1

Topic: Migrate 0.8.7 to 0.9.5-1 can't login

==== Required information ==== Purchase dateMay 18, 2014
- iRedMail version (check /etc/iredmail-release): iRedMail-0.8.7/iRedAdmin-Pro-LDAP-2.2.2
- Linux/BSD distribution name and version: CentOS7
- Store mail accounts in which backend (LDAP/MySQL/PGSQL): LDAP
- Web server (Apache or Nginx): Apache
- Manage mail accounts with iRedAdmin-Pro?  iRedAdmin-Pro-LDAP-2.6.1
- Related log if you're reporting an issue: Magrate fail
====

I want migrate iRedMail-0.8.7/iRedAdmin-Pro-LDAP-2.2.2  6 domain 200user about  on CentOS6.5

TO

iRedMail-0.9.5-1 / iRedAdmin-Pro-LDAP-2.6.1 on CentOS7 install new server complete.

flow up http://www.iredmail.org/docs/backup.restore.html 

After #slapadd -f /etc/openldap/slapd.conf -l /fromOldServer/2016.11.18.03.00.02.ldif  100% and restart server

Can't login iRedAdmin-Pro I don't sure in After LDAP restore not have updateLDAPValues_087_to_095.py

Please advise me about migrate I'm try 3 time same result can't login after slapadd step

----

Spider Email Archiver: On-Premises, lightweight email archiving software developed by iRedMail team. Supports Amazon S3 compatible storage and custom branding.

2

Re: Migrate 0.8.7 to 0.9.5-1 can't login

After restored LDAP data, did you run scripts mentioned in our tutorial "After LDAP restore"?
http://www.iredmail.org/docs/backup.res … ap-restore

New iRedMail releases may use different LDAP filter to query mail accounts while login, so you may experience "cannot login" issue. Please run all scripts required by iRedMail-0.8.7 and newer releases immediately after restored ldap data.

3 (edited by pattanotai 2016-11-21 17:56:42)

Re: Migrate 0.8.7 to 0.9.5-1 can't login

ZhangHuangbin wrote:

After restored LDAP data, did you run scripts mentioned in our tutorial "After LDAP restore"?
http://www.iredmail.org/docs/backup.res … ap-restore

New iRedMail releases may use different LDAP filter to query mail accounts while login, so you may experience "cannot login" issue. Please run all scripts required by iRedMail-0.8.7 and newer releases immediately after restored ldap data.


OK, I run  2 script  already and restart server "Error: Username or password is incorrect." same before.

updateLDAPValues_087_to_090.py
updateLDAPValues_094_to_095.py

4

Re: Migrate 0.8.7 to 0.9.5-1 can't login

OK, any error in Dovecot log file (/var/log/dovecot.log)? Please consider turn on debug mode in Dovecot and reproduce this issue, extract related log from Dovecot log file and paste here.

FYI: http://www.iredmail.org/docs/debug.dovecot.html

5

Re: Migrate 0.8.7 to 0.9.5-1 can't login

iredadmin-pro login not have any error dovecot log.

webmail log in error log as below

Nov 21 22:14:59 auth: Debug: Loading modules from directory: /usr/lib64/dovecot/auth
Nov 21 22:14:59 auth: Debug: Module loaded: /usr/lib64/dovecot/auth/libdriver_mysql.so
Nov 21 22:14:59 auth: Debug: Module loaded: /usr/lib64/dovecot/auth/libdriver_pgsql.so
Nov 21 22:14:59 auth: Debug: Module loaded: /usr/lib64/dovecot/auth/libdriver_sqlite.so
Nov 21 22:14:59 auth: Debug: Loading modules from directory: /usr/lib64/dovecot/auth
Nov 21 22:14:59 auth: Debug: Module loaded: /usr/lib64/dovecot/auth/libauthdb_ldap.so
Nov 21 22:14:59 auth: Debug: Read auth token secret from /var/run/dovecot/auth-token-secret.dat
Nov 21 22:14:59 auth: Debug: passwd-file /etc/dovecot/dovecot-master-users: Read 1 users in 0 secs
Nov 21 22:14:59 auth: Debug: auth client connected (pid=2450)
Nov 21 22:14:59 auth: Debug: client in: AUTH    1       PLAIN   service=imap    secured session=YnN+HtFBxop/AAAB        lip=127.0.0.1rip=127.0.0.1    lport=143       rport=35526     resp=AHBvc3RtYXN0ZXJAbHNlbmdpbmVlcmluZy5jby50aABicGVAMjU2MA== (previous base64 data may contain sensitive data)
Nov 21 22:14:59 auth: Error: LDAP: binding failed (dn cn=vmail,dc=xxxxxxx,dc=com): Invalid credentials
Nov 21 22:14:59 auth: Debug: ldap(postmaster@xxxxxx.com,127.0.0.1,<YnN+HtFBxop/AAAB>): bind search: base=o=domains,dc=xxxxxxx,dc=com filter=(&(objectClass=mailUser)(accountStatus=active)(enabledService=mail)(enabledService=imapsecured)(|(mail=postmaster@xxxxxx.com)(&(enabledService=shadowaddress)(shadowAddress=postmaster@xxxxx.com))))
Nov 21 22:14:59 auth: Error: LDAP: binding failed (dn cn=vmail,dc=xxxxxx,dc=com): Invalid credentials
Nov 21 22:15:03 auth: Info: ldap(postmaster@xxxxxx.com,127.0.0.1,<YnN+HtFBxop/AAAB>): Aborting (timeout), we're not connected to LDAP server
Nov 21 22:15:05 auth: Debug: client passdb out: FAIL    1       user=postmaster@xxxxxx.com     temp
Nov 21 22:15:05 imap-login: Info: Disconnected (auth failed, 1 attempts in 6 secs): user=<postmaster@xxxxxx.com>, method=PLAIN, rip=127.0.0.1, lip=127.0.0.1, secured, session=<YnN+HtFBxop/AAAB>

