Hey Guys, Anybody else have known issues with Kopano anytime throughout 2020-2021? I haven't used it in a long time really, but it worked the last time I tried to login. Here's what I'm seeing in the Kopano server.log:
I'm getting this in the Kopano gateway.log:
I know the user is valid. I've even experimented with another user who has been given Kopano privileges in his user account, although no errors show up in the logs when trying to login with his credentials. My browsers (I've tried several) just revert back to the dalbring username. I don't know where to begin looking other than the logs. All Kopano services are running.
Update: I keep digging and trying. The latest in Kopano's server/log:
Thu Jan 7 12:37:21 2021: [warning] Authentication by plugin failed for user "[email protected]": Trying to authenticate failed: [email protected] not found in LDAP; username = [email protected]
Thu Jan 7 12:44:22 2021: [error ] LDAP search error: Can't contact LDAP server. Will unbind, reconnect and retry.
Thu Jan 7 12:44:34 2021: [warning] Authentication by plugin failed for user "[email protected]": Trying to authenticate failed: [email protected] not found in LDAP; username = [email protected]
Thu Jan 7 12:44:39 2021: [error ] LDAP search error: Can't contact LDAP server. Will unbind, reconnect and retry.
Thu Jan 7 12:44:39 2021: [warning] Authentication by plugin failed for user "[email protected]": Trying to authenticate failed: [email protected] not found in LDAP; username = [email protected]
Thu Jan 7 12:44:41 2021: [error ] LDAP search error: Can't contact LDAP server. Will unbind, reconnect and retry.
Thu Jan 7 12:44:41 2021: [warning] Authentication by plugin failed for user "[email protected]": Trying to authenticate failed: [email protected] not found in LDAP; username = [email protected]
Thu Jan 7 12:44:41 2021: [error ] LDAP search error: Can't contact LDAP server. Will unbind, reconnect and retry.
Thu Jan 7 12:44:41 2021: [warning] Authentication by plugin failed for user "[email protected]": Trying to authenticate failed: [email protected] not found in LDAP; username = [email protected]
Thu Jan 7 12:45:40 2021: [error ] LDAP search error: Can't contact LDAP server. Will unbind, reconnect and retry.
I'm getting this in the Kopano gateway.log:
Thu Jan 7 12:44:34 2021: [error ] HrLogon server "http://localhost:236/" user "[email protected]": logon failed
Thu Jan 7 12:44:34 2021: [warning] Failed to login from [[::ffff:99.32.54.25]:55245] with invalid username "[email protected]" or wrong password: logon failed (80040111)
Thu Jan 7 12:44:39 2021: [error ] HrLogon server "http://localhost:236/" user "[email protected]": logon failed
Thu Jan 7 12:44:39 2021: [warning] Failed to login from [[::ffff:99.32.54.25]:55245] with invalid username "[email protected]" or wrong password: logon failed (80040111)
Thu Jan 7 12:44:41 2021: [error ] HrLogon server "http://localhost:236/" user "[email protected]": logon failed
Thu Jan 7 12:44:41 2021: [warning] Failed to login from [[::ffff:99.32.54.25]:55245] with invalid username "[email protected]" or wrong password: logon failed (80040111)
Thu Jan 7 12:44:41 2021: [error ] HrLogon server "http://localhost:236/" user "[email protected]": logon failed
Thu Jan 7 12:44:41 2021: [warning] Failed to login from [[::ffff:99.32.54.25]:55245] with invalid username "[email protected]" or wrong password: logon failed (80040111)
Thu Jan 7 12:44:41 2021: [error ] HrLogon server "http://localhost:236/" user "[email protected]": logon failed
Thu Jan 7 12:44:41 2021: [warning] Failed to login from [[::ffff:99.32.54.25]:55245] with invalid username "[email protected]" or wrong password: logon failed (80040111)
Thu Jan 7 12:47:49 2021: [error ] Failed to read line: Connection reset by peer
Thu Jan 7 12:48:14 2021: [error ] ECChannel::HrEnableTLS(): SSL_accept failed: 5
Thu Jan 7 12:48:14 2021: [error ] Unable to negotiate SSL connection
I know the user is valid. I've even experimented with another user who has been given Kopano privileges in his user account, although no errors show up in the logs when trying to login with his credentials. My browsers (I've tried several) just revert back to the dalbring username. I don't know where to begin looking other than the logs. All Kopano services are running.
Update: I keep digging and trying. The latest in Kopano's server/log:
Thu Jan 7 14:00:01 2021: [error ] LDAP search error: Can't contact LDAP server. Will unbind, reconnect and retry.
Share this post:
Responses (14)
-
Accepted Answer
-
Accepted Answer
-
Accepted Answer
Hey Nick, thanks for the replies. I'm just getting back to this. Learn2Automate.com was an old domain on an old server. That was probably 10-12 years ago and it doesn't even exist anymore. I don't see it even referenced in what I posted. Are you seeing something on the ClearCenter end that I'm not seeing? I don't think it shows up anywhere in my ClearOS Portal account. It doesn't even show up as an expired domain in my account. The renncoautomation.us server is a totally separate entity having nothing to do with the former.
