<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=5&amp;t=778" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2012-04-23T14:16:08+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=5&amp;t=778</id>
<entry>
<author><name><![CDATA[bjankowski]]></name></author>
<updated>2012-04-23T14:16:08+01:00</updated>
<published>2012-04-23T14:16:08+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=778&amp;p=3022#p3022</id>
<link href="https://forum.yubico.com/viewtopic.php?t=778&amp;p=3022#p3022"/>
<title type="html"><![CDATA[Re: LDAPS (AD) Yubiradius failure]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=778&amp;p=3022#p3022"><![CDATA[
So it turned out it was a problem with gnuTLS i debian with self-sgined certs. I managed to work it out using ldapsearch (ldap-utils).  <br />Bug desc. here:<a href="https://bugs.launchpad.net/ubuntu/+source/gnutls13/+bug/397636" class="postlink">https://bugs.launchpad.net/ubuntu/+source/gnutls13/+bug/397636</a><br /><br />What I did was to disable certificate check in <strong>/etc/ldap.conf </strong>option <strong>TLS_REQCERT</strong><p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2007">bjankowski</a> — Mon Apr 23, 2012 2:16 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[bjankowski]]></name></author>
<updated>2012-04-12T09:53:16+01:00</updated>
<published>2012-04-12T09:53:16+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=778&amp;p=3004#p3004</id>
<link href="https://forum.yubico.com/viewtopic.php?t=778&amp;p=3004#p3004"/>
<title type="html"><![CDATA[Re: LDAPS (AD) Yubiradius failure]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=778&amp;p=3004#p3004"><![CDATA[
Hello again!<br />From what I managed to work out my problem was because the DB was corrupt... Basically, I've decided to reinstall and use ver. 3.51, however I still cannot get it to work with LDAP(S). <br /><br />I've imported users and OTP validation against Yubicloud works, but when i troubleshoot sample user i get „Failed to bind to LDAP server”... any suggestions? <br /><br /><div class="codetitle"><b>Code:</b></div><div class="codecontent">Apr 12 16:19:53 yrva35 ykval&#91;1830&#93;: LOG_DEBUG:ykval-queue:synclib:db:DB query is: select distinct server from queue WHERE queued &lt; 1334227783 or queued is null<br />Apr 12 16:19:53 yrva35 ykval&#91;1830&#93;: LOG_INFO:ykval-queue:synclib:found 0 unique servers<br />Apr 12 16:19:58 yrva35 ykropval&#91;13175&#93;: LOG_DEBUG:ykropval-verify:&#91;127.0.0.1&#93; Request: <br />Apr 12 16:19:58 yrva35 ykropval&#91;13175&#93;: LOG_DEBUG:ykropval-common:Reading the appended from sys_settings table <br />Apr 12 16:19:58 yrva35 ykropval&#91;13175&#93;: LOG_DEBUG:ykropval-db:DB query is: SELECT * FROM sys_settings WHERE key = 'append_otp_to_un_or_passwd'<br />Apr 12 16:19:58 yrva35 ykropval&#91;13175&#93;: LOG_DEBUG:ykropval-verify:&#91;127.0.0.1&#93;  : a.user :  missing parameter(s)<br />Apr 12 16:19:58 yrva35 ykropval&#91;13175&#93;: LOG_DEBUG:ykropval-common:Reading the appended from sys_settings table <br />Apr 12 16:19:58 yrva35 