Cloudron makes it easy to run web apps like WordPress, Nextcloud, GitLab on your server. Find out more or install now.


Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • Bookmarks
  • Search
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

Cloudron Forum

Apps | Demo | Docs | Install
  1. Cloudron Forum
  2. Rocket.Chat
  3. Question about the AD/LDAP integration

Question about the AD/LDAP integration

Scheduled Pinned Locked Moved Solved Rocket.Chat
22 Posts 4 Posters 2.8k Views 4 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • P Offline
      P Offline
      privsec
      wrote on last edited by
      #1

      My new users can not sign into my rocket.chat instance. They have tried the following

      username
      username@domain.com
      cloudronemail@domain.com

      But nothing is working.

      Nextcloud works flawlessly with the LDAP integration, am I missing something here?

      ? 1 Reply Last reply
      0
      • P privsec

        My new users can not sign into my rocket.chat instance. They have tried the following

        username
        username@domain.com
        cloudronemail@domain.com

        But nothing is working.

        Nextcloud works flawlessly with the LDAP integration, am I missing something here?

        ? Offline
        ? Offline
        A Former User
        wrote on last edited by
        #2

        @privsec Same issue here. Just tried Rocket.chat because of my nextcloud talk issues. Turns out LDAP is messed up. Even with a manual sync it brings in every user BUT mine...

        girishG 1 Reply Last reply
        0
        • ? A Former User

          @privsec Same issue here. Just tried Rocket.chat because of my nextcloud talk issues. Turns out LDAP is messed up. Even with a manual sync it brings in every user BUT mine...

          girishG Do not disturb
          girishG Do not disturb
          girish
          Staff
          wrote on last edited by
          #3

          @atrilahiji @privsec Did you name the initial admin user as admin or did you give the Cloudron's username? If it's the latter, then the usernames with conflict with LDAP and it won't work.

          ? 1 Reply Last reply
          0
          • girishG girish

            @atrilahiji @privsec Did you name the initial admin user as admin or did you give the Cloudron's username? If it's the latter, then the usernames with conflict with LDAP and it won't work.

            ? Offline
            ? Offline
            A Former User
            wrote on last edited by
            #4

            @girish I made it admin

            1 Reply Last reply
            0
            • jdaviescoatesJ Offline
              jdaviescoatesJ Offline
              jdaviescoates
              wrote on last edited by
              #5

              This still seems to be working fine for me.

              @thetomester13 is a new user on my Cloudron and he managed to login to https://chat.uniteddiversity.coop fine yesterday.

              I use Cloudron with Gandi & Hetzner

              1 Reply Last reply
              1
              • P Offline
                P Offline
                privsec
                wrote on last edited by
                #6

                I just created a brand new user, and had them try to sign in, and its not working. I have my main account for rocket.chat as admin.

                P 1 Reply Last reply
                0
                • P privsec

                  I just created a brand new user, and had them try to sign in, and its not working. I have my main account for rocket.chat as admin.

                  P Offline
                  P Offline
                  privsec
                  wrote on last edited by
                  #7

                  So this is what I see for every combination. The last image is what I have in my user information table in cloudron

                  @privsec 4d026c7d-7b72-487f-9f99-49c8cdfa6351-image.png

                  abcd7a49-4602-4927-bda1-430aee266303-image.png

                  1c3f8ab2-01a1-4901-a07c-40e8c09eaec0-image.png

                  eff577ee-fcdf-4c5d-bf7a-3dcfee4b8b94-image.png

                  P 1 Reply Last reply
                  0
                  • P privsec

                    So this is what I see for every combination. The last image is what I have in my user information table in cloudron

                    @privsec 4d026c7d-7b72-487f-9f99-49c8cdfa6351-image.png

                    abcd7a49-4602-4927-bda1-430aee266303-image.png

                    1c3f8ab2-01a1-4901-a07c-40e8c09eaec0-image.png

                    eff577ee-fcdf-4c5d-bf7a-3dcfee4b8b94-image.png

                    P Offline
                    P Offline
                    privsec
                    wrote on last edited by
                    #8

