<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">
<channel>
	<title>Comments for Ryan Lane's Blog</title>
	
	<link>http://ryandlane.com/blog</link>
	<description />
	<lastBuildDate>Thu, 22 Dec 2011 19:36:12 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
	<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/CommentsForRyanLanesBlog" /><feedburner:info uri="commentsforryanlanesblog" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><item>
		<title>Comment on A process for puppetization of a service using Nova by Newsletter – December 2011 | Puppet Labs</title>
		<link>http://feedproxy.google.com/~r/CommentsForRyanLanesBlog/~3/lQQzdTTgOY8/</link>
		<dc:creator>Newsletter – December 2011 | Puppet Labs</dc:creator>
		<pubDate>Thu, 22 Dec 2011 19:36:12 +0000</pubDate>
		<guid isPermaLink="false">http://ryandlane.com/blog/?p=490#comment-4029</guid>
		<description>[...] OpenStack: Puppetization of a Service using Nova Ryan Lane shows you how. [...]</description>
		<content:encoded><![CDATA[<p>[...] OpenStack: Puppetization of a Service using Nova Ryan Lane shows you how. [...]</p>
<img src="http://feeds.feedburner.com/~r/CommentsForRyanLanesBlog/~4/lQQzdTTgOY8" height="1" width="1"/>]]></content:encoded>
	<feedburner:origLink>http://ryandlane.com/blog/2011/11/02/a-process-for-puppetization-of-a-service-using-nova/comment-page-1/#comment-4029</feedburner:origLink></item>
	<item>
		<title>Comment on Sharing home directories to instances within a project using puppet, LDAP, autofs, and Nova by Wikimedia blog » Wikimedia engineering November 2011 report</title>
		<link>http://feedproxy.google.com/~r/CommentsForRyanLanesBlog/~3/vxWtmkljhrY/</link>
		<dc:creator>Wikimedia blog » Wikimedia engineering November 2011 report</dc:creator>
		<pubDate>Fri, 02 Dec 2011 13:23:25 +0000</pubDate>
		<guid isPermaLink="false">http://ryandlane.com/blog/?p=482#comment-3982</guid>
		<description>[...] was also added for instances: project members now have sudo permissions, excluding global projects. Shared home directories are also available in a per project manner. 15 projects and 36 instances have been created and 46 [...]</description>
		<content:encoded><![CDATA[<p>[...] was also added for instances: project members now have sudo permissions, excluding global projects. Shared home directories are also available in a per project manner. 15 projects and 36 instances have been created and 46 [...]</p>
<img src="http://feeds.feedburner.com/~r/CommentsForRyanLanesBlog/~4/vxWtmkljhrY" height="1" width="1"/>]]></content:encoded>
	<feedburner:origLink>http://ryandlane.com/blog/2011/11/01/sharing-home-directories-to-instances-within-a-project-using-puppet-ldap-autofs-and-nova/comment-page-1/#comment-3982</feedburner:origLink></item>
