• Recent
    • Unsolved
    • Tags
    • Popular
    • Users
    • Groups
    • Search
    • Register
    • Login

    Users, not machines at the Active Directory.

    Scheduled Pinned Locked Moved
    General Problems
    5
    32
    5.8k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J
      jacoboren
      last edited by

      Hi,

      I’m brand new here and I log FOG.

      I look for a different thing of the trivial of Active directory.

      I don’t want to put machines at the AD like other topics, I looking for how to put the user login at the fog platform (serverimages.com/fog/management) separated by user not by local but as domain\jacob and then this user can save and deploy the images by himself.

      I joined the Linux server at the Domain but the FOG doesn’t recognize the users at the login.

      Someone knows?

      Many thanks.
      Jacob.

      1 Reply Last reply Reply Quote 0
      • george1421G
        george1421 Moderator
        last edited by

        Welcome to the FOG Project Forums.

        I don’t exactly understand your request. It may be a language translation problem. You may use your native language if want.

        I think you want to enable so users can login to the FOG management console using AD user accounts. You can do this if you install the LDAP plugin in fog. The FOG server OS does not need to be a member of AD for this function to work. You just need the FOG plugin and then to update the settings.

        Just be aware that FOG is not a backup tool. It is a whole disk imaging tool.

        Please help us build the FOG community with everyone involved. It's not just about coding - way more we need people to test things, update documentation and most importantly work on uniting the community of people enjoying and working on FOG!

        1 Reply Last reply Reply Quote 0
        • J
          jacoboren
          last edited by

          @george1421 said in Users, not machines at the Active Directory.:

          aware that FOG is not a backup tool. It is a whole disk imagin

          Thanks for your answer “georger1421”,

          The issue is, every user need to have his account separated to login at FOG. For this integration with AD is necessary.

          In my case each user will deploy and capture his own build.

          Thanks.

          Tom ElliottT 1 Reply Last reply Reply Quote 0
          • Tom ElliottT
            Tom Elliott @jacoboren
            last edited by

            @jacoboren As @george1421 pointed out, then I think what you’re looking for already exists.

            FOG Configuration Page->FOG Settings->Plugin Settings-> Enable Plugins.

            Go to the gear icon that becomes present.

            Click on “LDAP” plugin (Looks like a key).

            Go to install plugin.

            Click on “LDAP” plugin.

            Click on Install LDAP Plugin.

            You will then have a new icon appear that looks like the Key in the main menu item.

            Click there.

            Create New.

            Make the configuration as you need it.

            Please help us build the FOG community with everyone involved. It's not just about coding - way more we need people to test things, update documentation and most importantly work on uniting the community of people enjoying and working on FOG! Get in contact with me (chat bubble in the top right corner) if you want to join in.

            Web GUI issue? Please check apache error (debian/ubuntu: /var/log/apache2/error.log, centos/fedora/rhel: /var/log/httpd/error_log) and php-fpm log (/var/log/php*-fpm.log)

            Please support FOG if you like it: https://wiki.fogproject.org/wiki/index.php/Support_FOG

            Wayne WorkmanW 1 Reply Last reply Reply Quote 2
            • J
              jacoboren
              last edited by

              @Tom-Elliott , @george1421 Thanks for your assistance, I did it as Tom explain here,and find it this print also from @Tom-Elliott here

              https://forums.fogproject.org/assets/uploads/files/1481746756040-upload-0df64a0d-c188-4747-beec-b20c51d3dd38.png?v=qmakmgm1n9o

              But still without work. It is necessary that at the OS is integrate as well with the AD at /etc/krb5.conf for example or the plugin of FOG should be enough?

              Many thanks!
              Jacob.

              george1421G 1 Reply Last reply Reply Quote 0
              • S
                Sebastian Roth Moderator
                last edited by Sebastian Roth

                @jacoboren There is no need to join the machine to your domain (/etc/krb5.conf needed!). FOG does directly contact your LDAP/AD to authenticate users. Double check all the settings, e.g. your “Group Memeber Attribute” in AD might be named different to the one in the screenshot you posted. Although I think MS is all case-insensitive you might try sAMAccountName instead of samAccountName as well.