ykropval&#91;13175&#93;: LOG_DEBUG:ykropval-db:DB query is: SELECT * FROM sys_settings WHERE key = 'temp_passwd_length'<br />Apr 12 16:19:58 yrva35 ykropval&#91;13175&#93;: LOG_DEBUG:ykropval-common:Reading default domain =&gt; params &#91;user: a.user&#93;<br />Apr 12 16:19:58 yrva35 ykropval&#91;13175&#93;: LOG_DEBUG:ykropval-db:DB query is: SELECT * FROM globalconf WHERE 1 = '1'<br />Apr 12 16:19:58 yrva35 ykropval&#91;13175&#93;: LOG_DEBUG:ykropval-db:DB query is: SELECT d.domain FROM users u INNER JOIN domains d ON u.domain_id = d.id WHERE u.active = true AND d.active = true AND LOWER(u.login_name) = LOWER('a.user') ORDER BY d.id LIMIT 1<br />Apr 12 16:19:58 yrva35 ykropval&#91;13175&#93;: LOG_INFO:ykropvApr 12 16:19:53 yrva35 ykval&#91;1830&#93;: LOG_DEBUG:ykval-queue:synclib:db:DB query is: select distinct server from queue WHERE queued &lt; 1334227783 or queued is null<br />Apr 12 16:19:53 yrva35 ykval&#91;1830&#93;: LOG_INFO:ykval-queue:synclib:found 0 unique servers<br />Apr 12 16:19:58 yrva35 ykropval&#91;13175&#93;: LOG_DEBUG:ykropval-verify:&#91;127.0.0.1&#93; Request: <br />Apr 12 16:19:58 yrva35 ykropval&#91;13175&#93;: LOG_DEBUG:ykropval-common:Reading the appended from sys_settings table <br />Apr 12 16:19:58 yrva35 ykropval&#91;13175&#93;: LOG_DEBUG:ykropval-db:DB query is: SELECT * FROM sys_settings WHERE key = 'append_otp_to_un_or_passwd'<br />Apr 12 16:19:58 yrva35 ykropval&#91;13175&#93;: LOG_DEBUG:ykropval-verify:&#91;127.0.0.1&#93;  : a.user :  missing parameter(s)<br />Apr 12 16:19:58 yrva35 ykropval&#91;13175&#93;: LOG_DEBUG:ykropval-common:Reading the appended from sys_settings table <br />Apr 12 16:19:58 yrva35 ykropval&#91;13175&#93;: LOG_DEBUG:ykropval-db:DB query is: SELECT * FROM sys_settings WHERE key = 'temp_passwd_length'<br />Apr 12 16:19:58 yrva35 ykropval&#91;13175&#93;: LOG_DEBUG:ykropval-common:Reading default domain =&gt; params &#91;user: a.user&#93;<br />Apr 12 16:19:58 yrva35 ykropval&#91;13175&#93;: LOG_DEBUG:ykropval-db:DB query is: SELECT * FROM globalconf WHERE 1 = '1'<br />Apr 12 16:19:58 yrva35 ykropval&#91;13175&#93;: LOG_DEBUG:ykropval-db:DB query is: SELECT d.domain FROM users u INNER JOIN domains d ON u.domain_id = d.id WHERE u.active = true AND d.active = true AND LOWER(u.login_name) = LOWER('a.user') ORDER BY d.id LIMIT 1<br />Apr 12 16:19:58 yrva35 ykropval&#91;13175&#93;: LOG_INFO:ykropval-common:Reading rop configuration =&gt; params &#91;user: a.user, domain: mydomain.local&#93;<br />Apr 12 16:19:58 yrva35 ykropval&#91;13175&#93;: LOG_DEBUG:ykropval-db:DB query is: SELECT * FROM globalconf WHERE 1 = '1'<br />Apr 12 16:19:58 yrva35 ykropval&#91;13175&#93;: LOG_DEBUG:ykropval-db:DB query is: SELECT * FROM users u, domains d WHERE d.active = true AND u.active = true AND d.id = u.domain_id AND LOWER(u.login_name) = LOWER('a.user') AND LOWER(d.domain) = LOWER('mydomain.local')<br />Apr 12 16:19:58 yrva35 ykropval&#91;13175&#93;: LOG_DEBUG:ykropval-db:DB query is: SELECT * FROM ldap_config WHERE domain_id = '290'<br />Apr 12 16:19:58 yrva35 ykropval&#91;13175&#93;: LOG_DEBUG:ykropval-common:Finding the domain_id<br />Apr 12 16:19:58 yrva35 ykropval&#91;13175&#93;: LOG_DEBUG:ykropval-db:DB query is: SELECT * FROM globalconf WHERE 1 = '1'<br />Apr 12 16:19:58 yrva35 ykropval&#91;13175&#93;: LOG_DEBUG:ykropval-db:DB query is: SELECT id FROM domains where active = true and LOWER(domain) = LOWER('mydomain.local')<br />Apr 12 16:19:58 yrva35 ykropval&#91;13175&#93;: LOG_DEBUG:ykropval-db:DB query is: SELECT temp_passwd FROM users where active = true and domain_id = '290' and LOWER(login_name) = LOWER('a.user') and user_name != ''<br />Apr 12 16:19:59 yrva35 ykropval&#91;13175&#93;: LOG_DEBUG:ykropval-verify:&#91;127.0.0.1&#93; otp: ccccccbcnikugvkdnbdujbjjvcllughuirefltfcflrt verified<br />Apr 12 16:19:59 yrva35 ykropval&#91;13175&#93;: LOG_DEBUG:ykropval-verify:&#91;127.0.0.1&#93; Authenticating with LDAP/AD...<br />Apr 12 16:19:59 yrva35 ykropval&#91;13175&#93;: LOG_DEBUG:ykropval-verify:&#91;127.0.0.1&#93; LDAP server url: ldaps://192.1.1.1:636/<br />Apr 12 16:19:59 yrva35 ykropval&#91;13175&#93;: LOG_DEBUG:ykropval-verify:&#91;127.0.0.1&#93; LDAP server optional url: ldaps://:636/<br />Apr 12 16:19:59 yrva35 ykropval&#91;13175&#93;: LOG_DEBUG:ykropval-verify:&#91;127.0.0.1&#93; LDAP protocol version: 3<br />Apr 12 16:19:59 yrva35 ykropval&#91;13175&#93;: LOG_DEBUG:ykropval-verify:&#91;127.0.0.1&#93; Trying to bind to LDAP server with RDN: CN=206557,OU=93020000,OU=93000000,OU=90000000,OU=00000000,OU=OrgUnits,DC=UW,DC=local<br />Apr 12 16:19:59 yrva35 ykropval&#91;13175&#93;: LOG_DEBUG:ykropval-verify:&#91;127.0.0.1&#93; LDAP protocol version: 3<br />Apr 12 16:19:59 yrva35 ykropval&#91;13175&#93;: LOG_ERR:ykropval-verify:&#91;127.0.0.1&#93; Failed to bind to LDAP server<br />Apr 12 16:19:59 yrva35 ykropval&#91;13175&#93;: LOG_DEBUG:ykropval-db:DB query is: INSERT INTO authentication_logs (user_name, yk_publicname, auth_status, auth_cause, auth_details) VALUES ('a.user@mydomain.local','ccccccbcniku','0','0','LDAP validation failed')<br />Apr 12 16:19:59 yrva35 ykropval&#91;13175&#93;: LOG_DEBUG:ykropval-common:SIGN: status=AUTHENTICATION_ERROR&amp;t=2012-04-12T10:49:59Z0389 H=Hw5N1yGALVa84fRUHQ0Kg2rAGTQ= <br />Apr 12 16:20:00 yrva35 ykmap&#91;1821&#93;: LOG_DEBUG:ykmap-synclib:dsi:db:DB query is: select distinct server from queue WHERE queued &lt; 1334227790 or queued is null<br />Apr 12 16:20:03 yrva35 ykval&#91;1830&#93;: LOG_INFO:ykval-queue:synclib:starting resync<br />al-common:Reading rop configuration =&gt; params &#91;user: a.user, domain: mydomain.local&#93;<br />Apr 12 16:19:58 yrva35 ykropval&#91;13175&#93;: LOG_DEBUG:ykropval-db:DB query is: SELECT * FROM globalconf WHERE 1 = '1'<br />Apr 12 16:19:58 yrva35 ykropval&#91;13175&#93;: LOG_DEBUG:ykropval-db:DB query is: SELECT * FROM users u, domains d WHERE d.active = true AND u.active = true AND d.id = u.domain_id AND LOWER(u.login_name) = LOWER('a.user') AND LOWER(d.domain) = LOWER('mydomain.local')<br />Apr 12 16:19:58 yrva35 ykropval&#91;13175&#93;: LOG_DEBUG:ykropval-db:DB query is: SELECT * FROM ldap_config