minimum and check the LDIF that can be downloaded before performing the upload. Also, deselect any non-required modules on the first page of the upload. Best regards Roland Am 01.06.23 um

Re: [Lam-public] Managing account locking and password expiration in plain LDAP schema...

2023-05-21 Thread Roland Gruber
Hi Marco, Am 21.05.23 um 23:33 schrieb Marco Gaiarin: Shadow is only checked by the Unix system. If you want something to be enforced globally then go for PPolicy (needs to be activated on server): https://www.ldap-account-manager.org/static/doc/manual/ch04s02.html#mod_passwordPolicy If i've

Re: [Lam-public] Managing account locking and password expiration in plain LDAP schema...

2023-05-18 Thread Roland Gruber
Hi Marco, "passwd -l" should work when you configure "rootbinddn" in /etc/libnss-ldap.conf (you will also need to set the password in /etc/libnss-ldap.secret). There is no LDAP query for locked users possible as the attribute is not configured for substring matching. This is a technical

[Lam-public] LDAP Account Manager 8.4.RC1 with Docker on Mac and Duo universal prompt support

2023-05-13 Thread Roland Gruber
2023: Roland Gruber LAM is published under the GNU General Public License. The complete list of licenses can be found in the copyright file. ___ Lam-public mailing list Lam-public@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/lam-public

Re: [Lam-public] preconfigure "password never expires"

2023-04-27 Thread Roland Gruber
Hi Christian, there is no such option yet for new users. But as this is a very tiny change we will add it in the next release. Maybe it helps you to use the copy-option in the account list. If you create a user this way then the option will be copied, too. Best regards Roland Am

Re: [Lam-public] Error copy in tree view

2023-04-11 Thread Roland Gruber
Hi Robert, I was not able to reproduce a failing move operation on Windows server 2019 (for a computer account). Please check if the entry has any subnodes. In this case the move will be converted to a copy+delete (subtrees cannot be moved) which will fail because of naming conflicts. Copy

[Lam-public] LDAP Account Manager 8.3 with usability improvements and ability to remember 2FA device

2023-03-24 Thread Roland Gruber
installation: You can try our demo installation online. https://www.ldap-account-manager.org/lamcms/liveDemo Authors & Copyright: Copyright (C) 2003 - 2023: Roland Gruber LAM is published under the GNU General Public License. The complete list of licenses can be found in the copyright

[Lam-public] LDAP Account Manager 8.3.RC1 with usability improvements and ability to remember 2FA device

2023-03-09 Thread Roland Gruber
2003 - 2023: Roland Gruber LAM is published under the GNU General Public License. The complete list of licenses can be found in the copyright file. ___ Lam-public mailing list Lam-public@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo

Re: [Lam-public] LAM Pro Access levels

2023-02-14 Thread Roland Gruber
Hi Honza, first of all, please upgrade your LAM installation. In 8.0 a severe security issue was fixed. If the instance is accessible from the internet, reinstall the server to be on the safe side. The permissions should be setup on server-side to enforce them for all administration tools.

Re: [Lam-public] self service portal

2023-01-18 Thread Roland Gruber
Hi Andy, please try "(!(gidNumber=12345))". Best regards Roland Am 19.01.23 um 00:56 schrieb Wu, Andy via Lam-public: In the additional LDAP filter for selfservice how do I deny users with a gid of a certain number ? Andy Wu Principal Systems Engineer Smart Grid Technical Operations

[Lam-public] LDAP Account Manager 8.2 with usability improvements

2022-12-13 Thread Roland Gruber
accounts * editor for organizational units * schema browser * tree view * 2FA support Demo installation: You can try our demo installation online. https://www.ldap-account-manager.org/lamcms/liveDemo Authors & Copyright: Copyright (C) 2003 - 2022: Roland Gruber LAM is published under the

[Lam-public] LDAP Account Manager 8.2.RC1 with usability improvements

2022-11-27 Thread Roland Gruber
ight: Copyright (C) 2003 - 2022: Roland Gruber LAM is published under the GNU General Public License. The complete list of licenses can be found in the copyright file. ___ Lam-public mailing list Lam-public@lists.sourceforge.net https://lists.sourceforge.net/l

Re: [Lam-public] Configuring LAM with Samba4

2022-11-24 Thread Roland Gruber
Hi Leopold, Am 24.11.22 um 20:19 schrieb Leopold Palomo-Avellaneda: I'm sorry, but it is not working. The uid field is empty but when we create a user it has a uid and gid number (showed after the creation). However, if we create another user, it has the _same_ uid and gid. the uidNumber is