                I just read somewhere that:

                For Microsoft Active Directory, specify the base DN in the following format: dc=domain1,dc=local. You will need to replace the domain1 and local for your specific configuration. Microsoft Server provides a tool called ldp.exe which is useful for finding out and configuring the the LDAP structure of your server.

                Web GUI issue? Please check apache error (debian/ubuntu: /var/log/apache2/error.log, centos/fedora/rhel: /var/log/httpd/error_log) and php-fpm log (/var/log/php*-fpm.log)

                Please support FOG if you like it: https://wiki.fogproject.org/wiki/index.php/Support_FOG

                1 Reply Last reply Reply Quote 0
                • george1421G
                  george1421 Moderator @jacoboren
                  last edited by

                  @jacoboren Some comments since I helped the developers with this plugin.

                  1. The ldap server name should be an IP address of an AD domain controller.
                  2. If you enable group matching then for admin users they must be members of the defined group to get access to FOG. If group matching == no then the login user must have a valid AD account only.
                  3. Search base DN is the root or starting point to look for users. If you set to the base of your AD tree it will look for users below that root (i.e dc=domain,dc=local would be your entire AD)
                  4. The group search base is where FOG will look for matching groups
                  5. Admin group. If group matching == yes then only people in the admin group will be allowed to access FOG.
                  6. Same for the mobile group
                  7. Search scope tells how far to look in AD Base and subtree is a good scope.
                  8. Bind DN and Bind Pass is just a read only AD account FOG uses to find users in AD.

                  If you are still having troubles and can share some info we can help define what should be in those fields. But Sebastian is right the host OS is not used for AD authentication that is done in PHP.

                  Please help us build the FOG community with everyone involved. It's not just about coding - way more we need people to test things, update documentation and most importantly work on uniting the community of people enjoying and working on FOG!

                  1 Reply Last reply Reply Quote 0
                  • J
                    jacoboren
                    last edited by

                    0_1500985598013_my_print_ldap.jpg

                    Hi, first thank so much for all help of you (@george1421 , @Tom-Elliott , @Sebastian-Roth ) make me more motivation to use FOG on my environment.

                    I saw that was missing the package: php5.6-ldap (from ubuntu) and was installed, and i still having the same issue even with “ad_account”

                    This is the print of my conf. Where can I see the .log output when I try to do login, have a dedicated file for it?

                    What is missing here?

                    Jacob.

                    Tom ElliottT george1421G 2 Replies Last reply Reply Quote 0
                    • Tom ElliottT
                      Tom Elliott @jacoboren
                      last edited by

                      @jacoboren First you should have different “user/mobile” groups. You can leave the group blank for one or the other (one must be filled), but it seems confusing, to me, to have both the admin and mobile group showing exactly the same.

                      Both search and Groups search are in the same element? (Groups are searched at CN Workers) as well as base lookup is performed at the same level?

                      The Base and Subtree is restricted to the search element. So base would be: workers, and subtree would be anything immediately under the workers CN.

                      You actually have a bind username/password?

                      Sorry if you’re not sure of all the answers, just trying to get clarity and hopefully help out a little.

                      Please help us build the FOG community with everyone involved. It's not just about coding - way more we need people to test things, update documentation and most importantly work on uniting the community of people enjoying and working on FOG! Get in contact with me (chat bubble in the top right corner) if you want to join in.

                      Web GUI issue? Please check apache error (debian/ubuntu: /var/log/apache2/error.log, centos/fedora/rhel: /var/log/httpd/error_log) and php-fpm log (/var/log/php*-fpm.log)

                      Please support FOG if you like it: https://wiki.fogproject.org/wiki/index.php/Support_FOG

                      1 Reply Last reply Reply Quote 0
                      • S
                        Sebastian Roth Moderator
                        last edited by

                        @jacoboren said in Users, not machines at the Active Directory.:

                        php5.6-ldap

                        Which version of FOG do you use? On ubuntu systems the installer should be adding php7.1* packages! Please see which version of the packages you have currently installed dpkg -l | grep php, post the full list here!

                        As well I am wondering about “Search Base DN” and “Group Search DN” both being the same. Does this make sense?