                    @privsec The only way I can get in is by registering. I have confirmed this to also be true in my osTicket instance

                    It seems my ldap is somehow borked

                    ? 1 Reply Last reply
                    0
                    • P privsec

                      @privsec The only way I can get in is by registering. I have confirmed this to also be true in my osTicket instance

                      It seems my ldap is somehow borked

                      ? Offline
                      ? Offline
                      A Former User
                      wrote on last edited by
                      #9

                      @privsec So it seems like its not just a blanket issue with LDAP. Likely config on those specific apps? Just tried verdaccio and it works just fine.

                      P 1 Reply Last reply
                      0
                      • ? A Former User

                        @privsec So it seems like its not just a blanket issue with LDAP. Likely config on those specific apps? Just tried verdaccio and it works just fine.

                        P Offline
                        P Offline
                        privsec
                        wrote on last edited by
                        #10

                        @atrilahiji Good point. Likely an issue with specific apps config files.

                        ? 1 Reply Last reply
                        0
                        • P privsec

                          @atrilahiji Good point. Likely an issue with specific apps config files.

                          ? Offline
                          ? Offline
                          A Former User
                          wrote on last edited by A Former User
                          #11

                          @privsec Heh I goofed. Should have been obvious. Did you by chance register the admin account using the same email you have for your cloudron admin account? That will cause this issue. It tries to map the email and can't because theres a duplicate.

                          P girishG 2 Replies Last reply
                          0
                          • ? A Former User

                            @privsec Heh I goofed. Should have been obvious. Did you by chance register the admin account using the same email you have for your cloudron admin account? That will cause this issue. It tries to map the email and can't because theres a duplicate.

                            P Offline
                            P Offline
                            privsec
                            wrote on last edited by
                            #12

                            @atrilahiji To be clear, my cloudron sign in email needs to be the same email as my admin account for rocket.chat?

                            Is that the same for all apps?

                            ? 1 Reply Last reply
                            0
                            • P privsec

                              @atrilahiji To be clear, my cloudron sign in email needs to be the same email as my admin account for rocket.chat?

                              Is that the same for all apps?

                              ? Offline
                              ? Offline
                              A Former User
                              wrote on last edited by A Former User
                              #13

                              @privsec No no no. It should not be. Make your initial admin account have an email like admin@local.com (doesn't need to be real) and ensure it has a username that does not match any account pulled in VIA LDAP

                              P 1 Reply Last reply
                              0
                              • ? A Former User

                                @privsec Heh I goofed. Should have been obvious. Did you by chance register the admin account using the same email you have for your cloudron admin account? That will cause this issue. It tries to map the email and can't because theres a duplicate.

                                girishG Do not disturb
                                girishG Do not disturb
                                girish
                                Staff
                                wrote on last edited by girish
                                #14

                                @atrilahiji said in Question about the AD/LDAP integration:

                                It tries to map the email and can't because theres a duplicate

                                Yup, exactly. I actually put the message in the post install dialog but it's easy to miss it. You can also see this text in the top right of the app configure view. In the drop down select, First time setup instructions.

                                0a29cb42-c95f-4ecc-bdbc-81a00892954c-image.png
                                Here it is again:

                                Please follow the following guidelines to complete the Rocket.Chat admin setup:
                                
                                * Use `admin` as the admin username in Rocket.Chat. This will avoid any conflict
                                  with Cloudron usernames.
                                
                                * Use an email address that is different from the Cloudron primary email. This will avoid
                                  any conflict with Cloudron email ids.
                                