Re: [Lam-public] Configuring LAM with Samba4

2022-11-23 Thread Roland Gruber
Hi Leopold, to assign users uid/uidNumber/gidNumber you will need to use the "Unix (posixAccount)" module. Make sure to use the "Windows" modules for the Samba part (and not Samba 3). In server profile, Windows, you put the Samba domain name (e.g. example.com). This should match your LDAP

Re: [Lam-public] 2FA

2022-11-15 Thread Roland Gruber
Hi Jürgen, thanks for the confirmation. I put it on the planning for 8.3 (March). Best regards Roland Am 14.11.22 um 23:25 schrieb Jürgen Holm: Hi Roland Hi Jürgen, just for clarification: what do you mean with secure device? Is it to allow to disable 2FA for future logins when the user

Re: [Lam-public] 2FA

2022-11-14 Thread Roland Gruber
Hi Jürgen, just for clarification: what do you mean with secure device? Is it to allow to disable 2FA for future logins when the user connects from the same device? E.g. user logs in with mobile and activates a checkbox. Next login from mobile would not trigger 2FA but login from desktop

Re: [Lam-public] Problem: No Samba password is set via SelfService.

2022-10-14 Thread Roland Gruber
Hi Peter, did you add the field "Samba 3: Sync Samba LM password with Unix password" on tab "Page layout"? This is a hidden field that should match your use-case. Best regards Roland Am 14.10.22 um 15:32 schrieb Resch, Peter: Hello together, we have successfully installed the LDAP

Re: [Lam-public] LAM ldap search email as username

2022-10-04 Thread Roland Gruber
Hi Ben, did you try this? LDAP filter: mail=%USER% With group membership: LDAP filter: (&(mail=%USER%)(memberOf=mygroup,dc=example,dc=com)) Best regards Roland Am 04.10.22 um 19:14 schrieb Ben Toms: Hi folks, Is there a way to set a server profile to require ldap search to

Re: [Lam-public] LAM web template

2022-09-22 Thread Roland Gruber
Hi Lucas, to write custom modules there is a HowTo: https://www.ldap-account-manager.org/lamcms/develdocs LAM Pro also supports custom object classes and attributes: https://www.ldap-account-manager.org/static/doc/manual/ch04s26.html For DHCP did you check the manual entry? There are some

[Lam-public] LDAP Account Manager 8.1 with support for simpleSecurityObject and Apache Guacamole

2022-09-22 Thread Roland Gruber
for organizational units * schema browser * tree view * 2FA support Demo installation: You can try our demo installation online. https://www.ldap-account-manager.org/lamcms/liveDemo Authors & Copyright: Copyright (C) 2003 - 2022: Roland Gruber LAM is published under the GNU General Public Lic

[Lam-public] LDAP Account Manager 8.1.RC1 with support for simpleSecurityObject and Apache Guacamole

2022-09-05 Thread Roland Gruber
* setting quotas * PDF output for all accounts * editor for organizational units * schema browser * tree view * 2FA support Demo installation: You can try our demo installation online. https://www.ldap-account-manager.org/lamcms/liveDemo Authors & Copyright: Copyright (C) 2003 - 2022: Ro

Re: [Lam-public] ERROR: Security token does not match POST data.

2022-08-23 Thread Roland Gruber
:20 schrieb Ben Toms: There is no "Group of Names" module available to be chosen, the LDAP backend is OpenLDAP On Tue, 23 Aug 2022 at 15:39, Roland Gruber wrote: Hi Ben, please check what object classes your groups have and select the corresponding account modules. E.g. there are modules for Win

Re: [Lam-public] ERROR: Security token does not match POST data.

2022-08-23 Thread Roland Gruber
ormation)" and "Unix (posixGroup)" and now there is an everyone group, but none of the other groups are showing (though they exist in LDAP). On Tue, 23 Aug 2022 at 07:22, Roland Gruber wrote: Hi Ben, are you on PHP 8.1? If yes please try to downgrade to PHP 7.4. Please also pro

Re: [Lam-public] ERROR: Security token does not match POST data.

