Bug #2366
closedError in User Manager - Privileges are not being enforced
0%
Description
After adding a user and granting that user all privileges (both by adding to admin group and manually selecting all privileges), the user is allowed to log in but get 201 error.
Through ssh, user does not get pfSense prompt, direct towards shell.
Installed packages:
nmap
Open-VM-Tools (non-beta version)
Files
Updated by Chris Buechler about 13 years ago
- Status changed from New to Rejected
not a legit bug report. the CLI behavior is expected, and assigning privileges as described works. no idea what a "201 error" would be or come from, post to the forum or list for help including details of "201 error".
Updated by Stephen Groat about 13 years ago
- File Screen Shot 2012-04-10 at 11.05.01 PM.png Screen Shot 2012-04-10 at 11.05.01 PM.png added
- File Screen Shot 2012-04-10 at 11.06.38 PM.png Screen Shot 2012-04-10 at 11.06.38 PM.png added
- File Screen Shot 2012-04-10 at 11.06.43 PM.png Screen Shot 2012-04-10 at 11.06.43 PM.png added
- File Screen Shot 2012-04-10 at 11.07.48 PM.png Screen Shot 2012-04-10 at 11.07.48 PM.png added
- File config-purple.cirt.vt.edu-20120410230924.xml config-purple.cirt.vt.edu-20120410230924.xml added
An example of what happens. User is sgroat. Granted admin access. Auth is through LDAP. When user logs on, logon is successful, but the user does not have the privileges granted.
Updated by Adam Esslinger over 10 years ago
I have also experienced this bug. When pfsense is set to use LDAP as the authentication server (specifically Active Directory) and a user either LDAP or local DB logs in and creates a new user the permissions aren't really applied, however the web GUI shows the permissions as applied. When you logout after account creation and login as the new user you will get an error 201 page. If you log back in and set the authentication back to local DB and create a new user the permissions are correctly applied on the new user. Im using 2.1.5-RELEASE (amd64)
Updated by Ermal Luçi over 10 years ago
You should follow setup procedures for AD.
Search the net and you will find them.