<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
</head>
<body>
Are you actually seeing the < and > characters?<br>
You didn't actually type those into the /opt/zendto/bin/adduser
command, did you?<br>
<br>
Have a read of the AD troubleshooting steps on<br>
<tt> zend.to/activedirectory</tt><br>
<br>
Do you know if you're running with a locally-signed certificate on
your AD servers?<br>
<br>
Assuming you have the hostname and port number (636 usually) of
your AD server, try<br>
<b><tt>openssl s_client -connect your-ad-server.company.com:636</tt></b><br>
<br>
That will show you the initial SSL/TLS handshake involving all the
certificates.<br>
You'll need to Ctrl-C it at the end, but what it prints out should
be very useful so you can see exactly what is using which certs.<br>
<br>
Hope that helps,<br>
Jules.<br>
<br>
<div class="moz-cite-prefix">On 15/07/2020 16:50, Marlon Deerr
wrote:<br>
</div>
<blockquote type="cite"
cite="mid:WM!2cfe276c58174c00a9928bf2c34df7658608e338c2751e3ad3cc2719c793931fa3c0b41ef577f2b59fa5f655dab1d60c!@mx.jul.es"><!-- Template generated by Exclaimer Signature Manager Exchange Edition on 11:50:52 Wednesday, 15 July 2020 -->
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
<style type="text/css">P.ImprintUniqueID {
MARGIN: 0cm 0cm 0pt
}
LI.ImprintUniqueID {
MARGIN: 0cm 0cm 0pt
}
DIV.ImprintUniqueID {
MARGIN: 0cm 0cm 0pt
}
TABLE.ImprintUniqueIDTable {
MARGIN: 0cm 0cm 0pt
}
DIV.Section1 {
page: Section1
}</style>
<meta name="Generator" content="Microsoft Word 15 (filtered
medium)">
<style><!--
/* Font Definitions */
@font-face
{font-family:"Cambria Math";
panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
{font-family:Calibri;
panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
{font-family:Consolas;
panose-1:2 11 6 9 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
{margin:0in;
margin-bottom:.0001pt;
font-size:11.0pt;
font-family:"Calibri",sans-serif;}
a:link, span.MsoHyperlink
{mso-style-priority:99;
color:#0563C1;
text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
{mso-style-priority:99;
color:#954F72;
text-decoration:underline;}
pre
{mso-style-priority:99;
mso-style-link:"HTML Preformatted Char";
margin:0in;
margin-bottom:.0001pt;
font-size:10.0pt;
font-family:"Courier New";}
span.EmailStyle17
{mso-style-type:personal;
font-family:"Calibri",sans-serif;
color:windowtext;}
span.HTMLPreformattedChar
{mso-style-name:"HTML Preformatted Char";
mso-style-priority:99;
mso-style-link:"HTML Preformatted";
font-family:Consolas;}
span.EmailStyle20
{mso-style-type:personal-reply;
font-family:"Calibri",sans-serif;
color:#1F497D;}
.MsoChpDefault
{mso-style-type:export-only;
font-size:10.0pt;}size:8.5in 11.0in;
margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
{page:WordSection1;}</style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
<div class="WordSection1">
<p class="MsoNormal"><span style="color:#1F497D">OK, my user
seems to be unlocked now but now I am getting the following
errors below. I must be missing something else in my setup:<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D">Warning: admin
authorization failed for <username1><o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D">And for other
users I still get the following error:<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D">Warning:
authorization failed for <username2><o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D">Note: I believe
I added <username1> as an admin.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
</div>
<br>
<p class="ImprintUniqueID"><font
style="font-family:Helvetica;font-size:9pt;color:#17365D;font-weight:bold;font-style:normal;">Marlon
Deerr</font>,
<font
style="font-family:Helvetica;font-size:9pt;color:#17365D;font-weight:bold;font-style:normal;">Technology
