Inedo Community Forums Forums
    • Recent
    • Tags
    • Popular
    • Login

    Welcome to the Inedo Forums! Check out the Forums Guide for help getting started.

    If you are experiencing any issues with the forum software, please visit the Contact Form on our website and let us know!

    Permissions only work when set for specific user, not a group (LDAP)

    Scheduled Pinned Locked Moved Support
    34 Posts 5 Posters 56 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • Dan_WoolfD Offline
      Dan_Woolf inedo-engineer
      last edited by

      Hi @kichikawa_2913,

      Thanks for checking that for me. Based on the fact that you cannot view/download the packages via the UI, this sounds like a permissions configuration issue. Is it possible to share a screen shot of your permissions configuration? You can send it to support@inedo.com with the subject of [QA-785] Permissions Configuration if you do not feel comfortable posting on the forums. This will give us a better idea of things to check for (we would also not post any AD group names directly in the forums either).

      One last thing, can you confirm the version of ProGet you are using and the version of the InedoCore extension you have installed?

      Thanks,
      DAn

      K 1 Reply Last reply Reply Quote 0
      • K Offline
        kichikawa_2913 @Dan_Woolf
        last edited by

        @Dan_Woolf said in Permissions only work when set for specific user, not a group (LDAP):

        [QA-785] Permissions Configuration

        Sending an email with screenshots.

        We are running 6.0.8 Build 5 and InedoCore 1.13.0 with and update available to 1.13.1.

        1 Reply Last reply Reply Quote 0
        • Dan_WoolfD Offline
          Dan_Woolf inedo-engineer
          last edited by

          Hi @kichikawa_2913,

          Thanks for sending that over. Could you also screenshot the "Domains / User Directories" tab and send that over? Your permissions look correct, I'm wondering if there is another setting that might be conflicting.

          Thanks,
          Dan

          K 1 Reply Last reply Reply Quote 0
          • K Offline
            kichikawa_2913 @Dan_Woolf
            last edited by

            @Dan_Woolf Sent

            1 Reply Last reply Reply Quote 0
            • Dan_WoolfD Offline
              Dan_Woolf inedo-engineer
              last edited by

              Hi @kichikawa_2913,

              I think I see what is happening. You currently have both the Built-in and the LDAD user directory enabled. I'm guessing you have users added to the Built-In directory with the same username and it is favoring them. Since those are not in the LDAP group, it is not accepting the permissions. Since you are currently only using the LDAP user directory, I would suggest disabling the Built-In directory.

              The other options would be to remove those users from the built-in directory or add groups to the Built-In with the same name as the LDAP groups and give those groups permissions.

              Thanks,
              Dan

              K 1 Reply Last reply Reply Quote 0
              • K Offline
                kichikawa_2913 @Dan_Woolf
                last edited by

                @Dan_Woolf we only have one "emergency admin" account created with the built-in method. The only reason that is enabled is because the UI recommended it be enabled in case of an emergency or when switching between methods. We have absolutely no users from AD setup on the built-in method.

                1 Reply Last reply Reply Quote 0
                • Dan_WoolfD Offline
                  Dan_Woolf inedo-engineer
                  last edited by

                  Hi @kichikawa_2913,

                  Could you try two things for me?

                  1. Temporarily disable the Built-In directory and see if it works?
                  2. Re-enable Built-In and login with the user name in the format of "user@domail.local"?

                  Thanks,
                  Dan

                  K 1 Reply Last reply Reply Quote 0
                  • K Offline
                    kichikawa_2913 @Dan_Woolf
                    last edited by kichikawa_2913

                    @Dan_Woolf 1 did not work and 2 lets me log in but results in 403 unauthorized still.

                    stevedennisS 1 Reply Last reply Reply Quote 0
                    • stevedennisS Offline
                      stevedennis inedo-engineer @kichikawa_2913
                      last edited by

                      @kichikawa_2913 I'm wondering if this might be a regression with the preview feature, but I can't imagine how. I have one other idea, too...

                      I used the "test privileges" function and it shows that the group has View/Download permissions.

                      Can you clarify this? The "test privileges" should only work with a username, not a group name. Could share what happens when you:

                      1. Have a specific user navigate to a package in a NuGet feed, and then try to download it from UI? Is there a specific message body you see? (outside of 403)
                      2. Enter that same username in the "test privileges" with that particular feed? What are all the permissions you see?

                      After doing those, the last thing I would try is to revert to the 6.0 behavior, and see if the problem still occurs. AT least that will tell us where to look....

                      K 1 Reply Last reply Reply Quote 0
                      • K Offline
                        kichikawa_2913 @stevedennis
                        last edited by

                        @stevedennis

                        1. User logs in, clicks on "Feeds", and only sees the 403 message on the page with nothing else available.
                        2. I sent an email with screenshots of the test privileges for the group and specific user in that group.

                        What do you mean by "revert to the 6.0 behavior"? We are on 6.0.8, should we revert back to the initial release of 6.0.0?

                        1 Reply Last reply Reply Quote 0
                        • Dan_WoolfD Offline
                          Dan_Woolf inedo-engineer
                          last edited by

                          Hi @kichikawa_2913,

                          When you are on the "Domains / User Directories" tab, you should see a link at the top that says "revert to single-directory mode". Steve is requesting that you click that link and see if the problems with the groups still exists.