2022-08-23 Thread Roland Gruber
Hi Ben, are you on PHP 8.1? If yes please try to downgrade to PHP 7.4. Please also provide the list of active account modules for groups in your server profile. Best regards Roland Am 22.08.22 um 14:41 schrieb Ben Toms: Hi folks, We recently updated from 6. 9 to 8.0.1, now when we

Re: [Lam-public] WARNING: Unable to set locale, check if 'locale -a' returns en_GB.utf8

2022-08-23 Thread Roland Gruber
Hi Ben, please run this command on the webserver: locale -a It prints a list of supported locales on your system. If en_GB.utf8 is not in the list then you need to install it. On Debian/Ubuntu this can be done running "dpkg-reconfigure locales". Best regards Roland Am 22.08.22 um 15:02

Re: [Lam-public] Enabling LDAPS

2022-08-20 Thread Roland Gruber
at 08:26, Roland Gruber wrote: Hi Ben, there is no additional step needed. You should get an error message if encryption cannot be activated. Are you on the latest version of LAM? How do you see that LDAPS is not used? Best regards Roland Am 19.08.22 um 17:32 schrieb Ben Toms: Thanks

Re: [Lam-public] Enabling LDAPS

2022-08-20 Thread Roland Gruber
is that when I make the changes, LDAPS isn't being enabled. Is there some additional steps? On Fri, 19 Aug 2022 at 15:51, Roland Gruber wrote: Hi Ben, there is no visible change if you use LDAPS. Best regards Roland Am 19.08.22 um 09:18 schrieb Ben Toms: Thanks, Roland. I can see the wildcard cert

Re: [Lam-public] Enabling LDAPS

2022-08-19 Thread Roland Gruber
to change? On Fri, 19 Aug 2022 at 06:57, Roland Gruber wrote: Hi Ben, to activate encryption please enable TLS (most common) or LDAPS in general settings of the server profile: https://www.ldap-account-manager.org/static/doc/manual/ch03s02.html#idm858 For TLS use the drop-down, for LDAP

Re: [Lam-public] Enabling LDAPS

2022-08-18 Thread Roland Gruber
Hi Ben, to activate encryption please enable TLS (most common) or LDAPS in general settings of the server profile: https://www.ldap-account-manager.org/static/doc/manual/ch03s02.html#idm858 For TLS use the drop-down, for LDAPS use a URL starting with ldaps:// (e.g.

Re: [Lam-public] 8.0.1 installation issue on Ubuntu 22.04 LTS

2022-08-18 Thread Roland Gruber
Hi Ben, looks like the PHP module for Apache is not installed/activated. You get the PHP code as text instead of the executed result. Best regards Roland Am 18.08.22 um 20:52 schrieb Ben Toms: Hi folks, We're facing an issue updating to 8.0.1 on Ubuntu. We're on 6.9, but our instance is

Re: [Lam-public] Self Service Password Self-Rest Input Fields Missing

2022-08-17 Thread Roland Gruber
Hi Eugene, please upgrade to 8.0.1. Your version is very outdated and affected by severe security issues: https://github.com/LDAPAccountManager/lam/security/advisories https://www.ldap-account-manager.org/lamcms/node/455 For 8.0.1 there are no such self service issues known. Best regards

Re: [Lam-public] Changing password via SelfService does not update shadowLastChange

2022-08-09 Thread Roland Gruber
Hi Attila, thanks for the update. This is now fixed in the development version. There was a small typo: https://github.com/LDAPAccountManager/lam/commit/52b85ae6e8c006850e68dfe27bc2b8d44c4dd99b You can apply it manually to: /usr/share/ldap-account-manager/lib/modules/posixAccount.inc The fix

Re: [Lam-public] Changing password via SelfService does not update shadowLastChange

2022-08-08 Thread Roland Gruber
Hi Attila, please check if your user can read the attribute "shadowLastChange". LAM will only update the value if it is visible/existing. You can also use an admin bind user for the self service and tick "Use for all operations" in self service profile, first tab. Best regards Roland Am

Re: [Lam-public] Naming of WebAuthn devices

2022-07-03 Thread Roland Gruber
Hi Jürgen, Am 03.07.22 um 12:07 schrieb Juergen Holm: So, I added the column "name" via sqlite3 __lam.webauthn.sqlite as you wrote. Problem fixed! Did you remove the column "name" in your test environment and try to add it again via the LAM webinterface? yes, adding the column via LAM

Re: [Lam-public] Naming of WebAuthn devices

2022-07-03 Thread Roland Gruber
qhp - 134.76.xx.xxx - uid=xxx,ou=People,dc=theorie,dc=physik,dc=uni-goettingen,dc=de) - ERROR: Unable to add name column to table: SQLSTATE[HY000]: General error: 1 near "(": syntax error On Fri, 2022-07-01 at 19:49 +0200, Roland Gruber wrote: Hi Jürgen, I was not able to reproduce.

