Authenticating using an external OpenLDAP server

Discuss installation of Scalix software

Moderators: ScalixSupport, admin

ioitest
Posts: 19
Joined: Sun Dec 03, 2006 11:33 pm

Postby ioitest » Wed Jul 18, 2007 12:10 am

Realized that the smtpd.auth, omslapdeng, pamcheck and other configs are located in /opt/scalix/template/release.sys/pam.d/ for Scalix 11.04 FC5.

I reconfigure those files according to the wiki, with om_ldap.conf in /opt/scalix/template/release.sys/ .........

and still no joy :(

potatoinmiri
Posts: 58
Joined: Wed Mar 28, 2007 9:25 pm

Postby potatoinmiri » Wed Jul 18, 2007 12:38 am

Hi ioitest,

I think its weird that you are without the ~/sys and ~/sys/pam.d directory. There are dozens of directories under your /var/opt/scalix/sx/ , in fact it is where all your mailboxes and configuration lies. and what you should backup on a proper scalix backup plan.

Those directories are created automatically when you install scalix. I suggest you do a reinstallation. But before that, make sure you remove all existing scalix directories. locate scalix on your system and delete all directories with the word scalix on it and then do your installation. Last time i had problem with my configuration when i have the scalix home directory wrongly named because i didnt remove the home directory from my previous installation.
after reinstall, check if you got anything under /var/opt/scalix/sx. and not the sx should match your mailnode name. It takes the first and last alphabet of your scalix primary mailnode .

From my installation, i had the pam.d directory there by default, only had to create pamcheck file if i am not wrongly remember.

ioitest
Posts: 19
Joined: Sun Dec 03, 2006 11:33 pm

Postby ioitest » Wed Jul 18, 2007 12:51 am

Dear potatoinmiri,

Yep. the directory location is the problem. It is all located in /var/opt/scalix/sx/s/sys/pam.d/ ...... someone need to update those old version wikis..........

made the necessary adjustments. And the result is :

[root@scalix pam.d]# sxpamauth -vvv kohl
pam_start_om("pamcheck", "kohl")
pam_authenticate()
Password:
pam_acct_mgmt()

I now have scalix ldap authentication !!!
:lol: :lol: :lol: :lol:

Thanks a lot for your assistance.... maybe if i have the time i will try to create an updated version of the scalix-openldap wiki.......

potatoinmiri
Posts: 58
Joined: Wed Mar 28, 2007 9:25 pm

Postby potatoinmiri » Wed Jul 18, 2007 1:53 am

Hi ioitest,

Its great you that you have got it work, hehe.

ioitest
Posts: 19
Joined: Sun Dec 03, 2006 11:33 pm

Postby ioitest » Wed Jul 18, 2007 2:28 am

Dear Potatoinmiri,

First hurdle cleared! :D

Now comes the 2nd hurdle......

I cant change Helmut Kohl password from SWA or Outlook connector. The error message is "The old password is incorrect. Password was not changed". i dont think there is any docs on this.

My idea is to be able to change/sync password from scalix, intranet,samba,etc. As in viewtopic.php?t=5431

Any lights on why scalix cant change openldap password?

Valerion
Scalix Star
Scalix Star
Posts: 2730
Joined: Thu Feb 26, 2004 7:40 am
Location: Johannesburg, South Africa
Contact:

Postby Valerion » Wed Jul 18, 2007 5:43 am

As far as I remember in Scalix 10 om_ldap is unable to change passwords. I can't spot anything in the man page, but I don't think this changed in 11. (I may be wrong, of course).

You can use the Linux pam_ldap to do that instead of om_ldap, but then you will have to configure the pam_ldap config files as well. Got that working once on Scalix 10, but I haven't played with it in well over a year, so I can't help you a lot.

ioitest
Posts: 19
Joined: Sun Dec 03, 2006 11:33 pm

Postby ioitest » Wed Jul 18, 2007 10:41 pm

Dear Valerion,

Thanks for the info. At least I know where to begin with for the scalix change openldap password problem.

Will dig the docs and see what i can come out with. If successful, this can make a good wiki.

potatoinmiri
Posts: 58
Joined: Wed Mar 28, 2007 9:25 pm

Postby potatoinmiri » Tue Jul 31, 2007 11:23 am

Hi Ioitest,

Sorry for the late reply. I have just came back from my vacation.
I was planning to do the same thing as you too. I only got to the ldap authentication successfully bit, and read that omldapsync thingi must be implemented for the scalix and ldap to synchorize but i can't find many good documentation on how to use the omldapsync function to do that...maybe i am too dumb to figure it out.

will continue where i left off before my vacation tomorrow, hopefully i can get something work and share any successful story with you, sorry not much help yet.

potatoinmiri
Posts: 58
Joined: Wed Mar 28, 2007 9:25 pm

Postby potatoinmiri » Mon Aug 13, 2007 11:22 pm

Hi Ioitest,

Yeah Valerion is correct. You can change your openldap password from scalix. Please refer to the following thread.

viewtopic.php?p=38436#38436

From my setup now, i have omldapsync the accounts created from openldap. When you log into sac, you cans ee the accounts created from openldap are all greyed out, you can't edit anything. As for our setup, we are still undecided on whether we should use external openldap authentication or the existing scalix directory which comes out of our box.


Return to “Installation”



Who is online

Users browsing this forum: No registered users and 2 guests