	<item>
		<title>Comment on Sharing home directories to instances within a project using puppet, LDAP, autofs, and Nova by Community Weekly Review (Oct 28-Nov 4) » The OpenStack Blog</title>
		<link>http://feedproxy.google.com/~r/CommentsForRyanLanesBlog/~3/micNa7g2k2A/</link>
		<dc:creator>Community Weekly Review (Oct 28-Nov 4) » The OpenStack Blog</dc:creator>
		<pubDate>Fri, 04 Nov 2011 21:22:55 +0000</pubDate>
		<guid isPermaLink="false">http://ryandlane.com/blog/?p=482#comment-3920</guid>
		<description>[...] Sharing home directories to instances within a project using puppet, LDAP, autofs, and Nova http://ryandlane.com/blog/2011/11/01/sharing-home-directories-to-instances-within-a-project-using-pu... [...]</description>
		<content:encoded><![CDATA[<p>[...] Sharing home directories to instances within a project using puppet, LDAP, autofs, and Nova <a href="http://ryandlane.com/blog/2011/11/01/sharing-home-directories-to-instances-within-a-project-using-pu.." rel="nofollow">http://ryandlane.com/blog/2011/11/01/sharing-home-directories-to-instances-within-a-project-using-pu..</a>. [...]</p>
<img src="http://feeds.feedburner.com/~r/CommentsForRyanLanesBlog/~4/micNa7g2k2A" height="1" width="1"/>]]></content:encoded>
	<feedburner:origLink>http://ryandlane.com/blog/2011/11/01/sharing-home-directories-to-instances-within-a-project-using-puppet-ldap-autofs-and-nova/comment-page-1/#comment-3920</feedburner:origLink></item>
	<item>
		<title>Comment on Configuring a local environment for dealing with git by Ryan Lane</title>
		<link>http://feedproxy.google.com/~r/CommentsForRyanLanesBlog/~3/WxSMEQ5U6bQ/</link>
		<dc:creator>Ryan Lane</dc:creator>
		<pubDate>Thu, 03 Nov 2011 17:57:31 +0000</pubDate>
		<guid isPermaLink="false">http://ryandlane.com/blog/?p=453#comment-3915</guid>
		<description>Glad I could help ;)</description>
		<content:encoded><![CDATA[<p>Glad I could help ;)</p>
<img src="http://feeds.feedburner.com/~r/CommentsForRyanLanesBlog/~4/WxSMEQ5U6bQ" height="1" width="1"/>]]></content:encoded>
	<feedburner:origLink>http://ryandlane.com/blog/2011/09/23/configuring-a-local-environment-for-dealing-with-git/comment-page-1/#comment-3915</feedburner:origLink></item>
	<item>
		<title>Comment on Configuring a local environment for dealing with git by Roan Kattouw</title>
		<link>http://feedproxy.google.com/~r/CommentsForRyanLanesBlog/~3/G8k8XrLIa9g/</link>
		<dc:creator>Roan Kattouw</dc:creator>
		<pubDate>Thu, 03 Nov 2011 15:31:14 +0000</pubDate>
		<guid isPermaLink="false">http://ryandlane.com/blog/?p=453#comment-3914</guid>
		<description>This is very useful, thanks!