[Lam-public] LDAP Account Manager 8.0.1 bugfix release

2022-06-29 Thread Roland Gruber
PDF output for all accounts * editor for organizational units * schema browser * tree view * 2FA support Demo installation: You can try our demo installation online. https://www.ldap-account-manager.org/lamcms/liveDemo Authors & Copyright: Copyright (C) 2003 - 2022: Roland Gruber LAM is p

Re: [Lam-public] Server Profile "Passwoerter aendern" Not working

2022-06-28 Thread Roland Gruber
Hi Martin, thank you very much for your report. There is a small issue in 8.0 that prevents to display the icon. This will be fixed as part of a maintenance release the next few days. Best regards Roland Am 28.06.22 um 17:41 schrieb 0993, Putschögl, Martin: Hi, I've updated from LAM

[Lam-public] LDAP Account Manager 8.0 with important security fixes, PHP 8.1 compatibility and new captcha providers

2022-06-27 Thread Roland Gruber
-account-manager.org/lamcms/liveDemo Authors & Copyright: Copyright (C) 2003 - 2022: Roland Gruber LAM is published under the GNU General Public License. The complete list of licenses can be found in the copyright file. ___ Lam-public mailing list

Re: [Lam-public] lamdaemon settings and lamdaemon test

2022-06-21 Thread Roland Gruber
Hi Fred, please check that you do not have the "Defaults" settings mentioned here: https://www.ldap-account-manager.org/static/doc/manual/apds03.html Also check that the NOPASSWD option is set. Best regards Roland Am 21.06.22 um 09:39 schrieb Fred Obermann: I have my OpenLDAP server

Re: [Lam-public] Help with LAM

2022-06-13 Thread Roland Gruber
Hi Darren, please check the Apache log files for any issues. Maybe Apache cannot create the session file. Also, cookies might be blocked. You should see a message in browser console then. Does our official LAM docker image work in your environment? Best regards Roland Am 13. Juni 2022

Re: [Lam-public] user add to groups

2022-06-08 Thread Roland Gruber
Hi Andy, for "member" please use group of names module: https://www.ldap-account-manager.org/static/doc/manual/ch04s06.html Best regards Roland Am 08.06.22 um 21:59 schrieb Wu, Andy via Lam-public: Roland, So I notice when I add a user to a group in LAM Pro he is added as attribute

Re: [Lam-public] self service portal ssh key upload errors

2022-06-07 Thread Roland Gruber
Hi Andy, looks like you use a proxy in front of LAM. Please check that /templates/misc is part of your proxy rules. See here for an example: https://www.ldap-account-manager.org/static/doc/manual/apbs07.html#idm6639 Best regards Roland Am 07.06.22 um 20:41 schrieb Wu, Andy via

Re: [Lam-public] Do I understand how to set-up and use lamdaemon correctly?

2022-06-01 Thread Roland Gruber
Hi Fred, yes, you need to setup sudo for lamdaemon. See here (incl. next pages) for a list of steps: https://www.ldap-account-manager.org/static/doc/manual/apd.html Best regards Roland Am 1. Juni 2022 08:04:28 MESZ schrieb Fred Obermann : >My understanding is that if home directories are

Re: [Lam-public] Permissions LDAP-Tree

2022-04-09 Thread Roland Gruber
Hi Tobias, this will require a LDAP move-operation to work. Currently, LAM does a copy+delete. The change is planned for 8.0 in June. Best regards Roland Am 08.04.22 um 07:57 schrieb Roland Gruber: Hi Tobias, was able to reproduce it. Will need to dig deeper what happens here. Best

Re: [Lam-public] Permissions LDAP-Tree

2022-04-07 Thread Roland Gruber
Hi Tobias, can you post a screenshot of the error message? Maybe the entry has subentries? Not all LDAP servers allow move operations for entries with children. Best regards Roland Am 05.04.22 um 12:10 schrieb Tobias Kirchhofer via Lam-public: Hi, sometimes we use the LDAP tree to move

Re: [Lam-public] Cannot connect to openldap after upgrade LAM Pro from 7.8 to 7.9

