Ausnahme gefangen: SSL certificate problem: certificate is not yet valid ๐Ÿ“Œ ProFTPd + Windows AD (LDAP) - user cant sign-in

๐Ÿ  Team IT Security News

TSecurity.de ist eine Online-Plattform, die sich auf die Bereitstellung von Informationen,alle 15 Minuten neuste Nachrichten, Bildungsressourcen und Dienstleistungen rund um das Thema IT-Sicherheit spezialisiert hat.
Ob es sich um aktuelle Nachrichten, Fachartikel, Blogbeitrรคge, Webinare, Tutorials, oder Tipps & Tricks handelt, TSecurity.de bietet seinen Nutzern einen umfassenden รœberblick รผber die wichtigsten Aspekte der IT-Sicherheit in einer sich stรคndig verรคndernden digitalen Welt.

16.12.2023 - TIP: Wer den Cookie Consent Banner akzeptiert, kann z.B. von Englisch nach Deutsch รผbersetzen, erst Englisch auswรคhlen dann wieder Deutsch!

Google Android Playstore Download Button fรผr Team IT Security



๐Ÿ“š ProFTPd + Windows AD (LDAP) - user cant sign-in


๐Ÿ’ก Newskategorie: Linux Tipps
๐Ÿ”— Quelle: reddit.com

Currently we still have an old FTP server running, and we want to replace the installation (this due to various reasons).

โ€‹

Now I wish to use ProFTPd in combination with LDAP (MS Windows AD).

โ€‹

I have a connection with LDAP working, yet connection (non TLS) keeps getting refused and reccomendations?

Documentation to set this up:

https://warlord0blog.wordpress.com/2018/05/10/proftpd-and-ldap-active-directory/

โ€‹

Idea is that all in the ad-group "FTP-users" should have acces to the FTP server via LDAP (ms AD)

The mod_ldap logs show the following:

2020-01-08 22:37:34,021 mod_ldap/2.9.4[500]: generated filter OU=ad-domain-name-Users,DC=corp,DC=ad-domain-name,DC=xyz from template OU=ad-domain-name-Users,DC=corp,DC=ad-domain-name,DC=xyz and value ftp-user