I had already set up working directories as screen window titles as an extension of one of your previous blog posts ( http://ryandlane.com/blog/2011/03/23/screen-with-ssh-on-a-shell-server/ ; I've also gotten vi/vim/view to display the file being edited as the screen window title) but could never quite get that to work reliably. PROMPT_COMMAND (which I didn't know about before) definitely helped there.</description>
		<content:encoded><![CDATA[<p>This is very useful, thanks!</p>
<p>I had already set up working directories as screen window titles as an extension of one of your previous blog posts ( <a href="http://ryandlane.com/blog/2011/03/23/screen-with-ssh-on-a-shell-server/" rel="nofollow">http://ryandlane.com/blog/2011/03/23/screen-with-ssh-on-a-shell-server/</a> ; I&#8217;ve also gotten vi/vim/view to display the file being edited as the screen window title) but could never quite get that to work reliably. PROMPT_COMMAND (which I didn&#8217;t know about before) definitely helped there.</p>
<img src="http://feeds.feedburner.com/~r/CommentsForRyanLanesBlog/~4/G8k8XrLIa9g" height="1" width="1"/>]]></content:encoded>
	<feedburner:origLink>http://ryandlane.com/blog/2011/09/23/configuring-a-local-environment-for-dealing-with-git/comment-page-1/#comment-3914</feedburner:origLink></item>
	<item>
		<title>Comment on Building a test and development infrastructure using OpenStack by Sharing home directories to instances within a project using puppet, LDAP, autofs, and Nova | Ryan Lane's Blog</title>
		<link>http://feedproxy.google.com/~r/CommentsForRyanLanesBlog/~3/PIGBQHL1uPQ/</link>
		<dc:creator>Sharing home directories to instances within a project using puppet, LDAP, autofs, and Nova | Ryan Lane's Blog</dc:creator>
		<pubDate>Tue, 01 Nov 2011 17:49:16 +0000</pubDate>
		<guid isPermaLink="false">http://ryandlane.com/blog/?p=394#comment-3909</guid>
		<description>[...] mentioned in an older post, I’m building a test and development environment using OpenStack. The environment is intended [...]</description>
		<content:encoded><![CDATA[<p>[...] mentioned in an older post, I&#8217;m building a test and development environment using OpenStack. The environment is intended [...]</p>
<img src="http://feeds.feedburner.com/~r/CommentsForRyanLanesBlog/~4/PIGBQHL1uPQ" height="1" width="1"/>]]></content:encoded>
	<feedburner:origLink>http://ryandlane.com/blog/2011/01/02/building-a-test-and-development-infrastructure-using-openstack/comment-page-1/#comment-3909</feedburner:origLink></item>
	<item>
		<title>Comment on Screen with SSH on a Shell Server by IRC caused me to use Linux! Quick how to setup a shell server. | Linux Admins</title>
		<link>http://feedproxy.google.com/~r/CommentsForRyanLanesBlog/~3/ZvmF-Y_H-g0/</link>
		<dc:creator>IRC caused me to use Linux! Quick how to setup a shell server. | Linux Admins</dc:creator>
		<pubDate>Tue, 18 Oct 2011 00:08:32 +0000</pubDate>
		<guid isPermaLink="false">http://ryandlane.com/blog/?p=422#comment-3891</guid>
		<description>[...] easy how to on how to setup a shell server quickly. I hope you learned something or found it useful!Years ago back in the day as they say I was constantly on IRC! I was told try Linux to run several s...might have been Slackware 6! That is what sticks out in the the mind... I setup a shell server today [...]</description>
		<content:encoded><![CDATA[<p>[...] easy how to on how to setup a shell server quickly. I hope you learned something or found it useful!Years ago back in the day as they say I was constantly on IRC! I was told try Linux to run several s&#8230;might have been Slackware 6! That is what sticks out in the the mind&#8230; I setup a shell server today [...]</p>
<img src="http://feeds.feedburner.com/~r/CommentsForRyanLanesBlog/~4/ZvmF-Y_H-g0" height="1" width="1"/>]]></content:encoded>
	<feedburner:origLink>http://ryandlane.com/blog/2011/03/23/screen-with-ssh-on-a-shell-server/comment-page-1/#comment-3891</feedburner:origLink></item>
	<item>
		<title>Comment on Using the LDAP Authentication Plugin for MediaWiki – The Basics (Part 1) by Jeff B</title>
		<link>http://feedproxy.google.com/~r/CommentsForRyanLanesBlog/~3/JzPm7c-lN54/</link>
		<dc:creator>Jeff B</dc:creator>
		<pubDate>Fri, 14 Oct 2011 20:46:41 +0000</pubDate>
		<guid isPermaLink="false">http://ryandlane.com/wprdl/?p=41#comment-3887</guid>
		<description>I just wanted to say thank you for everyone's comments.  You guys helped me out so much.
I just wanted a small wiki my small team of IT guys could us in our intranet.