                        Web GUI issue? Please check apache error (debian/ubuntu: /var/log/apache2/error.log, centos/fedora/rhel: /var/log/httpd/error_log) and php-fpm log (/var/log/php*-fpm.log)

                        Please support FOG if you like it: https://wiki.fogproject.org/wiki/index.php/Support_FOG

                        1 Reply Last reply Reply Quote 0
                        • george1421G
                          george1421 Moderator @jacoboren
                          last edited by

                          @jacoboren As Tom said, you should have a different group name between admin and mobile groups. We have not tested what will happen if you do it this way.

                          As for the group search dn and the search base dn. The group search dn is used the fine the group yakov if that group is in the OU workers then your search base is correct.

                          One thing I noticed with your search dn path. Microsoft uses special folders and not OUs for their default ldap objects they use the cn= reference. If someone created the workers OU then you need to use the ou= reference and not the cn= reference. I might think your search dn would look like this ou=workers,dc=,dc=corp,dc=inte

                          Please help us build the FOG community with everyone involved. It's not just about coding - way more we need people to test things, update documentation and most importantly work on uniting the community of people enjoying and working on FOG!

                          1 Reply Last reply Reply Quote 0
                          • J
                            jacoboren
                            last edited by Sebastian Roth

                            Hi,

                            @Sebastian-Roth

                            I saw that I have php7 and php5 maybe is a mismatch here? Right? Need to remove php7.1*

                            This is my output of :

                             dpkg -l | grep php
                            
                            ii  libapache2-mod-php7.1                      7.1.6-1~ubuntu16.04.1+deb.sury.org+1                        amd64        server-side, HTML-embedded scripting language (Apache 2 module)
                            ii  php-common                                 1:52+deb.sury.org~xenial+1                                  all          Common files for PHP packages
                            ii  php-gettext                                1.0.11-2+deb.sury.org~xenial+1                              all          read gettext MO files directly, without requiring anything other than PHP
                            ii  php-ldap                                   1:7.1+53~ubuntu16.04.1+deb.sury.org+1                       all          LDAP module for PHP [default]
                            ii  php-pear                                   1:1.10.4+submodules+notgz-1~ubuntu16.04.1+deb.sury.org+1    all          PEAR Base System
                            ii  php-xml                                    1:7.1+52+deb.sury.org~xenial+1                              all          DOM, SimpleXML, WDDX, XML, and XSL module for PHP [default]
                            ii  php5.6-common                              5.6.31-1~ubuntu16.04.1+deb.sury.org+1                       amd64        documentation, examples and common module for PHP
                            ii  php5.6-ldap                                5.6.31-1~ubuntu16.04.1+deb.sury.org+1                       amd64        LDAP module for PHP
                            ii  php7.1                                     7.1.6-1~ubuntu16.04.1+deb.sury.org+1                        all          server-side, HTML-embedded scripting language (metapackage)
                            ii  php7.1-bcmath                              7.1.6-1~ubuntu16.04.1+deb.sury.org+1                        amd64        Bcmath module for PHP
                            ii  php7.1-cli                                 7.1.6-1~ubuntu16.04.1+deb.sury.org+1                        amd64        command-line interpreter for the PHP scripting language
                            ii  php7.1-common                              7.1.6-1~ubuntu16.04.1+deb.sury.org+1                        amd64        documentation, examples and common module for PHP
                            ii  php7.1-curl                                7.1.6-1~ubuntu16.04.1+deb.sury.org+1                        amd64        CURL module for PHP
                            ii  php7.1-fpm                                 7.1.6-1~ubuntu16.04.1+deb.sury.org+1                        amd64        server-side, HTML-embedded scripting language (FPM-CGI binary)
                            ii  php7.1-gd                                  7.1.6-1~ubuntu16.04.1+deb.sury.org+1                        amd64        GD module for PHP
                            ii  php7.1-json                                7.1.6-1~ubuntu16.04.1+deb.sury.org+1                        amd64        JSON module for PHP
                            ii  php7.1-ldap                                7.1.6-1~ubuntu16.04.1+deb.sury.org+1                        amd64        LDAP module for PHP
                            ii  php7.1-mbstring                            7.1.6-1~ubuntu16.04.1+deb.sury.org+1                        amd64        MBSTRING module for PHP
                            ii  php7.1-mcrypt                              7.1.6-1~ubuntu16.04.1+deb.sury.org+1                        amd64        libmcrypt module for PHP
                            ii  php7.1-mysql                               7.1.6-1~ubuntu16.04.1+deb.sury.org+1                        amd64        MySQL module for PHP
                            ii  php7.1-opcache                             7.1.6-1~ubuntu16.04.1+deb.sury.org+1                        amd64        Zend OpCache module for PHP
                            ii  php7.1-readline                            7.1.6-1~ubuntu16.04.1+deb.sury.org+1                        amd64        readline module for PHP
                            ii  php7.1-xml                                 7.1.6-1~ubuntu16.04.1+deb.sury.org+1                        amd64        DOM, SimpleXML, WDDX, XML, and XSL module for PHP
                            