2020-01-08 22:37:34,021 mod_ldap/2.9.4[500]: generated filter (&(objectClass=user)(sAMAccountName=ftp-user)) from template (&(objectClass=user)(sAMAccountName=%u)) and value ftp-user 2020-01-08 22:37:34,021 mod_ldap/2.9.4[500]: parsed 'ldap://a.b.c.d/??sub' as 'ldap://a.b.c.d:389/??sub' 2020-01-08 22:37:34,021 mod_ldap/2.9.4[500]: attempting connection to URL ldap://a.b.c.d/??sub 2020-01-08 22:37:34,026 mod_ldap/2.9.4[500]: set LDAP protocol version to 3 2020-01-08 22:37:34,026 mod_ldap/2.9.4[500]: connected to URL ldap://a.b.c.d/??sub 2020-01-08 22:37:34,029 mod_ldap/2.9.4[500]: successfully bound as DN 'CN=read-only user,CN=Users,DC=corp,DC=ad-domain-name,DC=xyz' with password (see config) 2020-01-08 22:37:34,030 mod_ldap/2.9.4[500]: set dereferencing to 0 2020-01-08 22:37:34,030 mod_ldap/2.9.4[500]: set query timeout to 5 secs 2020-01-08 22:37:34,031 mod_ldap/2.9.4[500]: searched under base DN OU=ad-domain-name-Users,DC=corp,DC=ad-domain-name,DC=xyz using filter (&(objectClass=user)(sAMAccountName=ftp-user)) 2020-01-08 22:37:34,031 mod_ldap/2.9.4[500]: fetching values for attribute sAMAccountName 2020-01-08 22:37:34,031 mod_ldap/2.9.4[500]: fetching values for attribute uidNumber 2020-01-08 22:37:34,031 mod_ldap/2.9.4[500]: fetching values for attribute gidNumber 2020-01-08 22:37:34,031 mod_ldap/2.9.4[500]: no values for attribute gidNumber, trying defaults 2020-01-08 22:37:34,031 mod_ldap/2.9.4[500]: using LDAPDefaultGID 100 2020-01-08 22:37:34,031 mod_ldap/2.9.4[500]: fetching values for attribute homeDirectory 2020-01-08 22:37:34,031 mod_ldap/2.9.4[500]: no values for attribute homeDirectory, trying defaults 2020-01-08 22:37:34,031 mod_ldap/2.9.4[500]: no homeDirectory attribute for DN CN=FTP USER,OU=ad-domain-name-Users,DC=corp,DC=ad-domain-name,DC=xyz, LDAPGenerateHomedir not enabled 2020-01-08 22:37:34,035 mod_ldap/2.9.4[500]: generated filter OU=ad-domain-name-Users,DC=corp,DC=ad-domain-name,DC=xyz from template OU=ad-domain-name-Users,DC=corp,DC=ad-domain-name,DC=xyz and value ftp-user 2020-01-08 22:37:34,035 mod_ldap/2.9.4[500]: generated filter (&(objectClass=user)(sAMAccountName=ftp-user)) from template (&(objectClass=user)(sAMAccountName=%u)) and value ftp-user 2020-01-08 22:37:34,035 mod_ldap/2.9.4[500]: parsed 'ldap://a.b.c.d/??sub' as 'ldap://a.b.c.d:389/??sub' 2020-01-08 22:37:34,035 mod_ldap/2.9.4[500]: attempting connection to URL ldap://a.b.c.d/??sub 2020-01-08 22:37:34,035 mod_ldap/2.9.4[500]: set LDAP protocol version to 3 2020-01-08 22:37:34,035 mod_ldap/2.9.4[500]: connected to URL ldap://a.b.c.d/??sub 2020-01-08 22:37:34,038 mod_ldap/2.9.4[500]: successfully bound as DN 'CN=read-only user,CN=Users,DC=corp,DC=ad-domain-name,DC=xyz' with password (see config) 2020-01-08 22:37:34,038 mod_ldap/2.9.4[500]: set dereferencing to 0 2020-01-08 22:37:34,038 mod_ldap/2.9.4[500]: set query timeout to 5 secs 2020-01-08 22:37:34,039 mod_ldap/2.9.4[500]: searched under base DN OU=ad-domain-name-Users,DC=corp,DC=ad-domain-name,DC=xyz using filter (&(objectClass=user)(sAMAccountName=ftp-user)) 2020-01-08 22:37:34,039 mod_ldap/2.9.4[500]: fetching values for attribute sAMAccountName 2020-01-08 22:37:34,039 mod_ldap/2.9.4[500]: fetching values for attribute uidNumber 2020-01-08 22:37:34,039 mod_ldap/2.9.4[500]: fetching values for attribute gidNumber 2020-01-08 22:37:34,039 mod_ldap/2.9.4[500]: no values for attribute gidNumber, trying defaults 2020-01-08 22:37:34,039 mod_ldap/2.9.4[500]: using LDAPDefaultGID 100 2020-01-08 22:37:34,039 mod_ldap/2.9.4[500]: fetching values for attribute homeDirectory 2020-01-08 22:37:34,039 mod_ldap/2.9.4[500]: no values for attribute homeDirectory, trying defaults 2020-01-08 22:37:34,039 mod_ldap/2.9.4[500]: no homeDirectory attribute for DN CN=FTP USER,OU=ad-domain-name-Users,DC=corp,DC=ad-domain-name,DC=xyz, LDAPGenerateHomedir not enabled 2020-01-09 11:12:57,545 mod_ldap/2.9.4[682]: generated filter OU=ad-domain-name-Users,DC=corp,DC=ad-domain-name,DC=xyz from template