Inedo Community Forums Forums
    • Recent
    • Tags
    • Popular
    • Login
    1. Home
    2. rhessinger
    3. Posts

    Welcome to the Inedo Forums! Check out the Forums Guide for help getting started.

    If you are experiencing any issues with the forum software, please visit the Contact Form on our website and let us know!

    rhessingerR Offline
    • Profile
    • Following 0
    • Followers 0
    • Topics 0
    • Posts 799
    • Groups 2

    Posts

    Recent
    • RE: How can i exclude npm packages from pgutil

      Hi @Valentijn,

      It looks like when we migrated pgscan in to pgutil, the functionality for this was removed. We will add a new flag to pgutil builds scan called --do-not-scan-npm that will ignore scanning for npm packages. I should have this released later this week or early next week. I will let you know as soon as we push the change.

      Thanks,
      Rich

      posted in Support
      rhessingerR
      rhessinger
    • RE: PyPI connector to Azure Artifacts returns 401, same URL and PAT work with curl

      Hi @carl.westman_8110,

      Always happy to help! I have actually already made the fix internally. If you would like, I can provide a pre-release build of ProGet 2026.13 that includes the fix.

      Thanks,
      Rich

      posted in Support
      rhessingerR
      rhessinger
    • RE: PyPI connector to Azure Artifacts returns 401, same URL and PAT work with curl

      Hi @carl.westman_8110,

      I did a little more digging. The actual issue was that the Azure Simple API was including extra information in the response Content Type. That triggered our connector to switch to the old HTML based parsing, which prevented the files from being found. I have corrected this in PG-3399, which is due out October 16, 2026 in ProGet 2026.13.

      Thanks,
      Rich

      posted in Support
      rhessingerR
      rhessinger
    • RE: ProGet: Delete Asset History Files

      Hi @Ashley,

      I can confirm that F7\._proget_file_history_ is specific to the Feed with an ID 7.

      Thanks,
      Rich

      posted in Support
      rhessingerR
      rhessinger
    • RE: PyPI connector to Azure Artifacts returns 401, same URL and PAT work with curl

      Hi @carl.westman_8110,

      I ran a test against our test Dev Ops instance. I created a connector and I used basic authentication with my Microsoft account username (my email) as the username and the PAT as the password. I found it was finding my package, but ADO's simple API was not returning the file list which is causing our connector to skip over it. We are currently investigating this further.

      As a work around, have you tried importing those packages into your ProGet feed? You can do that by using Import Package -> Download Package from Another Source. That will allow you to import all the packages and version from your ADO artifact feed.

      Thanks,
      Rich

      posted in Support
      rhessingerR
      rhessinger
    • RE: ProGet: Delete Asset History Files

      Hi @Ashley,

      The F7\._proget_file_history_, is specific to the Feed with an ID 7. I'm guessing that is the asset feed that you disabled the history on. You can verify the ID by navigating to the Asset Directory, then click the Manage Directory button. Then in the URL you will see FeedId=. That number will be your feed id and should match 7. If so, then you can just delete F7\._proget_file_history_.

      Please note, if you delete that folder and re-enable versions, the version history will no longer exist.

      Thanks,
      Rich

      posted in Support
      rhessingerR
      rhessinger
    • RE: Proget Installation as container with external Postgres

      Hi @hardik.turakhia,

      Using nginx as a reverse-proxy in front of ProGet is definitely the easiest way. I'm guessing you already took a look at our example nginx config file. When it comes to certificates, I find that it's easiest to use .pem files on Linux. There are a lot of guides out there on how to convert certificates to .pem files and configure them in nginx. The best source is to check with your SSL provider on how to create a fullchain (includes the intermediate certificates) .pem file. We do have some notes in the HTTPS on Windows guide in the update config section that has some commands on how to convert a .pfx file to .pem, which includes some crossover with converting .crt files to .pem files.

      If you are planning to use a dynamic SSL provider like Let's Encrypt, certbot has an extension called certbot-nginx on most distros or via snap on ubuntu/debian distros. That will configure nginx for you.

      Thanks,
      Rich

      posted in Support
      rhessingerR
      rhessinger
    • RE: Does Active Directory support require domain-joining, even with "Domain controller host" set?

      Hi @sai.pabbareddy,

      If you could pull a full LDAP trace/packate capture that would be great. I also setup a single-domain/single-dc. I can even share my setup as I used a VM and docker to set it up. My VM is a base alpine install with docker, docker-compose, and nano installed. Here is my the compose file I tested with. NOTE: my container uses the host network mode because that was the only way I could get it to bind the port in Samba. This is probably not needed if ProGet sat in the same Docker network as the Samba container.

