By: Itay Malka user 25 Oct 2021 at 6:25 a.m. CDT

15 Responses
Itay Malka gravatar
Hi, After setting up LDAP on a GLUU server We get an error login.errorSessionInvalidMessage Log we see the error 2021-10-25 13: 42: 16,521 ERROR [qtp1224347463-17411] [gluu.oxauth.authorize.ws.rs.AuthorizeAction] (AuthorizeAction.java:285) - Failed to get CustomScriptConfiguration. auth_step: 1, acr_values: simple_password_auth Can help please help? Regards

By Mohib Zico staff 25 Oct 2021 at 6:54 a.m. CDT

Mohib Zico gravatar
@Mobarak Hosen.Shakil: let's test this situation. - Connect a simple SAML SP with 4.3 - Try to SSO, see what happens. - If we get above situation what Itay stated: - Enable 'auth_ldap_server' from Manage Authentication - Select 'auth_ldap_server' for both oxTrust and oxAuth Default Authentication Method. Hit "Save" - Try SSO again.

By Itay Malka user 26 Oct 2021 at 12:29 a.m. CDT

Itay Malka gravatar
Hi, Does anyone have an answer please? Regards Itay

By Mobarak Hosen Shakil staff 26 Oct 2021 at 8:41 a.m. CDT

Mobarak Hosen Shakil gravatar
Hi Itay Malka, I'm working on it. I will give an update soon. Regards ~ Shakil

By Mobarak Hosen Shakil staff 26 Oct 2021 at 12:10 p.m. CDT

Mobarak Hosen Shakil gravatar
Hi, I have tested both authentication method of `simple_password_auth` and `auth_ldap_server` with SAML SSO. Both are worked fine. Can you please try to log in `incognito` mode? Regards ~ Shakil

By Itay Malka user 27 Oct 2021 at 1:05 a.m. CDT

Itay Malka gravatar
Hi, I checked it, I get the same error An unexpected error has occurred at null login.errorSessionInvalidMessage Regards Itay

By Mohib Zico staff 27 Oct 2021 at 1:20 a.m. CDT

Mohib Zico gravatar
Hello Itay, Let's try [this](https://support.gluu.org/cache-refresh/10047/loginerrorsessioninvalidmessage/#at72815). If that doesn't work, please record a screencast of above configurations and show us when you get that error message ( full workflow ). Thanks!

By Itay Malka user 27 Oct 2021 at 3:02 a.m. CDT

Itay Malka gravatar
Hi, At the moment all possibilities are blocked for me on the WEB. Can you please write down step by step how I make the change? Regards Itay

By Mobarak Hosen Shakil staff 27 Oct 2021 at 11:02 a.m. CDT

Mobarak Hosen Shakil gravatar
Please check out this link: https://gluu.org/docs/gluu-server/4.3/operation/faq/#manual-method and try to change the authentication method to `simple_password_auth`. Regards ~ Shakil

By Itay Malka user 28 Oct 2021 at 3:08 a.m. CDT

Itay Malka gravatar
Hi, We have done what the process sent successfully, But still get the same error This is the command we sent opt / opendj / bin / ldapmodify -h localhost -p 1636 -Z -X -D "cn = directory manager" -w "****" -f restore_access_to_gluu_ldap_opendj.txt Processing MODIFY request for ou = configuration, o = gluu MODIFY operation successful for DN ou = configuration, o = gluu We get the same error An unexpected error has occurred at null login.errorSessionInvalidMessage Regards

By Mobarak Hosen Shakil staff 28 Oct 2021 at 6:23 a.m. CDT

Mobarak Hosen Shakil gravatar
Please record a screencast and share with us to find out exact issue. > https://support.gluu.org/cache-refresh/10047/loginerrorsessioninvalidmessage/#at72873 Regards ~ Shakil

By Itay Malka user 28 Oct 2021 at 7:12 a.m. CDT

Itay Malka gravatar
Hi, We have restarted the server and now the GUI is not working. There is no error in the LOG. Can I have some help please? Regards

By Mobarak Hosen Shakil staff 28 Oct 2021 at 10:16 a.m. CDT

Mobarak Hosen Shakil gravatar
Can you please share the process you have followed during LDAP setup? If you think everything is stucked, I would like to suggest you to do a fresh installation. Regards ~ Shakil

By Itay Malka user 31 Oct 2021 at 2:39 a.m. CDT

Itay Malka gravatar
Hi, We are trying to connect to openLdap / opt / opendj / bin / ldapsearch -h 127.0.0.1 -p 1636 -Z -X -D 'cn = directory manager, o = gluu' -b 'ou = oxtrust, ou = configuration, o = gluu' -s base "objectClass = *" -w '******' And get an error: The LDAP search request failed: 53 (Unwilling to Perform) Additional Information: Unable to process the simple bind request because it contained a bind DN but no password, which is forbidden by the server configuration Can anyone help please? Regards