OU=ad-domain-name-Users,DC=corp,DC=ad-domain-name,DC=xyz and value ftp-user 2020-01-09 11:12:57,545 mod_ldap/2.9.4[682]: generated filter (&(objectClass=user)(sAMAccountName=ftp-user)) from template (&(objectClass=user)(sAMAccountName=%u)) and value ftp-user 2020-01-09 11:12:57,545 mod_ldap/2.9.4[682]: parsed 'ldap://a.b.c.d/??sub' as 'ldap://a.b.c.d:389/??sub' 2020-01-09 11:12:57,545 mod_ldap/2.9.4[682]: attempting connection to URL ldap://a.b.c.d/??sub 2020-01-09 11:12:57,570 mod_ldap/2.9.4[682]: set LDAP protocol version to 3 2020-01-09 11:12:57,570 mod_ldap/2.9.4[682]: connected to URL ldap://a.b.c.d/??sub 2020-01-09 11:12:57,573 mod_ldap/2.9.4[682]: successfully bound as DN 'CN=read-only user,CN=Users,DC=corp,DC=ad-domain-name,DC=xyz' with password (see config) 2020-01-09 11:12:57,574 mod_ldap/2.9.4[682]: set dereferencing to 0 2020-01-09 11:12:57,574 mod_ldap/2.9.4[682]: set query timeout to 5 secs 2020-01-09 11:12:57,575 mod_ldap/2.9.4[682]: searched under base DN OU=ad-domain-name-Users,DC=corp,DC=ad-domain-name,DC=xyz using filter (&(objectClass=user)(sAMAccountName=ftp-user)) 2020-01-09 11:12:57,575 mod_ldap/2.9.4[682]: fetching values for attribute sAMAccountName 2020-01-09 11:12:57,575 mod_ldap/2.9.4[682]: fetching values for attribute uidNumber 2020-01-09 11:12:57,575 mod_ldap/2.9.4[682]: fetching values for attribute gidNumber 2020-01-09 11:12:57,575 mod_ldap/2.9.4[682]: no values for attribute gidNumber, trying defaults 2020-01-09 11:12:57,575 mod_ldap/2.9.4[682]: using LDAPDefaultGID 100 2020-01-09 11:12:57,575 mod_ldap/2.9.4[682]: fetching values for attribute homeDirectory 2020-01-09 11:12:57,575 mod_ldap/2.9.4[682]: no values for attribute homeDirectory, trying defaults 2020-01-09 11:12:57,575 mod_ldap/2.9.4[682]: no homeDirectory attribute for DN CN=FTP USER,OU=ad-domain-name-Users,DC=corp,DC=ad-domain-name,DC=xyz, LDAPGenerateHomedir not enabled 2020-01-09 11:12:57,577 mod_ldap/2.9.4[682]: generated filter OU=ad-domain-name-Users,DC=corp,DC=ad-domain-name,DC=xyz from template OU=ad-domain-name-Users,DC=corp,DC=ad-domain-name,DC=xyz and value ftp-user 2020-01-09 11:12:57,577 mod_ldap/2.9.4[682]: generated filter (&(objectClass=user)(sAMAccountName=ftp-user)) from template (&(objectClass=user)(sAMAccountName=%u)) and value ftp-user 2020-01-09 11:12:57,577 mod_ldap/2.9.4[682]: parsed 'ldap://a.b.c.d/??sub' as 'ldap://a.b.c.d:389/??sub' 2020-01-09 11:12:57,577 mod_ldap/2.9.4[682]: attempting connection to URL ldap://a.b.c.d/??sub 2020-01-09 11:12:57,577 mod_ldap/2.9.4[682]: set LDAP protocol version to 3 2020-01-09 11:12:57,577 mod_ldap/2.9.4[682]: connected to URL ldap://a.b.c.d/??sub 2020-01-09 11:12:57,580 mod_ldap/2.9.4[682]: successfully bound as DN 'CN=read-only user,CN=Users,DC=corp,DC=ad-domain-name,DC=xyz' with password (see config) 2020-01-09 11:12:57,580 mod_ldap/2.9.4[682]: set dereferencing to 0 2020-01-09 11:12:57,580 mod_ldap/2.9.4[682]: set query timeout to 5 secs 2020-01-09 11:12:57,581 mod_ldap/2.9.4[682]: searched under base DN OU=ad-domain-name-Users,DC=corp,DC=ad-domain-name,DC=xyz using filter (&(objectClass=user)(sAMAccountName=ftp-user)) 2020-01-09 11:12:57,581 mod_ldap/2.9.4[682]: fetching values for attribute sAMAccountName 2020-01-09 11:12:57,581 mod_ldap/2.9.4[682]: fetching values for attribute uidNumber 2020-01-09 11:12:57,581 mod_ldap/2.9.4[682]: fetching values for attribute gidNumber 2020-01-09 11:12:57,581 mod_ldap/2.9.4[682]: no values for attribute gidNumber, trying defaults 2020-01-09 11:12:57,581 mod_ldap/2.9.4[682]: using LDAPDefaultGID 100 2020-01-09 11:12:57,581 mod_ldap/2.9.4[682]: fetching values for attribute homeDirectory 2020-01-09 11:12:57,581 mod_ldap/2.9.4[682]: no values for attribute homeDirectory, trying defaults 2020-01-09 11:12:57,581 mod_ldap/2.9.4[682]: no homeDirectory attribute for DN CN=FTP USER,OU=ad-domain-name-Users,DC=corp,DC=ad-domain-name,DC=xyz, LDAPGenerateHomedir not enabled 
submitted by /u/dutch2005
[link] [comments] ...