                          Thanks,
                          Dan

                          K 1 Reply Last reply Reply Quote 0
                          • Dan_WoolfD Offline
                            Dan_Woolf inedo-engineer
                            last edited by

                            Also, I just reviewed the email you sent about the view effective privilege's and it looks like something is not linking up correctly for your users group. Would you be able to run the our AD Test tool 1.13.1 from a windows computer and see if your users show up when searching for members in that group? You will see a tab in that tool called "Get Group's Users". It will allow you to verify we are pulling those users back in that group.

                            Thanks,
                            Dan

                            K 2 Replies Last reply Reply Quote 0
                            • K Offline
                              kichikawa_2913 @Dan_Woolf
                              last edited by

                              @Dan_Woolf from a Visual Studio perspective it seems to be working better, meaning we can see all versions for a package but unable to download certain versions of packages. The only example I have so far is Selenium ChromeDriver NuGet.

                              Error Package 'Selenium.WebDriver.ChromeDriver 99.0.4844.5100' is not found in the following primary source(s): 'https://repo.dev.summit.network/nuget/approved-nuget/v3/index.json'. Please verify all your online package sources are available (OR) package id, version are specified correctly.

                              Despite the package version there and downloadable:

                              a25df9c7-5287-4248-8d11-b925c9e241e1-image.png

                              If I log into the UI with a user from that group I still get 403.

                              1 Reply Last reply Reply Quote 0
                              • K Offline
                                kichikawa_2913 @Dan_Woolf
                                last edited by

                                @Dan_Woolf I'm not getting any users back, I emailed you the debug log.

                                1 Reply Last reply Reply Quote 0
                                • K Offline
                                  kichikawa_2913 @Dan_Woolf
                                  last edited by

                                  @Dan_Woolf sent a second email showing all the settings used in the tool.

                                  1 Reply Last reply Reply Quote 0
                                  • Dan_WoolfD Offline
                                    Dan_Woolf inedo-engineer
                                    last edited by Dan_Woolf

                                    Hi @kichikawa_2913,

                                    Do you happen to have multiple groups with the same name in different OUs? Your log output looks like it found the group, but then the search for the users is not returning any users. If you look at the last line of the debug statement you sent, it shows the group name and OUs it is using when searching. That starts at memberOf=CN=<Group_Name>,OU=.

                                    Thanks,
                                    Dan

                                    1 Reply Last reply Reply Quote 0
                                    • S Offline
                                      sebastian...
                                      last edited by

                                      @kichikawa_2913 Not sure if this is related to your problem, but we had some strange problems after upgrading to ProGet 6.0.8 / 6.0.9 as well, so maybe sharing the following info might help you:

                                      We first encountered problems after upgrading to ProGet 6.0.8: Users could access feeds, but could not download any packages. After upgrading to version 6.0.9 this was resolved.

                                      We then had a problem where access became very slow until users could not access any ressources on our ProGet server anymore (even those with "Anonymous" access rights!). We deactivated the "6.1 Preview Features" and restarted everything (including the IIS). This resolved the issue. We also updated the InedoCore extension, but I don' t think this was related to the problem.

                                      I think the 6.1 features are still kind of buggy. We try to avoid activating them for now.

                                      K 1 Reply Last reply Reply Quote 1
                                      • K Offline
                                        kichikawa_2913 @sebastian...
                                        last edited by

                                        @sebastian thanks for the info! We'll try to update to most recent version and restarting the instance.

                                        @Dan_Woolf we don't have that group in different OUs from what I can see, that looks like the "path"/hierarchy to the group ("Security Groups" -> "Roles" -> "IT"). I'm not as familiar with AD as I would like to be, so I'll ping our admins on that.

                                        1 Reply Last reply Reply Quote 0
                                        • K Offline
                                          kichikawa_2913
                                          last edited by

                                          We are now having issues just creating the container getting the following error:

                                          Error: error creating temporary passwd file for container 441b7e059858087ded586bf7b20a02284af788603bd6fb67e532a0021107db1c: open /home/{username}/.local/share/containers/storage/overlay/6b312eb340dc2cafa8c6aaccdec719d8c249b226b4825ada3250bafd209a607d/merged/etc/passwd: value too large for defined data type

                                          I don't think this is related to ProGet, so I'll report back after we get this resolved.

                                          1 Reply Last reply Reply Quote 0
                                          • Dan_WoolfD Offline
                                            Dan_Woolf inedo-engineer
                                            last edited by

                                            Hi @kichikawa_2913,

                                            I would agree that does not look like a ProGet error. Please let us know what you find.

                                            Thanks,
                                            Dan

                                            K 3 Replies Last reply Reply Quote 0

                                            Hello! It looks like you're interested in this conversation, but you don't have an account yet.

                                            Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.

                                            With your input, this post could be even better 💗

                                            Register Login
                                            • 1
                                            • 2
                                            • 2 / 2
                                            • First post
                                              Last post
                                            Inedo Website Home • Support Home • Code of Conduct • Forums Guide • Documentation