WHERE domain_id = '290'<br />Apr 12 16:19:58 yrva35 ykropval&#91;13175&#93;: LOG_DEBUG:ykropval-common:Finding the domain_id<br />Apr 12 16:19:58 yrva35 ykropval&#91;13175&#93;: LOG_DEBUG:ykropval-db:DB query is: SELECT * FROM globalconf WHERE 1 = '1'<br />Apr 12 16:19:58 yrva35 ykropval&#91;13175&#93;: LOG_DEBUG:ykropval-db:DB query is: SELECT id FROM domains where active = true and LOWER(domain) = LOWER('mydomain.local')<br />Apr 12 16:19:58 yrva35 ykropval&#91;13175&#93;: LOG_DEBUG:ykropval-db:DB query is: SELECT temp_passwd FROM users where active = true and domain_id = '290' and LOWER(login_name) = LOWER('a.user') and user_name != ''<br />Apr 12 16:19:59 yrva35 ykropval&#91;13175&#93;: LOG_DEBUG:ykropval-verify:&#91;127.0.0.1&#93; otp: ccccccbcnikugvkdnbdujbjjvcllughuirefltfcflrt verified<br />Apr 12 16:19:59 yrva35 ykropval&#91;13175&#93;: LOG_DEBUG:ykropval-verify:&#91;127.0.0.1&#93; Authenticating with LDAP/AD...<br />Apr 12 16:19:59 yrva35 ykropval&#91;13175&#93;: LOG_DEBUG:ykropval-verify:&#91;127.0.0.1&#93; LDAP server url: ldaps://192.1.1.1:636/<br />Apr 12 16:19:59 yrva35 ykropval&#91;13175&#93;: LOG_DEBUG:ykropval-verify:&#91;127.0.0.1&#93; LDAP server optional url: ldaps://:636/<br />Apr 12 16:19:59 yrva35 ykropval&#91;13175&#93;: LOG_DEBUG:ykropval-verify:&#91;127.0.0.1&#93; LDAP protocol version: 3<br />Apr 12 16:19:59 yrva35 ykropval&#91;13175&#93;: LOG_DEBUG:ykropval-verify:&#91;127.0.0.1&#93; Trying to bind to LDAP server with RDN: CN=206557,OU=93020000,OU=93000000,OU=90000000,OU=00000000,OU=OrgUnits,DC=UW,DC=local<br />Apr 12 16:19:59 yrva35 ykropval&#91;13175&#93;: LOG_DEBUG:ykropval-verify:&#91;127.0.0.1&#93; LDAP protocol version: 3<br />Apr 12 16:19:59 yrva35 ykropval&#91;13175&#93;: LOG_ERR:ykropval-verify:&#91;127.0.0.1&#93; Failed to bind to LDAP server<br />Apr 12 16:19:59 yrva35 ykropval&#91;13175&#93;: LOG_DEBUG:ykropval-db:DB query is: INSERT INTO authentication_logs (user_name, yk_publicname, auth_status, auth_cause, auth_details) VALUES ('a.user@mydomain.local','ccccccbcniku','0','0','LDAP validation failed')<br />Apr 12 16:19:59 yrva35 ykropval&#91;13175&#93;: LOG_DEBUG:ykropval-common:SIGN: status=AUTHENTICATION_ERROR&amp;t=2012-04-12T10:49:59Z0389 H=Hw5N1yGALVa84fRUHQ0Kg2rAGTQ= <br />Apr 12 16:20:00 yrva35 ykmap&#91;1821&#93;: LOG_DEBUG:ykmap-synclib:dsi:db:DB query is: select distinct server from queue WHERE queued &lt; 1334227790 or queued is null<br />Apr 12 16:20:03 yrva35 ykval&#91;1830&#93;: LOG_INFO:ykval-queue:synclib:starting resync<br /></div><br />Cheers!<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2007">bjankowski</a> — Thu Apr 12, 2012 9:53 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[bjankowski]]></name></author>
<updated>2012-04-10T08:50:13+01:00</updated>
<published>2012-04-10T08:50:13+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=778&amp;p=2997#p2997</id>
<link href="https://forum.yubico.com/viewtopic.php?t=778&amp;p=2997#p2997"/>
<title type="html"><![CDATA[Re: LDAPS (AD) Yubiradius failure]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=778&amp;p=2997#p2997"><![CDATA[