๐Ÿ“Œ PHP up to 5.6.35/7.0.29/7.1.16/7.2.4 LDAP Server ext/ldap/ldap.c ldap_get_dn denial of service


๐Ÿ“ˆ 39.17 Punkte

๐Ÿ“Œ Traccar GPS Tracking System up to 4.8 LDAP Search Filter LDAP injection ldap injection


๐Ÿ“ˆ 39.17 Punkte

๐Ÿ“Œ Because You Cant Run, You Cant Hide: Some Musings on API Design || James Powell


๐Ÿ“ˆ 39.15 Punkte

๐Ÿ“Œ Groovy LDAP API LDAP.java returnObjFlag erweiterte Rechte


๐Ÿ“ˆ 26.11 Punkte

๐Ÿ“Œ Groovy LDAP API LDAP.java returnObjFlag erweiterte Rechte


๐Ÿ“ˆ 26.11 Punkte

๐Ÿ“Œ Dokeos up to 1.6.4 LDAP ldap.inc.php claro_CasLibPath privilege escalation


๐Ÿ“ˆ 26.11 Punkte

๐Ÿ“Œ Groovy LDAP API LDAP.java returnObjFlag privilege escalation


๐Ÿ“ˆ 26.11 Punkte

๐Ÿ“Œ Debian nss-ldap up to 0.6.7 LDAP Server Cleartext information disclosure


๐Ÿ“ˆ 26.11 Punkte

๐Ÿ“Œ Huawei TE60/ViewPoint 9030 LDAP Server LDAP Connection Resource Exhaustion denial of service


๐Ÿ“ˆ 26.11 Punkte

๐Ÿ“Œ 389-ds-base up to 1.3.6.12/1.3.7.8/1.4.0.4 LDAP Search Filter LDAP Request Stack-based denial of service


๐Ÿ“ˆ 26.11 Punkte

๐Ÿ“Œ 389-ds-base 1.4.x LDAP Search Filter LDAP Request Out-of-Bounds denial of service


๐Ÿ“ˆ 26.11 Punkte

๐Ÿ“Œ LDAP-Signierung und LDAP Channel Binding fรผr Domรคnencontroller


๐Ÿ“ˆ 26.11 Punkte

๐Ÿ“Œ NixOS bis 17.03 LDAP /etc/ldap.conf schwache Verschlรผsselung


๐Ÿ“ˆ 26.11 Punkte

๐Ÿ“Œ OneDev up to 4.4.1 LDAP External Authentication ldap injection


๐Ÿ“ˆ 26.11 Punkte

๐Ÿ“Œ CVE-2017-11501 | NixOS up to 17.03 LDAP /etc/ldap.conf certificate validation (ID 27506)


๐Ÿ“ˆ 26.11 Punkte

๐Ÿ“Œ CVE-2022-45046 | Apache Camel up to 3.14.5/3.18.3 camel-ldap ldap injection


๐Ÿ“ˆ 26.11 Punkte

๐Ÿ“Œ 389-ds-base bis 1.3.6.12/1.3.7.8/1.4.0.4 LDAP Search Filter LDAP Request Stack-based Denial of Service


๐Ÿ“ˆ 26.11 Punkte

๐Ÿ“Œ CVE-2023-23749 | LDAP Integration with Active Directory and OpenLDAP - NTLM & Kerberos Login Extension ldap injection


๐Ÿ“ˆ 26.11 Punkte

๐Ÿ“Œ CVE-2023-29050 | Open-Xchange OX App Suite up to 7.10.6-rev50/8.16 LDAP Contacts Provider ldap injection (oxas-adv-2023-0005)


๐Ÿ“ˆ 26.11 Punkte

๐Ÿ“Œ 389-ds-base 1.4.x LDAP Search Filter LDAP Request Out-of-Bounds Denial of Service


๐Ÿ“ˆ 26.11 Punkte

๐Ÿ“Œ heise+ | Single Sign-on fรผr SSH mit LDAP und Kerberos einrichten


๐Ÿ“ˆ 23.42 Punkte

๐Ÿ“Œ heise-Angebot: iX-Workshop: Single Sign-on mit Kerberos, LDAP und Active Directory


๐Ÿ“ˆ 23.42 Punkte

๐Ÿ“Œ heise-Angebot: iX-Workshop: Single Sign-on mit Kerberos, LDAP und AD (Last Call)


๐Ÿ“ˆ 23.42 Punkte

๐Ÿ“Œ Does anyone know how to fixthis? Im trying to access windows, but once i click on windows this pops up so i cant get in


๐Ÿ“ˆ 23.31 Punkte

๐Ÿ“Œ Cant boot windows installer, only linux installer on laptop. what gives?


๐Ÿ“ˆ 21.44 Punkte

๐Ÿ“Œ How to Solve โ€œThis app cant open error message in Windows Issueโ€?


๐Ÿ“ˆ 21.44 Punkte

๐Ÿ“Œ Cant access windows since i install Linux Mint.


๐Ÿ“ˆ 21.44 Punkte

๐Ÿ“Œ Help: I accidentally formatted EFI partition cant boot into windows.


๐Ÿ“ˆ 21.44 Punkte

๐Ÿ“Œ One tap sign-up and automatic sign-in without password entry using Smart Lock


๐Ÿ“ˆ 20.73 Punkte











matomo