<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=4&amp;t=904" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2013-01-06T22:59:21+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=4&amp;t=904</id>
<entry>
<author><name><![CDATA[nzkiwi68]]></name></author>
<updated>2013-01-06T22:59:21+01:00</updated>
<published>2013-01-06T22:59:21+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=904&amp;p=3437#p3437</id>
<link href="https://forum.yubico.com/viewtopic.php?t=904&amp;p=3437#p3437"/>
<title type="html"><![CDATA[Re: YubiRADIUS V3.5.4 - auto provision problem]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=904&amp;p=3437#p3437"><![CDATA[
I've been monitoring our newly installed server1 and server2 - V3.5.4<br /><br />Now, there are 7 yubico keys in total associated under the reports &quot;YubiKey Assignment&quot; and under the domain &quot;co.local&quot;, 3 tokens are assigned to users, the other 4 are for another domain name.<br /><br />Using webadmin and browsing the domain list of users:<br />      <strong>Domain - co.local (domainname) - All Users</strong><br /><br />Only ONE of those 3 users displays in webadmin, but only 1!<br /><br /><br />I would expect all 3 would be displayed or none, but not 1 out 3.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2232">nzkiwi68</a> — Sun Jan 06, 2013 10:59 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[nzkiwi68]]></name></author>
<updated>2013-01-06T20:39:15+01:00</updated>
<published>2013-01-06T20:39:15+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=904&amp;p=3434#p3434</id>
<link href="https://forum.yubico.com/viewtopic.php?t=904&amp;p=3434#p3434"/>
<title type="html"><![CDATA[YubiRADIUS V3.5.4 - auto provision problem]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=904&amp;p=3434#p3434"><![CDATA[
I have rebuilt using 2 servers (server1 and server2) using V3.5.4 and setup sync between them.<br />(V3.5.4 because HardKnoX and I cannot get users to associate with tokens with a fresh install of V3.6.0)<br /><br />That's all working good using V3.5.4. User accounts have been imported from Active Directory successfully and correctly on both server1 and server.<br /><br />If I manually logon to server1 using the webadmin and associate <!-- e --><a href="mailto:user1@co.local">user1@co.local</a><!-- e --> with a token on server1, then, shortly thereafter on server2, <!-- e --><a href="mailto:user1@co.local">user1@co.local</a><!-- e --> shows being associated with the same token. Good...<br /><br />I have globally enabled auto provision on both server1 and server2 AND additionally I have enabled auto provision within the specific domain &quot;co.local&quot; on both server1 and server2.<br /><br /><strong>Right, the problem:</strong><br />If a valid user logons (say <!-- e --><a href="mailto:user2@co.local">user2@co.local</a><!-- e -->) and is authenticated by say, server1 and this user does NOT have a token associtaed with them, then auto provision kicks in and they get authenticated successfully, just as expected. The issue is, in webadmin on server1, &quot;user2&quot; shows as NOT have having a token assigned to them!<br /><br />If you then run the &quot;<em>Reports</em>&quot; - &quot;<em>YubiKey Assignment</em>&quot; this shows that <!-- e --><a href="mailto:user2@co.local">user2@co.local</a><!-- e --> does in fact have a token assigned.<br />Interestingly, if you then logon to server2 using webadmin, again, under the domain &quot;co.local&quot;, user2 is shown as NOT have a token assigned to them, yet, the YubiKey Assignement report on server2 also shows that <!-- e --><a href="mailto:user2@co.local">user2@co.local</a><!-- e --> does have a token.<br /><br />This means we cannot delete tokens from users, becuase, according to webadmin, no user has any tokens assigned (except for any manual token assignments we manually did).<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2232">nzkiwi68</a> — Sun Jan 06, 2013 8:39 pm</p><hr />
]]></content>
</entry>
</feed>