How to configure multiple users and group bases ?
The Users Base and Groups Base fields on the LDAP configuration screen define a root node to search for entries. The searches are recursive and will traverse the hierarchy starting from those nodes. If your multiple paths share a common base you can configure that value in these properties. For instance, lets assume the following bases:
CN=Sales,CN=Users,DC=test,DC=windows,DC=frevvo,DC=com CN=HR,CN=Users,DC=test,DC=windows,DC=frevvo,DC=com CN=Marketing,CN=Users,DC=test,DC=windows,DC=frevvo,DC=com
A common path among these is CN=Users,DC=test,DC=windows,DC=frevvo,DC=com and that is what you can configure in the Users Base field.
Can I have more than one LDAP tenant ?
Yes, you can configure as many tenants as you want. Each tenant can have its own LDAP configuration.
Can I connect to more than one LDAP Server ?
Each tenant can connect to only one LDAP server. However each tenant can connect to a different LDAP server.
LDAP Troubleshooting
If things are not working as you expected:
- The primary source of information is the log file. In most cases, the LDAP connector will try to indicate what the problem is in the logs. In the log file, look for lines with LDAPSecurityManager or LdapDao.
- It is useful to have an LDAP browser at hand, for instance, the Apache Directory Studio. With the browser you can:
- Check if the connection parameters that you configured in are correct.
- Run queries against LDAP and make sure that the expressions you configured in are correct and returning what you expect.
- If you can't spot the problem and need to contact frevvo support:
- Stop
- Go to <frevvo-home>/tomcat/logs/frevvo.log.
- Follow these steps to change the log level from INFO to DEBUG
- Restart
- Execute the steps that is causing problems.
- Send the log file (zip) to Live Forms support (support@frevvo.com) with a description of the problem.
- Restore the log level to INFO.
Below are some common cases to help with troubleshooting. All of them assume that the connectivity is working, meaning that you tested, from the same box where is running and that the connection parameters to the LDAP server you configured in are correct.
As an admin I can't list the users or groups for the LDAP tenant
This is can be a problem with the expression you configured in All Users Filter (for users) and/or All Groups Filter (for groups) on the Edit Tenant screen. Also verify that the search bases are correct in the Users Base (users) and Groups Base (groups) fields. The LDAP Browser is useful here. Execute a search directly on your LDAP server using the same expression and bases you configured in and check if the result is correct.
A user that should be a designer logs in but can't design forms
- Login to your LDAP/AD Server.
- Make sure you have a group defined for the designer role and it is named frevvo.Designers.
- Make sure the user having the problem is a member of the frevvo.Designers group.
Another potential issue is case sensitivity. Please refer to the topic Mixed or Upper case User Names .
A user that should be an administrator logs in but can't manage the tenant
- Login to your LDAP/AD Server.
- Make sure you have a group defined for the designer role and it is named frevvo.TenantAdmin.
- Make sure the user having the problem is a member of the frevvo.TenantAdmin group.
Another potential issue is case sensitivity. Please refer to the topic Mixed or Upper case User Names.
I can authenticate against LDAP via the Live Forms login page but SSO is not working
- In IIS:
- Make sure Windows Authentication is set in the Default Web App (or the web app used to send requests to )
- Verify that Anonymous Authentication is NOT set in the default Web App (or the web used to send requests to )
- In :
- Open FREVVO_HOME/tomcat/conf/server.xml
- Look at the AJP connector configuration.
- Verify that it has the attribute tomcatAuthentication="false"
Admin Search for a task locked by a user does not show all LDAP users
Although the user list from the LDAP appears correct, the user does not appear in the admin search for a task locked by a user.
- Verify that your LDAP configuration is correct.
- Check if the MaxPageSize property is set in Active Directory. Look for "MaxPageSize" on this Microsoft Support Page for reference. The default value is 1000.
- Change the MaxPageSize from 1000 to the number of users/groups in your Active Directory.
LDAP Errors
The table below lists LDAP errors you may encounter when configuring your tenant with the LDAP Security Manager. Follow the recommended corrective action to resolve.
Parameters | Value | Error on Edit Tenant page |
---|---|---|
Connection URL | Wrong URL | Group access failure: AuthenticationException?: [LDAP: error code 49 - 80090308: LdapErr: DSID-0C0903A9, comment: AcceptSecurityContext error, data 52e, v1db1] |
Connection User | Wrong username | Group access failure: AuthenticationException?: [LDAP: error code 49 - 80090308: LdapErr: DSID-0C090334, comment: AcceptSecurityContext error, data 525, vece] |
Connection Password | Wrong password | Group access failure: AuthenticationException?: [LDAP: error code 49 - 80090308: LdapErr: DSID-0C090334, comment: AcceptSecurityContext error, data 52e, vece] |
Users Base | Wrong CN | "User access failure: NameNotFoundException?: [LDAP: error code 32 - 0000208D: NameErr: DSID-031001CD, problem 2001 (NO_OBJECT), data 0, best match of: 'DC=frevvo,DC=com' ] |
Users Base | Wrong DC | User access failure: UnknownHostException?: frevvod.com |
Groups Base | Wrong CN | Group access failure: NameNotFoundException?: [LDAP: error code 32 - 0000208D: NameErr: DSID-031001CD, problem 2001 (NO_OBJECT), data 0, best match of: 'DC=frevvo,DC=com' ] |
Groups Base | Wrong DC | Group access failure: UnknownHostException?: fqrevvo.com |
All Groups Filter | Syntax error like mismatched brackets | Group access failure: InvalidSearchFilterException?: Unbalanced parenthesis |
All Groups Filter | Invalid search e.g. (objectClasses=group) instead of (objectClass=group) | Group access failure: InvalidSearchFilterException?: [LDAP: error code 18 - 0000216B: AtrErr: DSID-03140274, #1: 0: 0000216B: DSID-03140274, problem 1004 (WRONG_MATCH_OPER), data 0, Att 180006 (objectClasses) ] |
All Groups Filter | Wrong value e.g. (objectClass=groups) instead of (objectClass=group) | Tenant updates successfully |
All Users Filter | Same as all groups filter | Same as all groups filter |