Unable to create another ldap Account if another account is linked to ldap group in the same domain
- Vorherrschende Sprache
- Java
- Sterne
- 3.1k
- Forks
- 1.4k
- Ø Merge
- 6 T. 19 Std.
- Gemergte PRs (30 T.)
- 32
Beschreibung
##### ISSUE TYPE
* Bug Report
##### COMPONENT NAME
~~~
ldap
~~~
##### CLOUDSTACK VERSION
~~~
4.19
~~~
##### CONFIGURATION
Advanced Networking, Domain tree with multiple subdomains
##### OS / ENVIRONMENT
RHEL 9.3
VMware 8.0c (8.0.0.3)
LDAP 389 Directory Server
##### SUMMARY
If I create ldap account in domain with ldapCreateAccount, then link this account to ldap group with linkAccountToLdap, I'm not able to create another account in the same domain. I got error:
CloudStack error: HTTP 534 response from CloudStack
{
"createaccountresponse": {
"cserrorcode": 9999,
"errorcode": 534,
"errortext": "No LDAP user exists with the username of test_user",
"uuidList": []
}
}
If I create multiple accounts with ldapCreateAccount first, then I'm able to link all these accounts to ldap groups with linkAccountToLdap. But again, not able to create any other new ldap accounts
##### STEPS TO REPRODUCE
~~~
cs --post ldapCreateAccount username=test_admin account='Test admins' accounttype=2 domainid=6xxxxxx0e-d170-48ea-a9bf-90fexxxxx122
cs --post linkAccountToLdap account='Test Admins' accounttype=2 domainid=6xxxxxx0e-d170-48ea-a9bf-90fexxxxx122 ldapdomain='cn=test admins,cn=test,ou=groups,dc=my,dc=domain,dc=com' type=GROUP
cs --post ldapCreateAccount username=test_users account='Test users' accounttype=0 domainid=6xxxxxx0e-d170-48ea-a9bf-90fexxxxx122
~~~
##### EXPECTED RESULTS
~~~
Create another account in ldap and link it to another ldap group
~~~
##### ACTUAL RESULTS
~~~
CloudStack error: HTTP 534 response from CloudStack
{
"createaccountresponse": {
"cserrorcode": 9999,
"errorcode": 534,
"errortext": "No LDAP user exists with the username of test_user",
"uuidList": []
}
}
~~~
Beitragsleitfaden
Rechercherichtung
Reproduziere das Problem mit ldapCreateAccount, gefolgt von linkAccountToLdap, in der beschriebenen CloudStack 4.19-LDAP-Konfiguration und untersuche anschließend die Einstiegspunkte für die Erstellung von LDAP-Konten und die Gruppenverknüpfung. Als abgeschlossen gilt, wenn ein zweites Konto in derselben Domain erstellt und mit einer anderen LDAP-Gruppe verknüpft werden kann, ohne den HTTP 534-Fehler; pull request #13945 ist bereits offen.
Vom Indexierungsmodell aus dem Issue-Text verfasst.
Bewertung
- Tech-Stack
- java
- Bereich
- authentication
- Issue-Typ
- Bug
- Schwierigkeit
- 4/5
- Geschätzter Aufwand
- 3-5 Tage
- Aktivitätsstatus
- Veraltet
- Klarheit
- Größtenteils klar
- Anfängerfreundlichkeit
- 25/100