As far as how I log in, I do use dalbring as a username at the login, not [email protected]. Do you think the system could be appending the domain to the username somewhere? I haven't changed anything in that respect. I would think it has to be somewhere in the postfix or Kopano config since I can login to all other services fine, like Webconfig, MariaDB via phpMyAdmin, etc. Plus Kopano Webapp won't allow any user to login. It remains on the splash page. -
Accepted Answer
I think you have a bigger problem than your username, but I don't know what. Is it just you or all users? It could be an LDAP issue or LDAP settings in Kopano. From /etc/kopano/ldap.cfg, how do your ldap_bind_user and ldap_bind_passwd compare with Bind DN and Bind Password in the directory server app?
As a separate thought, is Apache running OK ("systemctl status httpd")? -
Accepted Answer
I think you have a bigger problem than your username, but I don't know what. Is it just you or all users? It could be an LDAP issue or LDAP settings in Kopano. From /etc/kopano/ldap.cfg, how do your ldap_bind_user and ldap_bind_passwd compare with Bind DN and Bind Password in the directory server app?
I don't have a lot of users, but the ones that I do can't login to the Kopano Webapp. The ldap settings in Kopano's configuration match the directory server's.
As a separate thought, is Apache running OK ("systemctl status httpd")?
No problems with Apache, that I can see anyway.
This morning I rotated my logs to view today's issues only. When trying to login to the Kopano Webapp with a couple different users, the Kopano server.log says:
Wed Jan 20 10:10:06 2021: [warning] Log connection was reset
Wed Jan 20 10:10:57 2021: [error ] LDAP search error: Can't contact LDAP server. Will unbind, reconnect and retry.
Wed Jan 20 10:11:00 2021: [warning] SQL [00016336] info: Try to reconnect
Wed Jan 20 10:12:08 2021: [error ] LDAP search error: Can't contact LDAP server. Will unbind, reconnect and retry.
Wed Jan 20 10:12:08 2021: [error ] Not all objects in relation found for object "sean"
Wed Jan 20 10:12:18 2021: [error ] LDAP search error: Can't contact LDAP server. Will unbind, reconnect and retry.
Wed Jan 20 10:12:53 2021: [error ] Not all objects in relation found for object "sean"
Wed Jan 20 10:13:08 2021: [error ] LDAP search error: Can't contact LDAP server. Will unbind, reconnect and retry.
Do you know when the last update for Kopano on ClearOS came out? I haven't done an update to Kopano in a long time. Maybe an update (if there has been one) would fix any issues? -
Accepted Answer
-
Accepted Answer
-
Accepted Answer
Check out this thread: https://sfj48-fkj200.heiksthsd.cf/clearfoundation/social/community/update-kopano,-webapp-and-z-push
I don't think the mirror sites in your write up are any good. When I try a yum update, having created the repo files as prescribed in your write up and putting my kopano serial number (given to me by ClearCenter) after each instance of "serial:", I get the following:
ailure: repodata/repomd.xml from Kopano-Core: [Errno 256] No more mirrors to try.
https://serial:[email protected]/supported/core:/final/RHEL_7/repodata/repomd.xml: [Errno 14] HTTPS Error 401 - Unauthorized
So either the mirrors are no good or they don't like my serial number. I don't know why that would be since my subscription through ClearCenter is still good and it worked before.
Can you try a "kopano-condrestart" which should restart everything, then have a look at the logs from restart. Is there anything significant?
So I did a logrotate of the kopano logs, then I did a condrestart, then I looked at the kopano logs. The only two logs that were populated were the following:
kopano spooler.log
Thu Jan 28 14:25:37 2021: [warning] [12728] Log connection was reset
Thu Jan 28 14:26:06 2021: [=======] Starting kopano-spooler version 8.7.12.0 (pid 20999 uid 0)
Thu Jan 28 14:26:06 2021: [=======] Starting kopano-spooler version 8.7.12.0 (pid 20999 uid 985)
Thu Jan 28 14:26:06 2021: [error ] [20999] Logon to file:///var/run/kopano/server.sock: Remote side closed connection.
Thu Jan 28 14:26:06 2021: [error ] [20999] HrLogon server "default:" user "SYSTEM": network error
Thu Jan 28 14:26:06 2021: [error ] [20999] Unable to open admin session: network error (80040115)
Thu Jan 28 14:26:06 2021: [warning] [20999] Server connection lost. Reconnecting in 3 seconds...
kopano server.log
Thu Jan 28 14:25:37 2021: [warning] Log connection was reset
Thu Jan 28 14:25:50 2021: [=======] Server shutdown complete.
Thu Jan 28 14:26:05 2021: [=======] Starting kopano-server version 8.7.12.0 (pid 20955 uid 0)
Thu Jan 28 14:26:06 2021: [=======] Starting kopano-server version 8.7.12.0 (pid 20955 uid 985)
Thu Jan 28 14:26:07 2021: [error ] Not all objects in relation found for object "dalbring"
Thu Jan 28 14:26:07 2021: [error ] Not all objects in relation found for object "sean"
Thu Jan 28 14:33:28 2021: [error ] LDAP search error: Can't contact LDAP server. Will unbind, reconnect and retry.