Hello samir,<br />I've verified my Client ID and API Key, and it seems to be working since I am able to successfully authenticate my OTP against YubiCloud. <br />I'll send my log files asap. <br /><br />Moreover, is there any official howto/tutorial regarding integration with Juniper SA solutuions?<br />Cheers!<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2007">bjankowski</a> — Tue Apr 10, 2012 8:50 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[samir]]></name></author>
<updated>2012-04-06T10:50:51+01:00</updated>
<published>2012-04-06T10:50:51+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=778&amp;p=2989#p2989</id>
<link href="https://forum.yubico.com/viewtopic.php?t=778&amp;p=2989#p2989"/>
<title type="html"><![CDATA[Re: LDAPS (AD) Yubiradius failure]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=778&amp;p=2989#p2989"><![CDATA[
If you are using the YubiCloud validation service for validating the OTPs, please verify you have configured the correct Client ID and corresponding API Key in your YRVA settings (the following steps use a pre-created Client ID and API key that can work but for security reasons we recommend you to create a new Client ID and API key by visiting link <a href="https://upgrade.yubico.com/getapikey/" class="postlink">https://upgrade.yubico.com/getapikey/</a>):<br />a) In the YRVA Webmin console, navigate to Global Configuration &gt;&gt; Validation Server and select the YubiCloud-Online Validation Service<br />b) Set the Client ID: 4233 (or your Client ID)<br />c) API key: 'H9xX7BeTIbhYK3xCb/PSEeRVNvY=' (without quotes) (or the API key corresponding to your Client ID)<br /> <br />If the problem still persists, please configure the log files, make a few authentication attempts and send the log files to [url]support@yubico.com[/url]along with the following details:<br /> <br />1) Version of the YubiRADIUS virtual appliance (YRVA) you are using<br />2) The OTP validation server you have configured i.e. YubiCloud or on-board OTP validation server in YRVA<br /> <br />To enable logging, following these steps:<br />I. Login to webmin console for YubiRADIUS<br />II. Go to &quot;System&quot; &gt;&gt; &quot;System Logs&quot;<br />III. Click on log file (ykropval, etc. mentioned below)<br />IV. Select &quot;all&quot; option in &quot;priorities&quot; field of &quot;Message types to log&quot; section<br />V. Please click on &quot;save&quot; button to save the changes.<br />VI. Please repeat step 3, 4 and 5 for other log files mentioned below.<br />VII. Please click on &quot;Apply Changes&quot; button on System Logs page<br />VIII. Go to &quot;Servers&quot; &gt;&gt; &quot;YubiRADIUS Virtual Appliance&quot;<br />IX. Navigate 'Global Configuration' &gt;&gt; 'FreeRADIUS' menu, please enable FreeRADIUS Logging<br />X. Could you please ssh to the YRVA instance and restart the rsyslog process by executing the following  command:<br />    /etc/init.d/rsyslog restart<br />XI. Please try to reassign and test the user with YubiKey credentials.<br /> <br />Please send the following log files to [url]support@yubico.com[/url]<br />/var/log/syslog<br />/var/log/messages<br />/var/log/ykval.log<br />/var/log/ykropval.log<br />/var/log/ykmap.log<br />/var/log/freeradius/radius.log<br /> <br />Thanks!<br /> <br />Samir.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=1076">samir</a> — Fri Apr 06, 2012 10:50 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[bjankowski]]></name></author>
