How to configure LDAP for pgadmin.whl

Viewed 2155

Configured according to the instructions https://www.digitalocean.com/community/tutorials/how-to-install-configure-pgadmin4-server-mode-ru When setting up pgadmin.whl I use python3.6 In config_local.py added:

LOG_FILE = '/var/log/pgadmin4/pgadmin4.log'
SQLITE_PATH = '/var/lib/pgadmin4/pgadmin4.db'
SESSION_DB_PATH = '/var/lib/pgadmin4/sessions'
STORAGE_DIR = '/var/lib/pgadmin4/storage'
SERVER_MODE = True
AUTHENTICATION_SOURCES = ['ldap', 'internal']
LDAP_AUTO_CREATE_USER = True
LDAP_CONNECTION_TIMEOUT = 30
LDAP_SERVER_URI =  'ldaps://myldapsserver:636'
LDAP_BASE_DN =  'ou=users,dc=mydc,dc=ru'
LDAP_USERNAME_ATTRIBUTE = 'uid'
LDAP_SEARCH_FILTER = 'uid={0}'

When trying LDAP authorization, I get an error:

2020-05-20 14:29:09,990: ERROR  flask.app:      Error binding to the LDAP server.
Traceback (most recent call last):
  File "/home/administrator/environments/my_env/lib/python3.6/site-packages/pgadmin4/pgadmin/authenticate/ldap.py", line 115, in connect
    auto_bind=True
  File "/home/administrator/environments/my_env/lib/python3.6/site-packages/ldap3/core/connection.py", line 355, in __init__
    self.do_auto_bind()
  File "/home/administrator/environments/my_env/lib/python3.6/site-packages/ldap3/core/connection.py", line 384, in do_auto_bind
    raise LDAPBindError(self.last_error)
ldap3.core.exceptions.LDAPBindError: None

Please tell me how it can be fixed?

1 Answers

I follow https://www.pgadmin.org/docs/pgadmin4/latest/enabling_ldap_authentication.html and it is working for me, with theses parameters :

[root@pg ~]# cat /usr/lib/python3.6/site-packages/pgadmin4-web/config_distro.py
HELP_PATH = '/usr/share/doc/pgadmin4-docs/en_US/html'
UPGRADE_CHECK_ENABLED = False
LOG_FILE = '/var/log/pgadmin4/pgadmin4.log'
SQLITE_PATH = '/var/lib/pgadmin4/pgadmin4.db'
SESSION_DB_PATH = '/var/lib/pgadmin4/sessions'
STORAGE_DIR = '/var/lib/pgadmin4/storage'
AUTHENTICATION_SOURCES = ['ldap', 'internal']
LDAP_AUTO_CREATE_USER = True
LDAP_SERVER_URI = 'ldaps://idm.mydomain.org:636'
LDAP_USERNAME_ATTRIBUTE = 'uid'
LDAP_BASE_DN = 'cn=users,cn=accounts,dc=mydomain,dc=org'
LDAP_SEARCH_FILTER = '(&(objectclass=inetUser)(|(memberOf=cn=developpeurs,cn=groups,cn=accounts,dc=mydomain,dc=org)))'
LDAP_USE_STARTTLS = True
LDAP_CA_CERT_FILE = '/etc/ipa/ca.crt'
LDAP_CERT_FILE = '/etc/pki/tls/certs/http.mydomain.org.crt'
LDAP_KEY_FILE = '/etc/pki/tls/private/http.mydomain.org.key'

And the filter is on the group "developpeurs". After, You can find ldap users into "User Management" into pgadmin4 automatically.

Related