2022-03-30 Thread Roland Gruber
Hi Yu, this could be related to the LDAP server certificate. I guess the connection to OpenLDAP is secured via "ldaps://" or TLS? LAM 7.9 uses a new version of the Debian operating system. This has higher requirements for certificates. E.g. SHA1 signatures are no longer supported. Try to

Re: [Lam-public] LAM Pro Migration/Upgrade Question

2022-03-10 Thread Roland Gruber
Hi Barry, please check if you are affected by one of the version specific topics: https://www.ldap-account-manager.org/static/doc/manual/ch02s02.html#a_versUpgrade Usually, the direct upgrade of the package should be fine. Check your configuration in LAM afterwards. E.g. tree view suffix is

[Lam-public] LDAP Account Manager 7.9 with multiple roots in tree view and custom script improvements

2022-03-09 Thread Roland Gruber
ight: Copyright (C) 2003 - 2022: Roland Gruber LAM is published under the GNU General Public License. The complete list of licenses can be found in the copyright file. ___ Lam-public mailing list Lam-public@lists.sourceforge.net h

[Lam-public] LDAP Account Manager 7.9.RC1 with multiple roots in tree view and custom script improvements

2022-02-25 Thread Roland Gruber
://www.ldap-account-manager.org/lamcms/liveDemo Authors & Copyright: Copyright (C) 2003 - 2022: Roland Gruber LAM is published under the GNU General Public License. The complete list of licenses can be found in the copyright

Re: [Lam-public] downgrade LAM Pro (7.4) to LAM ?

2022-02-23 Thread Roland Gruber
Hi Robert, see here: https://www.ldap-account-manager.org/static/doc/manual/ch02s02.html The downgrade works the same way as the upgrade. You can switch between both versions very easy. Best regards Roland Am 23.02.22 um 19:29 schrieb Robert Moulton: How is this done?

Re: [Lam-public] Hash type enforcement for crypt via lam doesn't work.

2022-02-17 Thread Roland Gruber
Hi Ricardo, the hash type CRYPT-SHA512 would be the right for you. It uses the default 5000 rounds. You can also use the hash type PLAIN to get passwords hashed on server side. Then it will take your OpenLDAP settings. Best regards Roland Am 17.02.22 um 22:46 schrieb Ricardo Barbosa via

Re: [Lam-public] Cannot set user password

2022-01-25 Thread Roland Gruber
Hi Jim, can you provide more details? E.g. do you get any error message? Was the LDAP server software upgraded, too? Please also activate LAM's logging to get more information: https://www.ldap-account-manager.org/static/doc/manual/ch03.html#conf_logging Best regards Roland Am 25.01.22

Re: [Lam-public] create windows-only users

2022-01-16 Thread Roland Gruber
Hi Mourik Jan, yes, this is possible. In server profile, tab Account types add another Users type (configure LDAP suffix, alias, ...). Then on tab Modules use "Account"/"Samba 3" (Samba 3) or "Windows" (Samba 4/AD). You will then see a new account type in LAM's menu that has no Unix

Re: [Lam-public] Security feature request

2022-01-12 Thread Roland Gruber
Hi Jürgen, is this to prevent the error message when trying to save a user without password? Users without password cannot be created anyway (Samba refuses them). Can you give some more details like if the random password should be shown to the user admin? Best regards Roland Am

[Lam-public] LDAP Account Manager 7.8 with updated design and PowerDNS support

2021-12-28 Thread Roland Gruber
units * schema browser * tree view * 2FA support Demo installation: -- You can try our demo installation online. https://www.ldap-account-manager.org/lamcms/liveDemo Authors & Copyright: Copyright (C) 2003 - 2021: Roland Gruber LAM is published u

[Lam-public] LDAP Account Manager 7.8.RC1 with updated design and PowerDNS support

2021-12-17 Thread Roland Gruber
ight: Copyright (C) 2003 - 2021: Roland Gruber LAM is published under the GNU General Public License. The complete list of licenses can be found in the copyright file. ___ Lam-public mailing list Lam-public@lists.sourceforge.net https://lists.sourceforge

Re: [Lam-public] privacyIDEA and LAM

2021-11-15 Thread Roland Gruber
Hi John, thanks for your detailed report. We will look into this. The background for using /auth is to get the list of possible OTP serials. But maybe this is not needed any more. Best regards Roland Am 15.11.21 um 18:38 schrieb John Maher: The following is a little complicated, so I