My Setup:
I was running Mediawiki on a Windows 2008 computer using Wamp, trying to connect to a 2008 AD.  I could get it to connect, but only using clear passwords.  I was able to later do a work around by putting in the line 
TLS_REQCERT never
in my ldap.conf file in c:\openldap\sysconf.  

But I needed better, the likelihood that we would get a MitM, or a DNS hijack is slim, but I still couldn't sleep well unless I got the certificates working.

My fix was not to use openssl to pull the certificate off the server using -

"openssl s_client -connect adserver1.testad.example.com:636"

Instead what I had to do was install Active Directory Certificate Services on my DC.  Then follow this website to make a self signed cert - very easy to follow.
http://www.christowles.com/2010/11/enable-ldap-over-ssl-ldaps-on-windows.html

Once I had a certificate I exported the certificate as a .cer file to my wamp server inside my c:\openldap\sysconf folder and edited the ldap.conf file to TLS_CACERT c:\openldap\sysconf\dc1.cer

SSL now works!  Seriously this all took me several days just gathering all the right info and troubleshooting.  That last little bit saved me.  active directory doesn't support ssl out of the box.  No wonder it wasn't working.</description>
		<content:encoded><![CDATA[<p>I just wanted to say thank you for everyone&#8217;s comments.  You guys helped me out so much.<br />
I just wanted a small wiki my small team of IT guys could us in our intranet.</p>
<p>My Setup:<br />
I was running Mediawiki on a Windows 2008 computer using Wamp, trying to connect to a 2008 AD.  I could get it to connect, but only using clear passwords.  I was able to later do a work around by putting in the line<br />
TLS_REQCERT never<br />
in my ldap.conf file in c:\openldap\sysconf.  </p>
<p>But I needed better, the likelihood that we would get a MitM, or a DNS hijack is slim, but I still couldn&#8217;t sleep well unless I got the certificates working.</p>
<p>My fix was not to use openssl to pull the certificate off the server using -</p>
<p>&#8220;openssl s_client -connect adserver1.testad.example.com:636&#8243;</p>
<p>Instead what I had to do was install Active Directory Certificate Services on my DC.  Then follow this website to make a self signed cert &#8211; very easy to follow.<br />
<a href="http://www.christowles.com/2010/11/enable-ldap-over-ssl-ldaps-on-windows.html" rel="nofollow">http://www.christowles.com/2010/11/enable-ldap-over-ssl-ldaps-on-windows.html</a></p>
<p>Once I had a certificate I exported the certificate as a .cer file to my wamp server inside my c:\openldap\sysconf folder and edited the ldap.conf file to TLS_CACERT c:\openldap\sysconf\dc1.cer</p>
<p>SSL now works!  Seriously this all took me several days just gathering all the right info and troubleshooting.  That last little bit saved me.  active directory doesn&#8217;t support ssl out of the box.  No wonder it wasn&#8217;t working.</p>
<img src="http://feeds.feedburner.com/~r/CommentsForRyanLanesBlog/~4/JzPm7c-lN54" height="1" width="1"/>]]></content:encoded>
	<feedburner:origLink>http://ryandlane.com/blog/2009/03/23/using-the-ldap-authentication-plugin-for-mediawiki-the-basics-part-1/comment-page-1/#comment-3887</feedburner:origLink></item>
	<item>
		<title>Comment on Thoughts on OpenStack Foundation by Join the OpenStack Foundation mailing list | Open Systems Journal</title>
		<link>http://feedproxy.google.com/~r/CommentsForRyanLanesBlog/~3/dguvt20_WsU/</link>
		<dc:creator>Join the OpenStack Foundation mailing list | Open Systems Journal</dc:creator>
		<pubDate>Thu, 13 Oct 2011 23:52:05 +0000</pubDate>
		<guid isPermaLink="false">http://ryandlane.com/blog/?p=477#comment-3885</guid>
		<description>[...] goals for the foundation and how to keep the discussion going after the conference. Ryan Lane had a nice post on the session, and we’ll also be posting the video of the session to vimeo soon. Scott [...]</description>
		<content:encoded><![CDATA[<p>[...] goals for the foundation and how to keep the discussion going after the conference. Ryan Lane had a nice post on the session, and we&#8217;ll also be posting the video of the session to vimeo soon. Scott [...]</p>
<img src="http://feeds.feedburner.com/~r/CommentsForRyanLanesBlog/~4/dguvt20_WsU" height="1" width="1"/>]]></content:encoded>
	<feedburner:origLink>http://ryandlane.com/blog/2011/10/10/thoughts-on-openstack-foundation/comment-page-1/#comment-3885</feedburner:origLink></item>
	<item>
		<title>Comment on Using the LDAP Authentication Plugin for MediaWiki – The Basics (Part 3) by Renan P.</title>
		<link>http://feedproxy.google.com/~r/CommentsForRyanLanesBlog/~3/pUfsRF3sxHs/</link>
		<dc:creator>Renan P.</dc:creator>
		<pubDate>Thu, 13 Oct 2011 20:09:14 +0000</pubDate>
		<guid isPermaLink="false">http://ryandlane.com/wprdl/?p=148#comment-3883</guid>
		<description>Hello!  Can someone help me!