Manager</font><br>
<font style="font-family:Helvetica;font-size:9pt;color:#17365D;">416-572-8795</font><font
color="#17365d"> <font size="2" face="Helvetica">(direct)</font>
|</font>
<span style="font-family:Helvetica;font-size:9pt;"><a
href="mailto:MDeerr@hshlawyers.com" title="Click to send
email to Marlon Deerr" target=""
style="font-family:Helvetica;font-size:9pt;"
moz-do-not-send="true"><span style="font-family:Helvetica;
font-size:9pt;">MDeerr@hshlawyers.com</span></a></span><br>
<a href="https://www.hshlawyers.com" target=""
moz-do-not-send="true"><img style="border: 0px Solid ; "
src="cid:part2.64CD00BE.E0FA4412@Zend.To" class=""
width="624" height="82"></a>
<table class="ImprintUniqueIDTable" style="HEIGHT: 17px; WIDTH:
80.83%; BORDER-COLLAPSE: collapse" cellspacing="0"
cellpadding="0" border="0">
<tbody>
<tr>
<td style="HEIGHT: 27px; WIDTH: 115px"><a
href="https://www.linkedin.com/company/howie-sacks-&-henry-llp---personal-injury-law/"
target="" moz-do-not-send="true"><img style="border:
0px Solid ; "
src="cid:part4.9FEA066F.8E64326F@Zend.To" class=""
width="24" height="23"></a> <a
href="https://twitter.com/hshlawyers" target=""
moz-do-not-send="true"><img style="border: 0px Solid ;
" src="cid:part6.79AA6B46.9F65BB96@Zend.To" class=""
width="24" height="23"></a> <a
href="https://www.facebook.com/HSHPersonalInjuryLawyers/"
target="" moz-do-not-send="true"><img style="border:
0px Solid ; "
src="cid:part8.20A17235.DA04DADA@Zend.To" class=""
width="24" height="23"></a> <a
href="https://www.youtube.com/user/hshlawyers"
target="" moz-do-not-send="true"><img style="border:
0px Solid ; "
src="cid:part10.3A1E35F8.0F9CAC00@Zend.To" class=""
width="24" height="23"></a></td>
<td style="WIDTH: 471px"><font size="2" face="Helvetica"
color="#002060">3500 - 20 Queen St. W., Toronto, ON
M5H 3R3<br>
</font><font size="2"><font face="Helvetica"><font
color="#002060">Fax: 416-361-0083 | Toll Free:
877-474-5997</font> |
</font></font><span
style="font-family:Helvetica;font-size:10pt;"><a
href="https://www.hshlawyers.com" title="" target=""
style="font-family:Helvetica;font-size:10pt;"
moz-do-not-send="true"><span
style="font-family:Helvetica; font-size:10pt;">www.hshlawyers.com</span></a></span></td>
</tr>
</tbody>
</table>
<br>
</p>
<p class="ImprintUniqueID" style="FONT-SIZE: 9pt; FONT-FAMILY:
Helvetica; FONT-STYLE: normal">
<table class="ImprintUniqueIDTable" style="WIDTH: 100%;
BORDER-COLLAPSE: collapse" cellspacing="0" cellpadding="0"
border="0">
<tbody>
<tr>
<td><font size="1" face="Helvetica" color="#3f3f3f">This
Howie Sacks & Henry e-mail is privileged,
confidential and subject to copyright. Any
unauthorized use or disclosure is prohibited.</font></td>
</tr>
</tbody>
</table>
<br>
<br>
</p>
<div class="WordSection1">
<div>
<div style="border:none;border-top:solid #E1E1E1
1.0pt;padding:3.0pt 0in 0in 0in">
<p class="MsoNormal"><b>From:</b> Jules
[<a class="moz-txt-link-freetext" href="mailto:Jules@Zend.To">mailto:Jules@Zend.To</a>] <br>
<b>Sent:</b> Wednesday, July 15, 2020 7:09 AM<br>
<b>To:</b> ZendTo Users <a class="moz-txt-link-rfc2396E" href="mailto:zendto@zend.to"><zendto@zend.to></a><br>
<b>Cc:</b> Marlon Deerr <a class="moz-txt-link-rfc2396E" href="mailto:MDeerr@hshlawyers.com"><MDeerr@hshlawyers.com></a><br>
<b>Subject:</b> Re: [ZendTo] Authentication Error - The
username or password was incorrect<o:p></o:p></p>
</div>
</div>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal" style="margin-bottom:12.0pt">Marlon,<br>
<br>
The crucial bit in the log is the "locked-out user" bit.<br>
<br>
ZendTo has a security feature in it to stop it being used as a
method of brute-force attacking your accounts from outside.<br>
If the same user has several failed logins in a row, that user
is locked out for the next 24 hours by default.<br>