Re: [Lam-public] Setting up OpenLDAP TOTP error

2021-11-14 Thread Roland Gruber
bindro" with the following access control in slapd.conf: access to * by dn.base="uid= bindro,dc=test,dc=lan" read by * break Any suggestions on a creating a bind user to "...add/remove the TOTP object classes and attributes." and the associated access control? I plan on

Re: [Lam-public] Setting up OpenLDAP TOTP error

2021-11-10 Thread Roland Gruber
Hi Jose, please check your self service profile. On tab "Module settings" there is "OpenLDAP TOTP" where you can specify the DN with the DN of the TOTP parameters. This DN must contain oathHMACAlgorithm, oathOTPLength, oathTOTPTimeStepPeriod. Best regards Roland Am 09.11.21 um 00:19

Re: [Lam-public] Password mail settings

2021-11-05 Thread Roland Gruber
Hi John, LAM is using the FROM setting from your server profile. But it could be that your SMTP server is enforcing the FROM to the sender user. E.g. this could be setup to avoid spam sending etc. I suggest to check with your local IT if they enforce the FROM address. Best regards Roland

Re: [Lam-public] Self service not changing Samba password

2021-11-04 Thread Roland Gruber
Hi John, on tab "Page layout" please add the field "Windows: Password". If you are on Samba 3 then there is a field "Samba3: Sync Samba NT password with Unix password". This should do the job. Best regards Roland Am 04.11.21 um 17:09 schrieb John Maher: I've just started playing around

Re: [Lam-public] LDAP Hosts multiple CN's

2021-10-29 Thread Roland Gruber
inal Message- From: Roland Gruber Sent: 28 October 2021 06:38 To: lam-public@lists.sourceforge.net Subject: Re: [Lam-public] LDAP Hosts multiple CN's Caution: This email has originated from outside of the organisation. Do not click links or open attachments unless you have verified the se

Re: [Lam-public] LDAP Hosts multiple CN's

2021-10-27 Thread Roland Gruber
Hi Steve, which account modules do you use for hosts? Maybe we can just add multi-value support for the field. Best regards Roland Am 27.10.21 um 10:56 schrieb Irvine, Stephen A. via Lam-public: Hey, I might just be missing something. So we have copied over a whole load of hosts from

Re: [Lam-public] privacyIDEA 2FA

2021-10-15 Thread Roland Gruber
Hi John, please set it to the domain of your privacyIdea server. E.g. "https://www.example.com;. It is important that this uses a proper SSL certificate that is trusted by the machine where LAM is running. You can also activate debug logging here:

Re: [Lam-public] WindowsManagedGroupsNotifyJob

2021-10-06 Thread Roland Gruber
Hi Mourik Jan, Am 06.10.21 um 09:12 schrieb mj: This is what we are getting now: PHP Notice:  Undefined index: WindowsPasswordNotifyJob_mailNotificationPeriod812856963856 in /usr/share/ldap-account-manager/lib/modules/windowsUser.inc on line 4521 Error in job WindowsPasswordNotifyJob:

Re: [Lam-public] WindowsManagedGroupsNotifyJob

2021-10-05 Thread Roland Gruber
with the WindowsPasswordNotifyJob in the latest 7.7 final. MJ Op 15-09-2021 om 19:07 schreef Roland Gruber: Hi Mourik Jan, thanks a lot for your report. This will be fixed in next release. Best regards Roland Am 15.09.21 um 09:06 schrieb mj: Hi, Just a minor remark: We are using the Managedby Groups

Re: [Lam-public] Docker image for LAM Pro

2021-10-02 Thread Roland Gruber
Hi Erik, Docker for LAM Pro is available on gitlab.com: https://www.ldap-account-manager.org/static/doc/manual/ch02.html#idm365 Please send me your Gitlab account name via direct email to get access. Best regards Roland Am 02.10.21 um 20:59 schrieb Erik Meitner via Lam-public: The docker

[Lam-public] LDAP Account Manager 7.7 with OpenID and OpenLDAP TOTP support

2021-09-30 Thread Roland Gruber
for organizational units * schema browser * tree view * 2FA support Demo installation: You can try our demo installation online. https://www.ldap-account-manager.org/lamcms/liveDemo Authors & Copyright: Copyright (C) 2003 - 2021: Roland Gruber LAM is published under the GNU General Public Lic

  1   2   3   4   5   6   7   >