This is my LocalSettings
# LDAP AUTENTICATION - Chamada do Aplicativo e Plugin
require_once ("$IP/extensions/LdapAuthentication/LdapAuthentication.php");
$wgAuth = new LdapAuthenticationPlugin();

#Basic Auth.
$wgLDAPDomainNames = array( "Bellcomsys" );
$wgLDAPServerNames = array( "Bellcomsys" =&gt; "server.bellcomsys.net" );
$wgLDAPSearchStrings = array( "Bellcomsys" =&gt; "USER-NAME@Bellcomsys" );
$wgLDAPEncryptionType = array( "Bellcomsys" =&gt; "clear" );

#GROUPS
$wgLDAPGroupUseFullDN = array( "Bellcomsys"=&gt;true );
$wgLDAPBaseDNs = array( 'Bellcomsys' =&gt; 'dc=bellcomsys,dc=net' );
$wgLDAPSearchAttributes = array( 'Bellcomsys' =&gt; 'sAMAccountName' );
$wgLDAPGroupsUseMemberOf = array( "Bellcomsys" =&gt; true );
$wgLDAPGroupObjectclass = array( "Bellcomsys"=&gt;"group" );
$wgLDAPGroupAttribute = array( "Bellcomsys"=&gt;"member" );
$wgLDAPGroupNameAttribute = array( "Bellcomsys"=&gt;"cn" );
$wgLDAPRequiredGroups = array( "Acesso,Edit"=&gt; array( "ou=wiki,ou=bellcomcorp,dc=bellcomsys,dc=net" ) );
#$wgLDAPRequiredGroups = array( "Edit"=&gt; array( "ou=wiki,ou=bellcomcorp,dc=bellcomsys,dc=net" ) );

#GSync
$wgLDAPUseLDAPGroups = array( "Bellcomsys"=&gt;true );
$wgLDAPGroupsPrevail = array( "Bellcomsys"=&gt;true );

#LOG
$wgLDAPDebug = 99; # 3
$wgDebugLogGroups["ldap"] = "./debug.txt" ;

#Permission
# The following permissions were set based on your choice in the installer
$wgGroupPermissions['*']['createaccount'] = false;
$wgWhitelistRead = array( "Main Page", "Special:Userlogin", "-", "MediaWiki:Monobook.css" );
$wgGroupPermissions['Acesso']['read'] = true;
$wgGroupPermissions['Edit']['edit'] = false;
$wgGroupPermissions['*']['read'] = false;

The Autentication is working fine, the Goups are Sync with the Data Base but the permissions dont work, as you can see, the group "Edit" = False but the members of this group still with the permission of edit files.

What am i doing wrong?