<br>
If you can login as an admin user, one of the extra admin red
buttons shows you the locked out users and lets you reset
them.<br>
<br>
Alternatively, you can unlock all locked users from the
command line with<br>
/opt/zendto/bin/unlockuser -a<br>
<br>
Cheers,<br>
Jules.<span style="font-size:12.0pt"><o:p></o:p></span></p>
<div>
<p class="MsoNormal">On 14/07/2020 18:45, Marlon Deerr via
ZendTo wrote:<o:p></o:p></p>
</div>
<blockquote style="margin-top:5.0pt;margin-bottom:5.0pt">
<p class="MsoNormal"><span lang="EN-CA">Ok, so I think I
finally (or almost finally) got my AD authentication
settings correct. I have installed the ldapsearch utility
to confirm that I’m able to successful search the OU where
my users reside, however when I attempt to log in with a
valid user, ZendTo keeps erroring with:</span><o:p></o:p></p>
<p class="MsoNormal"><span lang="EN-CA"> </span><o:p></o:p></p>
<p class="MsoNormal"><span lang="EN-CA">Authentication Error</span><o:p></o:p></p>
<p class="MsoNormal"><span lang="EN-CA">The username or
password was incorrect</span><o:p></o:p></p>
<p class="MsoNormal"><span lang="EN-CA"> </span><o:p></o:p></p>
<p class="MsoNormal"><span lang="EN-CA">I checked the
/var/log/zendto/zendto.log and it says the following:</span><o:p></o:p></p>
<p class="MsoNormal"><span lang="EN-CA"> </span><o:p></o:p></p>
<p class="MsoNormal"><span lang="EN-CA">“….Warning:
authorization attempt for locked-out user
<username1></span><o:p></o:p></p>
<p class="MsoNormal"><span lang="EN-CA">Then when I try
logging in as another user, I see the following in the log
</span><o:p></o:p></p>
<p class="MsoNormal"><span lang="EN-CA"> </span><o:p></o:p></p>
<p class="MsoNormal"><span lang="EN-CA">“…Warning:
authorization failed for <username2></span><o:p></o:p></p>
<p class="MsoNormal"><span lang="EN-CA"> </span><o:p></o:p></p>
<p class="MsoNormal"><span lang="EN-CA"> </span><o:p></o:p></p>
<p class="MsoNormal"><span lang="EN-CA"> </span><o:p></o:p></p>
<p class="MsoNormal"><span lang="EN-CA">I know that I have
both username/password correct so I must be missing
something. Anyone know what setting I may have applied
incorrectly?</span><o:p></o:p></p>
<p class="MsoNormal"><span lang="EN-CA"> </span><o:p></o:p></p>
<p class="MsoNormal"><span lang="EN-CA"> </span><o:p></o:p></p>
<p class="MsoNormal"><span
style="font-size:12.0pt;font-family:"Times New
Roman",serif"><br>
<br>
<o:p></o:p></span></p>
<pre>_______________________________________________<o:p></o:p></pre>
<pre>ZendTo mailing list<o:p></o:p></pre>
<pre><a href="mailto:ZendTo@zend.to" moz-do-not-send="true">ZendTo@zend.to</a><o:p></o:p></pre>
<pre><a href="http://jul.es/mailman/listinfo/zendto" moz-do-not-send="true">http://jul.es/mailman/listinfo/zendto</a><o:p></o:p></pre>
</blockquote>
<p class="MsoNormal"><span
style="font-size:12.0pt;font-family:"Times New
Roman",serif"><br>
<br>
<o:p></o:p></span></p>
<pre>Jules<o:p></o:p></pre>
<pre><o:p> </o:p></pre>
<pre>-- <o:p></o:p></pre>
<pre>Julian Field MEng CEng CITP MBCS MIEEE MACM<o:p></o:p></pre>
<pre><o:p> </o:p></pre>
<pre>'When a man points a finger at someone else, he should remember<o:p></o:p></pre>
<pre> that four of his fingers are pointing at himself.' - Louis Nizer<o:p></o:p></pre>
<pre><o:p> </o:p></pre>
<pre><a href="http://www.Zend.To" moz-do-not-send="true">www.Zend.To</a><o:p></o:p></pre>
<pre>Twitter: @JulesFM<o:p></o:p></pre>
</div>
</blockquote>
<br>
<pre class="moz-signature" cols="72">Jules
--
Julian Field MEng CEng CITP MBCS MIEEE MACM
'There is silent poetry in the stillness of morning;
in the calm, the cries & sighs of life sound like gentle music.'
- @Astro_Wheels
<a class="moz-txt-link-abbreviated" href="http://www.Zend.To">www.Zend.To</a>
Twitter: @JulesFM
</pre>
</body>
</html>