      version: '3.8'
      
      services:
        samba-test-ad:
          image: diegogslomp/samba-ad-dc:latest
          container_name: samba_test_ad
          hostname: DC1
          privileged: true
          network_mode: host
          environment:
            - REALM=PLANETEXPRESS.COM
            - DOMAIN=PLANETEXPRESS
            - ADMIN_PASS=GoodNewsEveryone123!
            - DNS_FORWARDER=8.8.8.8
          # NOTE: "ports" was removed because network_mode: host opens the container ports on the host natively
      
        samba-provisioner:
          image: alpine:latest
          container_name: samba_provisioner
          depends_on:
            - samba-test-ad
          # Shares host network context to communicate with the main container smoothly
          network_mode: host
          volumes:
            - /var/run/docker.sock:/var/run/docker.sock
          entrypoint:
            - /bin/sh
            - -c
            - |
              apk add --no-cache docker-cli
              echo "🚀 Monitoring Active Directory operational readiness..."
      
              while true; do
                if docker exec samba_test_ad /usr/local/samba/bin/samba-tool user list >/dev/null 2>&1; then
                  break
                fi
                echo "⏳ Samba is compiling directory tree schema... checking back in 3s"
                sleep 3
              done
      
              echo "🔌 Active Directory Engine Online and Accepting Modifications!"
      
              echo "--- Creating Test Groups ---"
              docker exec samba_test_ad /usr/local/samba/bin/samba-tool group add ship_crew || true
              docker exec samba_test_ad /usr/local/samba/bin/samba-tool group add admin_staff || true
      
              echo "--- Creating Pre-populated Test Users ---"
              docker exec samba_test_ad /usr/local/samba/bin/samba-tool user create fry FryPassword123! --given-name='Philip' --surname='Fry' --mail-address='fry@planetexpress.com' || true
              docker exec samba_test_ad /usr/local/samba/bin/samba-tool user create leela LeelaPassword123! --given-name='Turanga' --surname='Leela' --mail-address='leela@planetexpress.com' || true
              docker exec samba_test_ad /usr/local/samba/bin/samba-tool user create professor ProfPassword123! --given-name='Hubert' --surname='Farnsworth' --mail-address='professor@planetexpress.com' || true
      
              echo "--- Assigning Group Members ---"
              docker exec samba_test_ad /usr/local/samba/bin/samba-tool group addmembers ship_crew fry,leela || true
              docker exec samba_test_ad /usr/local/samba/bin/samba-tool group addmembers admin_staff professor || true
      
              echo "✅ Active Directory data successfully populated! Setup complete."
      

      Then for my ProGet configuration, I created a new V5: Active Directory and here were the settings:

      • General
        • Name: V5: Samba 4
        • Domain: planetexpress.com
        • User name: Administrator
        • Password: GoodNewsEveryone123!
      • Connection
        • Domain Controller Host: <IP Address of my VM>
        • LDAP Connection: Use LDAP

      Then I tested using Load user by username for the user fry in the group ship_crew. For recursive groups I used the user Administrator and the Group Denied RODC Password Replication Group.

      Then I added ship_crew to the Administer task and I logged in using fry/FryPassword123!.

      Thanks,
      Rich

      posted in Support
      rhessingerR
      rhessinger
    • RE: Does Active Directory support require domain-joining, even with "Domain controller host" set?

      Hi @sai.pabbareddy,

      I realized that how I was enabling it in code left it disabled still in practice due to how that library handles search constraints. I enabled it the right way and did some testing against a Samba 4 server I setup locally and referral chasing ended up making it so slow that it was unusable. With that said, I'm not getting referral exceptions when testing against it, so there may actually be something else going on. Is there anything unique about how your Samba 4 server is configured?

      Thank,
      Rich

      posted in Support
      rhessingerR
      rhessinger
    • RE: Is netsh http add urlacl still required for HTTPS port binding with the integrated Kestrel web server

      Hi @forbzie22_0253,

      Unfortunately, this is still required. By default on Windows, HTTP.sys reserves all ports below port 1024. The netsh http add urlacl url=https://*:443/ user="NETWORK SERVICE" tells HTTP.sys that NETWORK SERVICE can register port 443 and listen to all traffic on it bypassing HTTP.sys.

      If you specified a domain, https://my-domain.com:443 instead of https:://*:443, then HTTP.sys will handle all traffic but will allow NETWORK SERVICE to subscribe at that domain. HTTP.sys will still handle all traffic though. That will then cause the integrated web server (IWS) to use HTTP.sys instead of Kestrel, which is why we recommend the port binding method. This is all outside of IIS. That reason is also we added documentation on how to Use IIS as a reverse proxy.

      Hope this helps!

      Thanks,
      Rich

      posted in Support
      rhessingerR
      rhessinger
    • RE: Does Active Directory support require domain-joining, even with "Domain controller host" set?

      Hi @sai.pabbareddy,

      This has not gone through formal testing, but I just pushed a pre-release of the InedoCore extension that includes the referral following on Linux. Would you mine testing it out on your end and see if it fixes your issue with Samba 4?

      The fix is included in InedoCore 4.0.6-rc.1. To install a pre-release extensions, see installing pre-release extension in ProGet's documentation.

      Thanks,
      Rich

      posted in Support
      rhessingerR
      rhessinger
    • RE: OpenLDAP directory: authentication bind uses empty DN instead of resolved user

      Hi @sai.pabbareddy,

      Glad to hear it all works as expected!