Thanks for the Help!</description>
		<content:encoded><![CDATA[<p>Hello!  Can someone help me!</p>
<p>This is my LocalSettings<br />
# LDAP AUTENTICATION &#8211; Chamada do Aplicativo e Plugin<br />
require_once (&#8220;$IP/extensions/LdapAuthentication/LdapAuthentication.php&#8221;);<br />
$wgAuth = new LdapAuthenticationPlugin();</p>
<p>#Basic Auth.<br />
$wgLDAPDomainNames = array( &#8220;Bellcomsys&#8221; );<br />
$wgLDAPServerNames = array( &#8220;Bellcomsys&#8221; =&gt; &#8220;server.bellcomsys.net&#8221; );<br />
$wgLDAPSearchStrings = array( &#8220;Bellcomsys&#8221; =&gt; &#8220;USER-NAME@Bellcomsys&#8221; );<br />
$wgLDAPEncryptionType = array( &#8220;Bellcomsys&#8221; =&gt; &#8220;clear&#8221; );</p>
<p>#GROUPS<br />
$wgLDAPGroupUseFullDN = array( &#8220;Bellcomsys&#8221;=&gt;true );<br />
$wgLDAPBaseDNs = array( &#8216;Bellcomsys&#8217; =&gt; &#8216;dc=bellcomsys,dc=net&#8217; );<br />
$wgLDAPSearchAttributes = array( &#8216;Bellcomsys&#8217; =&gt; &#8216;sAMAccountName&#8217; );<br />
$wgLDAPGroupsUseMemberOf = array( &#8220;Bellcomsys&#8221; =&gt; true );<br />
$wgLDAPGroupObjectclass = array( &#8220;Bellcomsys&#8221;=&gt;&#8221;group&#8221; );<br />
$wgLDAPGroupAttribute = array( &#8220;Bellcomsys&#8221;=&gt;&#8221;member&#8221; );<br />
$wgLDAPGroupNameAttribute = array( &#8220;Bellcomsys&#8221;=&gt;&#8221;cn&#8221; );<br />
$wgLDAPRequiredGroups = array( &#8220;Acesso,Edit&#8221;=&gt; array( &#8220;ou=wiki,ou=bellcomcorp,dc=bellcomsys,dc=net&#8221; ) );<br />
#$wgLDAPRequiredGroups = array( &#8220;Edit&#8221;=&gt; array( &#8220;ou=wiki,ou=bellcomcorp,dc=bellcomsys,dc=net&#8221; ) );</p>
<p>#GSync<br />
$wgLDAPUseLDAPGroups = array( &#8220;Bellcomsys&#8221;=&gt;true );<br />
$wgLDAPGroupsPrevail = array( &#8220;Bellcomsys&#8221;=&gt;true );</p>
<p>#LOG<br />
$wgLDAPDebug = 99; # 3<br />
$wgDebugLogGroups["ldap"] = &#8220;./debug.txt&#8221; ;</p>
<p>#Permission<br />
# The following permissions were set based on your choice in the installer<br />
$wgGroupPermissions['*']['createaccount'] = false;<br />
$wgWhitelistRead = array( &#8220;Main Page&#8221;, &#8220;Special:Userlogin&#8221;, &#8220;-&#8221;, &#8220;MediaWiki:Monobook.css&#8221; );<br />
$wgGroupPermissions['Acesso']['read'] = true;<br />
$wgGroupPermissions['Edit']['edit'] = false;<br />
$wgGroupPermissions['*']['read'] = false;</p>
<p>The Autentication is working fine, the Goups are Sync with the Data Base but the permissions dont work, as you can see, the group &#8220;Edit&#8221; = False but the members of this group still with the permission of edit files.</p>
<p>What am i doing wrong?</p>
<p>Thanks for the Help!</p>
<img src="http://feeds.feedburner.com/~r/CommentsForRyanLanesBlog/~4/pUfsRF3sxHs" height="1" width="1"/>]]></content:encoded>
	<feedburner:origLink>http://ryandlane.com/blog/2009/07/09/using-the-ldap-authentication-plugin-for-mediawiki-%e2%80%93-the-basics-part-3/comment-page-1/#comment-3883</feedburner:origLink></item>
</channel>
</rss><!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Minified using memcached
Page Caching using memcached
Database Caching 1/44 queries in 0.020 seconds using memcached
Object Caching 513/558 objects using memcached

Served from: ryandlane.com @ 2011-12-23 02:25:15 -->