                            @george1421

                            Changed from “cn=” to “ou=” without success.

                            Thanks guys.

                            1 Reply Last reply Reply Quote 0
                            • S
                              Sebastian Roth Moderator
                              last edited by

                              @jacoboren said in Users, not machines at the Active Directory.:

                              php7.1-ldap

                              So this was installed already I suppose and has been used all the time. I think you can safely remove php5.6-common and php5.6-ldap but make sure it does not remove other packages when you do this!

                              Web GUI issue? Please check apache error (debian/ubuntu: /var/log/apache2/error.log, centos/fedora/rhel: /var/log/httpd/error_log) and php-fpm log (/var/log/php*-fpm.log)

                              Please support FOG if you like it: https://wiki.fogproject.org/wiki/index.php/Support_FOG

                              1 Reply Last reply Reply Quote 0
                              • J
                                jacoboren
                                last edited by Sebastian Roth

                                @Sebastian-Roth this is the output now:

                                 dpkg -l | grep php
                                ii  libapache2-mod-php7.1                      7.1.6-1~ubuntu16.04.1+deb.sury.org+1                        amd64        server-side, HTML-embedded scripting language (Apache 2 module)
                                ii  php-common                                 1:52+deb.sury.org~xenial+1                                  all          Common files for PHP packages
                                ii  php-gettext                                1.0.11-2+deb.sury.org~xenial+1                              all          read gettext MO files directly, without requiring anything other than PHP
                                ii  php-ldap                                   1:7.1+53~ubuntu16.04.1+deb.sury.org+1                       all          LDAP module for PHP [default]
                                ii  php-pear                                   1:1.10.4+submodules+notgz-1~ubuntu16.04.1+deb.sury.org+1    all          PEAR Base System
                                ii  php-xml                                    1:7.1+52+deb.sury.org~xenial+1                              all          DOM, SimpleXML, WDDX, XML, and XSL module for PHP [default]
                                ii  php7.1                                     7.1.6-1~ubuntu16.04.1+deb.sury.org+1                        all          server-side, HTML-embedded scripting language (metapackage)
                                ii  php7.1-bcmath                              7.1.6-1~ubuntu16.04.1+deb.sury.org+1                        amd64        Bcmath module for PHP
                                ii  php7.1-cli                                 7.1.6-1~ubuntu16.04.1+deb.sury.org+1                        amd64        command-line interpreter for the PHP scripting language
                                ii  php7.1-common                              7.1.6-1~ubuntu16.04.1+deb.sury.org+1                        amd64        documentation, examples and common module for PHP
                                ii  php7.1-curl                                7.1.6-1~ubuntu16.04.1+deb.sury.org+1                        amd64        CURL module for PHP
                                ii  php7.1-fpm                                 7.1.6-1~ubuntu16.04.1+deb.sury.org+1                        amd64        server-side, HTML-embedded scripting language (FPM-CGI binary)
                                ii  php7.1-gd                                  7.1.6-1~ubuntu16.04.1+deb.sury.org+1                        amd64        GD module for PHP
                                ii  php7.1-json                                7.1.6-1~ubuntu16.04.1+deb.sury.org+1                        amd64        JSON module for PHP
                                ii  php7.1-ldap                                7.1.6-1~ubuntu16.04.1+deb.sury.org+1                        amd64        LDAP module for PHP
                                ii  php7.1-mbstring                            7.1.6-1~ubuntu16.04.1+deb.sury.org+1                        amd64        MBSTRING module for PHP
                                ii  php7.1-mcrypt                              7.1.6-1~ubuntu16.04.1+deb.sury.org+1                        amd64        libmcrypt module for PHP
                                ii  php7.1-mysql                               7.1.6-1~ubuntu16.04.1+deb.sury.org+1                        amd64        MySQL module for PHP
                                ii  php7.1-opcache                             7.1.6-1~ubuntu16.04.1+deb.sury.org+1                        amd64        Zend OpCache module for PHP
                                ii  php7.1-readline                            7.1.6-1~ubuntu16.04.1+deb.sury.org+1                        amd64        readline module for PHP
                                ii  php7.1-xml                                 7.1.6-1~ubuntu16.04.1+deb.sury.org+1                        amd64        DOM, SimpleXML, WDDX, XML, and XSL module for PHP
                                