      Thanks,
      Rich

      posted in Support
      rhessingerR
      rhessinger
    • RE: OpenLDAP directory: authentication bind uses empty DN instead of resolved user

      Hi @sai.pabbareddy,

      Thanks for the heads up. The cache fix should exist in 26.0.11-rc.15, but I'll be very interested to hear if you still see those issues after the upgrade. Please keeps us informed and we can look into it further.

      Thanks,
      Rich

      posted in Support
      rhessingerR
      rhessinger
    • RE: ProGet 2026.11 — not appearing on Docker registry or my.inedo.com, six days after stated release

      Hi @sai.pabbareddy,

      My apologies. Looks like I typoed the date on that other post. I had the day of Friday correct, but the date should have been Sept 18, 2026. It will be releasing later today (normally in the evening in EST). I updated that response also to have the correct date.

      Thanks,
      Rich

      posted in Support
      rhessingerR
      rhessinger
    • RE: OpenLDAP directory: authentication bind uses empty DN instead of resolved user

      Hi @sai.pabbareddy,

      I think it would be a good idea to have you send over the exact directory config. The code paths for searching for users and groups are virtually identical, with the only difference being the LDAP filter. You can see what we are doing directly by looking at the code in GitHub: https://github.com/Inedo/inedox-inedocore/blob/16155c425cf4b4d180e2e7ced7af90e36fb4ed35/InedoCore/InedoExtension/UserDirectories/OpenLdap/OpenLdapUserDirectory.cs#L300

      I'm guessing there is something else going on that is causing this, maybe a hidden unicode character or something. When you paste in the ldap queries, can you make sure to include them using a markdown code block (``` ... ```)?

      Thanks,
      Rich

      posted in Support
      rhessingerR
      rhessinger
    • RE: OpenLDAP directory: authentication bind uses empty DN instead of resolved user

      Hi @sai.pabbareddy,

      Let me run some other tests. It could be related to the LDAP escaping that is happening, but that would be highly unlikely as we have many other users currently using the OpenLDAP/Generic LDAP user directory. I think the more peculiar thing is that when you hard coded the uid, the logs didn't show ?uid=, but with the %s it did. That makes me think that it does not like the value that is being passed in. Does the group search have the same issue and log message?

      Thanks,
      Rich

      posted in Support
      rhessingerR
      rhessinger
    • RE: Does Active Directory support require domain-joining, even with "Domain controller host" set?

      Hi @sai.pabbareddy,

      Glad to hear those settings fixed the initial error.

      The LdapReferralException is probably an issue with Samba 4's communication pattern. An LDAP referral typically happens when the AD server is handing off the AD connection to a different LDAP server. The fix is traditionally to connect ProGet to the upstream LDAP server directly. As ProGet supports multiple user directories to be active, this typically isn't a problem. My guess is that Samba 4 uses referrals as a hack for some issue that came up with AD. Based on your comments, I'm guessing the hack is to fix something how it looks up groups (or recursive groups), but I can't confirm that for sure. In v5, we moved this user directory to Active Directory only and force the magic OID for recursive group searches that Microsoft uses.

      You can test if the group portion is the issue by selecting the load by username option in the Test User Directory option and entering a group and username.

      We have not seen any direct Samba 4 ProGet users in support as of yet, so Samba 4 quirks are still a bit unknown to us. Looking at the code, it is most likely due to ProGet running in a container versus installed on Windows. We have to use a different library for LDAP based on the operating system. In this case, I think the issue is that referral chasing is disabled by default on linux. We can enable that feature in code, but it will require some extra testing on our part because this affects ALL ldap queries on the docker version of ProGet.

      Another option is to use the OpenLDAP/Generic LDAP user directory and configure it for Active Directory.

      Thanks,
      Rich

      posted in Support
      rhessingerR
      rhessinger
    • RE: OpenLDAP directory: authentication bind uses empty DN instead of resolved user

      Hi @sai.pabbareddy,

      The port can be changed to a custom port on the advanced tab.

      It looks like the %s is actually working in ProGet, but instead this is a feature of osixia/openldap OpenLDAP Server. When the logs shows a ? mark in front of an attribute in a sqerch query (like ?uid=), it means that either the uid attribute is missing of the objectClass does not exist, which therefore cannot confirm that uid exists on those objects. It also could be that the value is hidden for security reasons and you have to change your logging level to see. If you can provide me with the LDAP object for ldapuser1, I can help you build the proper search queries.

      Thanks,
      Rich

      posted in Support
      rhessingerR
      rhessinger
    • RE: OpenLDAP directory: authentication bind uses empty DN instead of resolved user

      Hi @sai.pabbareddy,

      You will have to also set the Group Search Base as well. Can you test that and let me know if anything changes?

      Also, what OpenLDAP server are you using to run these test with?

      Thanks,
      Rich

      posted in Support
      rhessingerR
      rhessinger
    • RE: Restart-dependent config caching

      Hi @sai.pabbareddy,

      We will be releasing ProGet 2026.11 this Friday, September 18th.

      Thanks,
      Rich

      posted in Support
      rhessingerR
      rhessinger
    • 1
    • 2
    • 3
    • 4
    • 5
    • 39
    • 40
    • 1 / 40