<updated>2012-04-04T14:22:27+01:00</updated>
<published>2012-04-04T14:22:27+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=778&amp;p=2985#p2985</id>
<link href="https://forum.yubico.com/viewtopic.php?t=778&amp;p=2985#p2985"/>
<title type="html"><![CDATA[LDAPS (AD) Yubiradius failure]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=778&amp;p=2985#p2985"><![CDATA[
Hi <br />I'm trying to integrate Juniper SA2500, AD 2008 and Yubiradius for 2 stage auth. I've already managed to import all users from ldap(s), and validate Yubikeys in Yubicloud. User has got assigned an Yubikey. However, when I try to troubleshoot auth. on sample user I get:<br /><div class="codetitle"><b>Code:</b></div><div class="codecontent">Sending Access-Request of id 191 to 127.0.0.1 port 1812<br />   User-Name = &quot;user.1&quot;<br />   User-Password = &quot;PASSWORDccccccbcniktbvrkrurkihvdftecldbhcnebfdrvcihg&quot;<br />   NAS-IP-Address = 127.0.1.1<br />   NAS-Port = 0<br />rad_recv: Access-Reject packet from host 127.0.0.1 port 1812, id=191, length=20<br /></div><br />In syslog:<br /><div class="codetitle"><b>Code:</b></div><div class="codecontent">Apr  4 18:56:03 yrva35 ykmap&#91;2145&#93;: LOG_DEBUG:ykmap-synclib:dsi:db:DB query is: select distinct server from queue WHERE queued &lt; 1333545953 or queued is null<br />Apr  4 18:56:03 yrva35 ykmap&#91;2145&#93;: LOG_INFO:ykmap-synclib:dsi:db:Database error: Array#012(#012    &#91;0&#93; =&gt; HY000#012    &#91;1&#93; =&gt; 7#012    &#91;2&#93; =&gt; no connection to the server#012)<br />Apr  4 18:56:08 yrva35 ykropval&#91;953&#93;: LOG_DEBUG:ykropval-verify:&#91;127.0.0.1&#93; Request: <br />Apr  4 18:56:08 yrva35 ykropval&#91;953&#93;: LOG_DEBUG:ykropval-common:Reading the appended from sys_settings table <br />Apr  4 18:56:08 yrva35 ykropval&#91;953&#93;: LOG_DEBUG:ykropval-db:DB query is: SELECT * FROM sys_settings WHERE key = 'append_otp_to_un_or_passwd'<br />Apr  4 18:56:08 yrva35 ykropval&#91;953&#93;: LOG_DEBUG:ykropval-verify:&#91;127.0.0.1&#93;  : user.1 :  missing parameter(s)<br />Apr  4 18:56:08 yrva35 ykropval&#91;953&#93;: LOG_DEBUG:ykropval-common:Reading the appended from sys_settings table <br />Apr  4 18:56:08 yrva35 ykropval&#91;953&#93;: LOG_DEBUG:ykropval-db:DB query is: SELECT * FROM sys_settings WHERE key = 'temp_passwd_length'<br />Apr  4 18:56:08 yrva35 ykropval&#91;953&#93;: LOG_DEBUG:ykropval-common:Reading default domain =&gt; params &#91;user: user.1&#93;<br />Apr  4 18:56:08 yrva35 ykropval&#91;953&#93;: LOG_DEBUG:ykropval-db:DB query is: SELECT * FROM globalconf WHERE 1 = '1'<br />Apr  4 18:56:08 