                                But still now working…

                                1 Reply Last reply Reply Quote 0
                                • J
                                  jacoboren
                                  last edited by

                                  This is my output on FOG right now.

                                  0_1500991379328_my_print_ldap2.jpg

                                  Tom ElliottT 2 Replies Last reply Reply Quote 0
                                  • Tom ElliottT
                                    Tom Elliott @jacoboren
                                    last edited by

                                    @jacoboren Remove the ger\ from yoru Admin Group.

                                    Please help us build the FOG community with everyone involved. It's not just about coding - way more we need people to test things, update documentation and most importantly work on uniting the community of people enjoying and working on FOG! Get in contact with me (chat bubble in the top right corner) if you want to join in.

                                    Web GUI issue? Please check apache error (debian/ubuntu: /var/log/apache2/error.log, centos/fedora/rhel: /var/log/httpd/error_log) and php-fpm log (/var/log/php*-fpm.log)

                                    Please support FOG if you like it: https://wiki.fogproject.org/wiki/index.php/Support_FOG

                                    1 Reply Last reply Reply Quote 0
                                    • Tom ElliottT
                                      Tom Elliott @jacoboren
                                      last edited by

                                      @jacoboren Change Search Base DN so you only have the dc= elements (just a guess.)

                                      Please help us build the FOG community with everyone involved. It's not just about coding - way more we need people to test things, update documentation and most importantly work on uniting the community of people enjoying and working on FOG! Get in contact with me (chat bubble in the top right corner) if you want to join in.

                                      Web GUI issue? Please check apache error (debian/ubuntu: /var/log/apache2/error.log, centos/fedora/rhel: /var/log/httpd/error_log) and php-fpm log (/var/log/php*-fpm.log)

                                      Please support FOG if you like it: https://wiki.fogproject.org/wiki/index.php/Support_FOG

                                      1 Reply Last reply Reply Quote 1
                                      • J
                                        jacoboren
                                        last edited by

                                        Hi guys, @Tom-Elliott @Sebastian-Roth @george1421

                                        I still having a thinking that something on the ldap integration with the OS can cause problems…so what I did it?

                                        Rebuild again on the step that doesn’t have any installation to fecth OS to Ldap, I though that some libs are creating conflict on this issue.

                                        So from now I only have the plugin installed, and follow everything that we talked before, I still without working…

                                        My FOG version is 1.4.3. What I am missing here? Any clue?