                                1 Reply Last reply
                                0
                                • ? A Former User

                                  @privsec No no no. It should not be. Make your initial admin account have an email like admin@local.com (doesn't need to be real) and ensure it has a username that does not match any account pulled in VIA LDAP

                                  P Offline
                                  P Offline
                                  privsec
                                  wrote on last edited by
                                  #15

                                  @atrilahiji Then it is set up correctly.
                                  My admin account is not tied to any real account in cloudron and the email is tied to email account that was created specifically for this app.

                                  girishG 1 Reply Last reply
                                  0
                                  • P privsec

                                    @atrilahiji Then it is set up correctly.
                                    My admin account is not tied to any real account in cloudron and the email is tied to email account that was created specifically for this app.

                                    girishG Do not disturb
                                    girishG Do not disturb
                                    girish
                                    Staff
                                    wrote on last edited by
                                    #16

                                    @privsec In the Access Control section, does it say "User management " or does it say "Dashboard Visibility" ?

                                    c5286e45-1e50-4cef-beb8-9f92c5734b86-image.png

                                    P 1 Reply Last reply
                                    0
                                    • girishG girish

                                      @privsec In the Access Control section, does it say "User management " or does it say "Dashboard Visibility" ?

                                      c5286e45-1e50-4cef-beb8-9f92c5734b86-image.png

                                      P Offline
                                      P Offline
                                      privsec
                                      wrote on last edited by
                                      #17

                                      @girish 8a4093cc-8796-4f55-9a71-ded91a2eb76e-image.png

                                      0598e84c-9637-4467-88a6-4b51f702bb3a-image.png

                                      1 Reply Last reply
                                      0
                                      • P Offline
                                        P Offline
                                        privsec
                                        wrote on last edited by
                                        #18

                                        To be clear, this is how my mailboxes are set up currently5aab4e12-29b4-4d58-ba84-37a323265f93-image.png

                                        This wouldn't be a problem, right? If it is, how do I fix this?

                                        girishG 1 Reply Last reply
                                        0
                                        • P privsec

                                          To be clear, this is how my mailboxes are set up currently5aab4e12-29b4-4d58-ba84-37a323265f93-image.png

                                          This wouldn't be a problem, right? If it is, how do I fix this?

                                          girishG Do not disturb
                                          girishG Do not disturb
                                          girish
                                          Staff
                                          wrote on last edited by
                                          #19

                                          @privsec The cloudron email server and the user email ids are totally separate things (i.e Cloudron LDAP integration point of view). The mailboxes is just local to the Cloudron Email and is not part of the LDAP directory and thus apps have no idea about it.

                                          The email id that apps know about is the one in the Users page. Users can also change this email in their profile page.

                                          This doesn't answer why you are unable to login as testuser though. I am not sure what is happening, can you send us an email on support@cloudron.io, so we can look into this? Our own rocket.chat instance seems to be working fine. I also tried a new local instance and that too works fine.

                                          P 1 Reply Last reply
                                          0
                                          • girishG girish

                                            @privsec The cloudron email server and the user email ids are totally separate things (i.e Cloudron LDAP integration point of view). The mailboxes is just local to the Cloudron Email and is not part of the LDAP directory and thus apps have no idea about it.

                                            The email id that apps know about is the one in the Users page. Users can also change this email in their profile page.

                                            This doesn't answer why you are unable to login as testuser though. I am not sure what is happening, can you send us an email on support@cloudron.io, so we can look into this? Our own rocket.chat instance seems to be working fine. I also tried a new local instance and that too works fine.

                                            P Offline
                                            P Offline
                                            privsec
                                            wrote on last edited by
                                            #20

                                            @girish Yes, I will send an email now

                                            P 1 Reply Last reply
                                            0
                                            Reply
                                            • Reply as topic
                                            Log in to reply
                                            • Oldest to Newest
                                            • Newest to Oldest
                                            • Most Votes


                                              • Login

                                              • Don't have an account? Register

                                              • Login or register to search.
                                              • First post
                                                Last post
                                              0
                                              • Categories
                                              • Recent
                                              • Tags
                                              • Popular
                                              • Bookmarks
                                              • Search