yrva35 ykropval&#91;953&#93;: LOG_DEBUG:ykropval-db:DB query is: SELECT d.domain FROM users u INNER JOIN domains d ON u.domain_id = d.id WHERE u.active = true AND d.active = true AND LOWER(u.login_name) = LOWER('user.1') ORDER BY d.id LIMIT 1<br />Apr  4 18:56:08 yrva35 ykropval&#91;953&#93;: LOG_INFO:ykropval-common:Reading rop configuration =&gt; params &#91;user: user.1, domain: mydomain.local&#93;<br />Apr  4 18:56:08 yrva35 ykropval&#91;953&#93;: LOG_DEBUG:ykropval-db:DB query is: SELECT * FROM globalconf WHERE 1 = '1'<br />Apr  4 18:56:08 yrva35 ykropval&#91;953&#93;: LOG_DEBUG:ykropval-db:DB query is: SELECT * FROM users u, domains d WHERE d.active = true AND u.active = true AND d.id = u.domain_id AND LOWER(u.login_name) = LOWER('user.1') AND LOWER(d.domain) = LOWER('mydomain.local')<br />Apr  4 18:56:08 yrva35 ykropval&#91;953&#93;: LOG_DEBUG:ykropval-db:DB query is: SELECT * FROM ldap_config WHERE domain_id = '149'<br />Apr  4 18:56:08 yrva35 ykropval&#91;953&#93;: LOG_DEBUG:ykropval-common:Finding the domain_id<br />Apr  4 18:56:08 yrva35 ykropval&#91;953&#93;: LOG_DEBUG:ykropval-db:DB query is: SELECT id FROM domains where active = true and domain ='mydomain.local'<br />Apr  4 18:56:08 yrva35 ykropval&#91;953&#93;: LOG_DEBUG:ykropval-common:Finding the domain_id<br />Apr  4 18:56:08 yrva35 ykropval&#91;953&#93;: LOG_DEBUG:ykropval-db:DB query is: SELECT id FROM domains where active = true and domain ='mydomain.local'<br />Apr  4 18:56:08 yrva35 ykropval&#91;953&#93;: LOG_INFO:ykropval-common:Error Invalid authentication<br />Apr  4 18:56:13 yrva35 ykmap&#91;2145&#93;: LOG_DEBUG:ykmap-synclib:dsi:db:DB query is: select distinct server from queue WHERE queued &lt; 1333545963 or queued is null<br />Apr  4 18:56:13 yrva35 ykmap&#91;2145&#93;: LOG_INFO:ykmap-synclib:dsi:db:Database error: Array#012(#012    &#91;0&#93; =&gt; HY000#012    &#91;1&#93; =&gt; 7#012    &#91;2&#93; =&gt; no connection to the server#012)<br />Apr  4 18:56:23 yrva35 ykmap&#91;2145&#93;: LOG_DEBUG:ykmap-synclib:dsi:db:DB query is: select distinct server from queue WHERE queued &lt; 1333545973 or queued is null<br />Apr  4 18:56:23 yrva35 ykmap&#91;2145&#93;: LOG_INFO:ykmap-synclib:dsi:db:Database error: Array#012(#012    &#91;0&#93; =&gt; HY000#012    &#91;1&#93; =&gt; 7#012    &#91;2&#93; =&gt; no connection to the server#012)<br /></div><br /><br />In reports it seems that user/pass values are not properly passed:<br /><div class="codetitle"><b>Code:</b></div><div class="codecontent">YubiRADIUS Virtual Appliance - Authentication Log Report (All records)<br />Time Range: Upto 2012-04-04 18:59:08<br />Generated On: 2012-04-04 18:59:08<br />Timestamp,Username,YubiKey Public ID,Authentication Status<br />2012-04-04 18:55:13,@,,LDAP validation failed<br />2012-04-04 18:54:47,@,,LDAP validation failed<br />2012-04-04 18:53:28,@,,LDAP validation failed<br /></div><br /><br />Thx for your help!<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2007">bjankowski</a> — Wed Apr 04, 2012 2:22 pm</p><hr />
]]></content>
</entry>
</feed>