Inedo Community Forums Forums
    • Recent
    • Tags
    • Popular
    • Login

    Welcome to the Inedo Forums! Check out the Forums Guide for help getting started.

    If you are experiencing any issues with the forum software, please visit the Contact Form on our website and let us know!

    ProGet LDAP Group Privileges

    Scheduled Pinned Locked Moved Support
    ldapproget
    4 Posts 1 Posters 7 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • ? This user is from outside of this forum
      Guest
      last edited by

      Using LDAP integration in ProGet, I have the following issues:

      1. I cannot add privileges for Domain Users, Authenticated Users or Domain Admins.
      2. I can add Users which I suspect is the local machines group BUT even though Domain Users is a member of this group, access is not granted and I get an error 500.
      3. Please change this error 500 to a 403 so that we can distinguish between setup issues and authorisation issues.

      2 is a show stopper.

      I look forward to your replies.

      S.

      Product: ProGet
      Version: 3.1.0

      1 Reply Last reply Reply Quote 0
      • ? This user is from outside of this forum
        Guest
        last edited by

        I cannot repro this, just tried adding "Domain Users" and "Domain Admins" on our test instance and it worked as expected. Are you saying you can't find them in the user search, or that adding them just does nothing? Also make sure that you've selected a role to assign - if no roles are checked then it will just close the modal and nothing will be added.

        1 Reply Last reply Reply Quote 0
        • ? This user is from outside of this forum
          Guest
          last edited by

          Scenarios:

          In 1-4. I am able to find the individual or group using the Find button/dialog.

          1. I add myself as administrator to everything - this works.
          2. I add individual colleagues as administrators, developers or read-only - 
             these all work as expected.
          

          Next, I remove all the individual privileges added in 2.

          3. I add Domain Users as read-only to (any) - does not work.
          4. I add Domain Users as read-only to a specific feed - does not work.
          
          5. I cannot find the domain group 'Authenticated Users' using the find dialog.
          

          Hope that's clear.

          1 Reply Last reply Reply Quote 0
          • ? This user is from outside of this forum
            Guest
            last edited by

            In this case, it sounds like the service account has some sort of enumeration problem with groups. This is not uncommon.

            As a test, i would suggestto run the ProGet webapp (either in IIS or the hosted web service) with your domain account.

            And of course, if you do find out specifically what caused this from the groups/permissions side of things, an update would most certainly be appreciated :)

            1 Reply Last reply Reply Quote 0

            Hello! It looks like you're interested in this conversation, but you don't have an account yet.

            Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.

            With your input, this post could be even better 💗

            Register Login
            • 1 / 1
            • First post
              Last post
            Inedo Website Home • Support Home • Code of Conduct • Forums Guide • Documentation