By Itay Malka user 31 Oct 2021 at 6:29 a.m. CDT

Itay Malka gravatar
Hi, We were able to reach ldapsearch We did all the steps and we still get the same error Attached here are the steps we did: ``` 1. / opt / opendj / bin / ldapmodify -h localhost -p 1636 -Z -X -D "cn = directory manager" -w **** -f restore_access_to_gluu_ldap_opendj.txt the file content dn: ou = configuration, o = gluu changetype: modify replace: oxTrustAuthenticationMode oxTrustAuthenticationMode: simple_password_auth ``` ``` 2. / opt / opendj / bin / ldapsearch -h 127.0.0.1 -p 1636 -Z -X -D 'cn = directory manager' -w .... -b 'ou = configuration, o = gluu' -s base "objectClass = *" dn: ou = configuration, o = gluu gluuFederationHostingEnabled: disabled gluuHTTPstatus: false gluuHostname: gal3.cc.huji.ac.il gluuLastUpdate: 20211031111123.585Z gluuManageIdentityPermission: true gluuMaxLogSize: 200 gluuOrgProfileMgt: false gluuPassportEnabled: true gluuRadiusEnabled: true gluuSamlEnabled: true gluuScimEnabled: true gluuSslExpiry: 351 gluuVdsCacheRefreshEnabled: true gluuVdsCacheRefreshPollingInterval: 1 gluuWhitePagesEnabled: disabled objectClass: gluuConfiguration objectClass: top ou: configuration oxAuthenticationMode: simple_password_auth oxCacheConfiguration: {"cacheProviderType": "NATIVE_PERSISTENCE", "memcachedConfiguration": {"servers": "localhost: 11211", "maxOperationQueueLength": 100000, "bufferSize": 32768, "defaultPutExpiration": 60, "connectionFactory" " "}," inMemoryConfiguration ": {" defaultPutExpiration ": 60}," redisConfiguration ": {" redisProviderType ":" STANDALONE "," servers ":" localhost: 6379 "," defaultPutExpiration ": 60," sentinelMasterGroupName ":" , "password": null, "useSSL": false, "sslTrustStoreFilePath": "", "maxIdleConnections": 10, "maxTotalConnections": 500, "connectionTimeout": 3000, "soTimeout": 3000, "maxRetryAttempts": 5} , "nativePersistenceConfiguration": {"defaultPutExpiration": 60, "defaultCleanupBatchSize": 10000, "deleteExpiredOnGetRequest": false}} oxDocumentStoreConfiguration: {"documentStoreType": "LOCAL", "localConfiguration": {"baseLocation": "/"}, "jcaConfiguration": {"serverUrl": "http: // localhost: 8080 / rmi", "workspaceName": "default", "connectionTimeout": 15, "userId": "admin", "password": ""}, "webDavConfiguration": null} oxIDPAuthentication: {"type": "auth", "name": "auth_ldap_server", "level": 0, "priority": 0, "enabled": true, "version": 1, "fields": [], "config": {"configId": "auth_ldap_server", "bindDN": "cn = directory manager", "bindPassword": "cgUtvJSaWHzy / m9AzJAI / Q ==", "servers": ["localhost: 1636"], "maxConnections": 1000, "useSSL": true, "baseDNs": ["ou = people, o = gluu"], "primaryKey": "uid", "localPrimaryKey": "uid", "useAnonymousBind": false, "enabled": true, "version": 0, "level": 0}} oxLogViewerConfig: {"log_template": [{"value1": "oxAuth logs", "value2": "/ opt / gluu / jetty / oxauth / logs / *. log", "hide": false, "description": " "}, {" value1 ":" oxTrust logs "," value2 ":" / opt / gluu / jetty / identity / logs / *. log "," hide ": false," description ":" "}]} oxTrustAuthenticationMode: simple_password_auth oxTrustCacheRefreshServerIpAddress: ******** oxTrustStoreConf: {"useJreCertificates": true} passwordResetAllowed: false ``` 3. OOPS An unexpected error has occurred at null login.errorSessionInvalidMessage Error from: /opt/gluu/jetty/oxauth/logs/2021_10_31.jetty.log ``` 2021-10-31 13: 09: 41,647 ERROR [qtp1224347463-10170] [gluu.oxauth.authorize.ws.rs.AuthorizeAction] (AuthorizeAction.java:285) - Failed to get CustomScriptConfiguration. auth_step: 1, acr_values: simple_password_auth ``` Can help please?

By Mohib Zico staff 31 Oct 2021 at 7:09 a.m. CDT

Mohib Zico gravatar
Record a [screencast](https://support.gluu.org/cache-refresh/10047/loginerrorsessioninvalidmessage/#at72873) please.