[389-users] Re: nsslapd-haproxy-trusted-ip is ignored

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Hi,

with 'send-proxy' HAProxy sends source IP and destination IP. If you're testing this on the same host, your destination IP would be your loopback interface (127.0.0.1 or ::1).
[01/Aug/2025:09:48:44.815980034 -0400] conn=11 fd=64 HAProxy new_address_from=127.0.0.1 to new_address_dest=127.0.0.1

For this corner case you can add nsslapd-haproxy-trusted-ip: 127.0.0.1 to your config.
If you test connection from another host to HAproxy using one the IPs that you already specified, it should work.
[01/Aug/2025:09:46:05.826598329 -0400] conn=9 fd=64 HAProxy new_address_from=10.xx.xx.xx to new_address_dest=10.yy.yy.yy

HTH
On Fri, Aug 1, 2025 at 2:27 PM Mitja Mihelič via 389-users <389-users@xxxxxxxxxxxxxxxxxxxxxxx> wrote:
I tried again on version 389-ds-base-3.1.2-3.el9, but I ran into the
same error
Disconnect - Protocol error - Unknown Proxy - P4

An I missing an obvious setting I should be configuring or might this be
a long standing unresolved bug?

Best regards,
Mitja

On 28. 7. 25 09:01, Mitja Mihelič via 389-users wrote:
> Hi!
>
> I am trying to set up HAProxy with two 389DS nodes in multi-supplier
> setup. I have followed the instructions on
> https://www.port389.org/docs/389ds/howto/howto-test-haproxy-ldaps.html and
> https://docs.redhat.com/en/documentation/red_hat_directory_server/12/html/configuration_and_schema_reference/assembly_core-server-configuration-attributes_config-schema-reference-title#nsslapd-haproxy-trusted-ip_assembly_cn-config.
>
>
> I am using 389-ds-base-2.6.1-10.el9_6 on AlmaLinux 9.6.
>
> Please excuse the IPs and hostnames, they have been changed.
>
> I have set "nsslapd-haproxy-trusted-ip" to the following
> [root@389ds-node1 ~]#  dsconf my-389ds-instance config add
> nsslapd-haproxy-trusted-ip=1.2.3.4 nsslapd-haproxy-trusted-ip=1:2:3::4
> nsslapd-haproxy-trusted-ip=2.3.4.5 nsslapd-haproxy-trusted-ip=2:3:4::5
>
> [root@389ds-node1 ~]# dsconf my-389ds-instance config get
> nsslapd-haproxy-trusted-ip
> nsslapd-haproxy-trusted-ip: 1.2.3.4
> nsslapd-haproxy-trusted-ip: 2.3.4.5
> nsslapd-haproxy-trusted-ip: 1:2:3::4
> nsslapd-haproxy-trusted-ip: 2:3:4::5
>
> When trying to connect through HAProxy, the client reports the
> following error
> [root@389ds-node1 ~]# ldapwhoami -vvv -H ldaps://ldap-test.example.com
> -D "uid=username@xxxxxxxxxxx,dc=example,dc=com" -x -W
> ldap_initialize( ldaps://ldap-test.example.com:636/??base )
> ldap_result: Can't contact LDAP server (-1)
>
> Access log on 389ds-node1 reports this
> [25/Jul/2025:08:32:41.207106191 +0200] conn=216 fd=74 slot=74 SSL
> connection from 1.2.3.4 to 11.22.33.44
> [25/Jul/2025:08:32:41.207237108 +0200] conn=216 op=-1 fd=74 Disconnect
> - Protocol error - Unknown Proxy - P4
>
> It looks like the values in "nsslapd-haproxy-trusted-ip" are being
> ignored.
>
> How can I get this to work?
>
> Best regards,
> Mitja

--
_______________________________________________
389-users mailing list -- 389-users@xxxxxxxxxxxxxxxxxxxxxxx
To unsubscribe send an email to 389-users-leave@xxxxxxxxxxxxxxxxxxxxxxx
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/389-users@xxxxxxxxxxxxxxxxxxxxxxx
Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue


--
Viktor
-- 
_______________________________________________
389-users mailing list -- 389-users@xxxxxxxxxxxxxxxxxxxxxxx
To unsubscribe send an email to 389-users-leave@xxxxxxxxxxxxxxxxxxxxxxx
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/389-users@xxxxxxxxxxxxxxxxxxxxxxx
Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue

[Index of Archives]     [Fedora User Discussion]     [Older Fedora Users]     [Fedora Announce]     [Fedora Package Announce]     [EPEL Announce]     [Fedora News]     [Fedora Cloud]     [Fedora Advisory Board]     [Fedora Education]     [Fedora Security]     [Fedora Scitech]     [Fedora Robotics]     [Fedora Maintainers]     [Fedora Infrastructure]     [Fedora Websites]     [Anaconda Devel]     [Fedora Devel Java]     [Fedora Legacy]     [Fedora Desktop]     [Fedora Fonts]     [ATA RAID]     [Fedora Marketing]     [Fedora Management Tools]     [Fedora Mentors]     [Fedora Package Review]     [Fedora R Devel]     [Fedora PHP Devel]     [Kickstart]     [Fedora Music]     [Fedora Packaging]     [Centos]     [Fedora SELinux]     [Fedora Legal]     [Fedora Kernel]     [Fedora QA]     [Fedora Triage]     [Fedora OCaml]     [Coolkey]     [Virtualization Tools]     [ET Management Tools]     [Yum Users]     [Tux]     [Yosemite News]     [Yosemite Photos]     [Linux Apps]     [Maemo Users]     [Gnome Users]     [KDE Users]     [Fedora Tools]     [Fedora Art]     [Fedora Docs]     [Maemo Users]     [Asterisk PBX]     [Fedora Sparc]     [Fedora Universal Network Connector]     [Fedora ARM]

  Powered by Linux