Thu Jan 28 14:33:28 2021: [warning] LDAP (simple) bind on cn=manager,ou=Internal,dc=system,dc=lan failed: Can't contact LDAP server
Thu Jan 28 14:33:29 2021: [warning] K-1502: Unable to retrieve list from external user source: Failure connecting any of the LDAP servers
Thu Jan 28 14:33:32 2021: [error ] LDAP search error: Can't contact LDAP server. Will unbind, reconnect and retry.
Thu Jan 28 14:33:32 2021: [warning] LDAP (simple) bind on cn=manager,ou=Internal,dc=system,dc=lan failed: Can't contact LDAP server
Thu Jan 28 14:33:32 2021: [warning] K-1502: Unable to retrieve list from external user source: Failure connecting any of the LDAP servers
Thu Jan 28 14:33:35 2021: [error ] LDAP search error: Can't contact LDAP server. Will unbind, reconnect and retry.
Thu Jan 28 14:33:35 2021: [warning] LDAP (simple) bind on cn=manager,ou=Internal,dc=system,dc=lan failed: Can't contact LDAP server
Thu Jan 28 14:33:35 2021: [warning] K-1502: Unable to retrieve list from external user source: Failure connecting any of the LDAP servers
Thu Jan 28 14:33:49 2021: [warning] LDAP (simple) bind on cn=manager,ou=Internal,dc=system,dc=lan failed: Can't contact LDAP server
Thu Jan 28 14:33:49 2021: [warning] K-1502: Unable to retrieve list from external user source: Failure connecting any of the LDAP servers
Thu Jan 28 14:33:50 2021: [error ] LDAP search error: Can't contact LDAP server. Will unbind, reconnect and retry. -
Accepted Answer
Have you by any chance set a password policy in the Directory Server app? ( > Policies > Accounts Access)
Accounts Access is "Disabled" in the Webconfig>Directory Server>Policies>Accounts Access field. The "Publish Policy" is set to All Networks - Secure. Could the disabled setting be messing me up, disallowing account access? If so, there are only two choices under Accounts Access. One is Anonymous and the other is Password Access, the latter making you set a password. I'd rather not have to worry about another password. I don't remember why I ever installed the Directory Server app. I might not have even checked Kopano's Webapp after the install. Is the Directory Server app necessary to use Kopano? If not, is it necessary to use any of the other apps on ClearOS? If not, would it hurt to uninstall it?
Upgrade to newer version of Kopano server and Webapp is easy, but i don’t think it will solve your problem.
I don't see where there's any means of upgrading on ClearOS. At least the Devs haven't posted any in the ClearOS repositories, nor are there any forum entries showing how to do that in 2020 or 2021. I would agree it probably wouldn't take care of my issue, which appears to be LDAP related. I think Nick's onto something though. -
Accepted Answer
Upgrade to newer version of Kopano server and Webapp is easy, but i don’t think it will solve your problem.
I don't see where there's any means of upgrading on ClearOS. At least the Devs haven't posted any in the ClearOS repositories, nor are there any forum entries showing how to do that in 2020 or 2021. I would agree it probably wouldn't take care of my issue, which appears to be LDAP related. I think Nick's onto something though.
Check out this thread: https://sfj48-fkj200.heiksthsd.cf/clearfoundation/social/community/update-kopano,-webapp-and-z-push
Be aware that you break the ClearOS updates with this.
I'm currently not using the Kopano updates from COS and following the Kopano repo updates
My versions are currently:
WebApp: 4.6.3.0-155.1
Kopano Core: 8.7.17
Z-Push: 2.6.1+0 -
Accepted Answer
-
Accepted Answer
What happens if you go to
https://serial:[email protected]/supported/core:/final/RHEL_7/x86_64/" target="_blank"> https://serial:[email protected]/supported/core:/final/RHEL_7/x86_64/
You can also check you subscription with Kopano
https://portal.kopano.com/frontpage" target="_blank"> https://portal.kopano.com/frontpage -
Accepted Answer
Patrick, I think you may have hit the nail on the head. When I subscribed to the Kopano portal and entered my license key, it showed it expired last November. Someone at ClearCenter must not have updated my subscription because ClearCenter shows it expires in November of this year. Nick, is that something you can take care of or do I need to put in a ticket?
Update: I put in a ticket, Nick. I'll wait on a reply. -
Accepted Answer
Dirk Albring wrote:
Patrick, I think you may have hit the nail on the head. When I subscribed to the Kopano portal and entered my license key, it showed it expired last November. Someone at ClearCenter must not have updated my subscription because ClearCenter shows it expires in November of this year. Nick, is that something you can take care of or do I need to put in a ticket?
Good. Lets hope this will solve your problem.
My subscription renew is also not renewed automatically, but Nick will contact Taylor
Please login to post a reply
You will need to be logged in to be able to post a reply. Login using the form on the right or register an account if you are new here.
Register Here »