Skip to Content.
Sympa Menu

grouper-users - RE: [grouper-users] SASL TLS/EXTERNAL in grouper-loader.properties

Subject: Grouper Users - Open Discussion List

List archive

RE: [grouper-users] SASL TLS/EXTERNAL in grouper-loader.properties


Chronological Thread 
  • From: Chris Hyzer <>
  • To: Francesco Malvezzi <>, "" <>
  • Subject: RE: [grouper-users] SASL TLS/EXTERNAL in grouper-loader.properties
  • Date: Tue, 10 Sep 2013 20:01:44 +0000
  • Accept-language: en-US

For these three configs:

ldap.personAuthLdap.pemCaFile=/etc/ssl/certs/tcs-chain.pem
ldap.personAuthLdap.pemCertFile=/etc/ssl/certs/grouper.pem
ldap.personAuthLdap.pemKeyFile=/opt/grouper/conf/grouper.key

Did you see those options in an example config file, or just type them in? I
don't think they are valid configs...

You can put this in (in 2.1.4+):

ldap.personLdap.configFileFromClasspath = ldap.personLdap.properties

And put any vt-ldap configs in there... does it work? If not, what version
of Grouper do you have, can you upgrade to the latest?

Thanks,
Chris


-----Original Message-----
From:


[mailto:]
On Behalf Of Francesco Malvezzi
Sent: Tuesday, September 10, 2013 6:19 AM
To:

Subject: [grouper-users] SASL TLS/EXTERNAL in grouper-loader.properties

Hallo all,

I was wondering if it is possibleto employ SASL TLS/EXTERNAL in
grouper-loader.properties.

I tried the following (copy/paste from a working example in
ldap.properties):

ldap.personAuthLdap.url = ldap://ldap2.example.org:389/dc=example,dc=org
ldap.personAuthLdap.tls = true
ldap.personAuthLdap.authtype=EXTERNAL
ldap.personAuthLdap.serviceUser=cn=grouper,ou=agents,dc=example,dc=org
ldap.personAuthLdap.pemCaFile=/etc/ssl/certs/tcs-chain.pem
ldap.personAuthLdap.pemCertFile=/etc/ssl/certs/grouper.pem
ldap.personAuthLdap.pemKeyFile=/opt/grouper/conf/grouper.key

but it is wrong, because the bind is anonymous.

Could you point me in the right direction?

thank you,

Francesco



Archive powered by MHonArc 2.6.16.

Top of Page