                                        0_1501160389971_my_print_ldap3.jpg

                                        dpkg -l | grep php

                                        ii libapache2-mod-php7.1 7.1.6-1~ubuntu16.04.1+deb.sury.org+1 amd64 server-side, HTML-embedded scripting language (Apache 2 module)
                                        ii php-common 1:52+deb.sury.org~xenial+1 all Common files for PHP packages
                                        ii php-gettext 1.0.11-2+deb.sury.org~xenial+1 all read gettext MO files directly, without requiring anything other than PHP
                                        ii php-pear 1:1.10.4+submodules+notgz-1~ubuntu16.04.1+deb.sury.org+1 all PEAR Base System
                                        ii php-xml 1:7.1+52+deb.sury.org~xenial+1 all DOM, SimpleXML, WDDX, XML, and XSL module for PHP [default]
                                        ii php7.1 7.1.6-1~ubuntu16.04.1+deb.sury.org+1 all server-side, HTML-embedded scripting language (metapackage)
                                        ii php7.1-bcmath 7.1.6-1~ubuntu16.04.1+deb.sury.org+1 amd64 Bcmath module for PHP
                                        ii php7.1-cli 7.1.6-1~ubuntu16.04.1+deb.sury.org+1 amd64 command-line interpreter for the PHP scripting language
                                        ii php7.1-common 7.1.6-1~ubuntu16.04.1+deb.sury.org+1 amd64 documentation, examples and common module for PHP
                                        ii php7.1-curl 7.1.6-1~ubuntu16.04.1+deb.sury.org+1 amd64 CURL module for PHP
                                        ii php7.1-fpm 7.1.6-1~ubuntu16.04.1+deb.sury.org+1 amd64 server-side, HTML-embedded scripting language (FPM-CGI binary)
                                        ii php7.1-gd 7.1.6-1~ubuntu16.04.1+deb.sury.org+1 amd64 GD module for PHP
                                        ii php7.1-json 7.1.6-1~ubuntu16.04.1+deb.sury.org+1 amd64 JSON module for PHP
                                        ii php7.1-ldap 7.1.6-1~ubuntu16.04.1+deb.sury.org+1 amd64 LDAP module for PHP
                                        ii php7.1-mbstring 7.1.6-1~ubuntu16.04.1+deb.sury.org+1 amd64 MBSTRING module for PHP
                                        ii php7.1-mcrypt 7.1.6-1~ubuntu16.04.1+deb.sury.org+1 amd64 libmcrypt module for PHP
                                        ii php7.1-mysql 7.1.6-1~ubuntu16.04.1+deb.sury.org+1 amd64 MySQL module for PHP
                                        ii php7.1-opcache 7.1.6-1~ubuntu16.04.1+deb.sury.org+1 amd64 Zend OpCache module for PHP
                                        ii php7.1-readline 7.1.6-1~ubuntu16.04.1+deb.sury.org+1 amd64 readline module for PHP
                                        ii php7.1-xml 7.1.6-1~ubuntu16.04.1+deb.sury.org+1 amd64 DOM, SimpleXML, WDDX, XML, and XSL module for PHP

                                        Tom ElliottT george1421G 2 Replies Last reply Reply Quote 0
                                        • Tom ElliottT
                                          Tom Elliott @jacoboren
                                          last edited by

                                          @jacoboren Is your domain actually:

                                          ger.corp.inte.com or is it gerglb.inte.com?

                                          Please help us build the FOG community with everyone involved. It's not just about coding - way more we need people to test things, update documentation and most importantly work on uniting the community of people enjoying and working on FOG! Get in contact with me (chat bubble in the top right corner) if you want to join in.

                                          Web GUI issue? Please check apache error (debian/ubuntu: /var/log/apache2/error.log, centos/fedora/rhel: /var/log/httpd/error_log) and php-fpm log (/var/log/php*-fpm.log)

                                          Please support FOG if you like it: https://wiki.fogproject.org/wiki/index.php/Support_FOG

                                          1 Reply Last reply Reply Quote 0
                                          • Tom ElliottT
                                            Tom Elliott
                                            last edited by

                                            Do your groups actually reside in a created OU called workers?

                                            Please help us build the FOG community with everyone involved. It's not just about coding - way more we need people to test things, update documentation and most importantly work on uniting the community of people enjoying and working on FOG! Get in contact with me (chat bubble in the top right corner) if you want to join in.

                                            Web GUI issue? Please check apache error (debian/ubuntu: /var/log/apache2/error.log, centos/fedora/rhel: /var/log/httpd/error_log) and php-fpm log (/var/log/php*-fpm.log)

                                            Please support FOG if you like it: https://wiki.fogproject.org/wiki/index.php/Support_FOG

                                            1 Reply Last reply Reply Quote 0
                                            • 1
                                            • 2
                                            • 1 / 2
                                            • First post
                                              Last post

                                            156

                                            Online

                                            12.0k

                                            Users

                                            17.3k

                                            Topics

                                            155.2k

                                            Posts
                                            Copyright © 2012-2024 FOG Project