6

Re: Migrate 0.8.7 to 0.9.5-1 can't login

pattanotai wrote:

Nov 21 22:14:59 auth: Error: LDAP: binding failed (dn cn=vmail,dc=xxxxxx,dc=com): Invalid credentials

LDAP bind dn or password is incorrect in /etc/dovecot/dovecot-ldap.conf.

Did you replace the password for 'cn=vmail,dc=xx,dc=xx' and 'cn=vmailadmin,dc=xx,dc=xx' BEFORE restoring? It's clearly mentioned in our tutorial. http://www.iredmail.org/docs/backup.restore.html

Never mind, just reset the password to the one used in /etc/dovecot/dovecot-ldap.conf, then it should work.

7 (edited by pattanotai 2016-11-22 14:43:14)

Re: Migrate 0.8.7 to 0.9.5-1 can't login

replace the password for 'cn=vmail,dc=xx,dc=xx' and 'cn=vmailadmin,dc=xx,dc=xx' BEFORE restoring?

Yes, Sure 100% replace by SSHA password already. I will  try change passwd in dovevot-ldap.conf already.

Fail same before auth: Error: LDAP: binding failed (dn cn=vmail,dc=xxxxxxxx,dc=com): Invalid credentials


how I reset password ldap all ?

8

Re: Migrate 0.8.7 to 0.9.5-1 can't login

pattanotai wrote:

replace the password for 'cn=vmail,dc=xx,dc=xx' and 'cn=vmailadmin,dc=xx,dc=xx' BEFORE restoring?

Yes, Sure 100% replace by SSHA password already. I will  try change passwd in dovevot-ldap.conf already.

Fail same before auth: Error: LDAP: binding failed (dn cn=vmail,dc=xxxxxxxx,dc=com): Invalid credentials


how I reset password ldap all ?


And I reinstall new again and flow-up step by step,  Can't login and error same before.
I don't know mistake something

9

Re: Migrate 0.8.7 to 0.9.5-1 can't login

Please check log file first, if you don't check log file to figure out why this error occurred, no matter how many times you repeat the procedure you will get same error.

Turn on debug mode in dovecot and try to login again, show us the errors in dovecot log file.

10

Re: Migrate 0.8.7 to 0.9.5-1 can't login

Error same Nov 21

Nov 22 13:41:13 master: Warning: Killed with signal 15 (by pid=2054 uid=0 code=kill)
Nov 22 13:41:13 master: Info: Dovecot v2.2.26.0 (23d1de6) starting up for pop3, imap, sieve, lmtp (core dumps disabled)
Nov 22 13:41:31 auth: Debug: Loading modules from directory: /usr/lib64/dovecot/auth
Nov 22 13:41:31 auth: Debug: Module loaded: /usr/lib64/dovecot/auth/libdriver_mysql.so
Nov 22 13:41:31 auth: Debug: Module loaded: /usr/lib64/dovecot/auth/libdriver_pgsql.so
Nov 22 13:41:31 auth: Debug: Module loaded: /usr/lib64/dovecot/auth/libdriver_sqlite.so
Nov 22 13:41:31 auth: Debug: Loading modules from directory: /usr/lib64/dovecot/auth
Nov 22 13:41:31 auth: Debug: Module loaded: /usr/lib64/dovecot/auth/libauthdb_ldap.so
Nov 22 13:41:31 auth: Debug: Read auth token secret from /var/run/dovecot/auth-token-secret.dat
Nov 22 13:41:31 auth: Debug: passwd-file /etc/dovecot/dovecot-master-users: Read 1 users in 0 secs
Nov 22 13:41:31 auth: Debug: auth client connected (pid=2109)
Nov 22 13:41:31 auth: Error: LDAP: binding failed (dn cn=vmail,dc=dc=xxxxxxxxxxxxx,dc=com): Invalid credentials
Nov 22 13:41:31 auth: Debug: client in: AUTH    1       PLAIN   service=imap    secured session=oAEUEN5Bgod/AAAB        lip=127.0.0.1rip=127.0.0.1    lport=143       rport=34690     resp=AHBvc3RtYXN0ZXJAbHNlbmdpbmVlcmluZy5jby50aABicGVAMjU2MA== (previous base64 data may contain sensitive data)
Nov 22 13:41:31 auth: Debug: ldap(postmaster@dc=xxxxxxxxxxxxx,dc=com,127.0.0.1,<oAEUEN5Bgod/AAAB>): bind search: base=o=domains,dc=dc=xxxxxxxxxxxxx,dc=com=th filter=(&(objectClass=mailUser)(accountStatus=active)(enabledService=mail)(enabledService=imapsecured)(|(mail=postmaster@dc=xxxxxxxxxxxxx,dc=comh)(&(enabledService=shadowaddress)(shadowAddress=postmaster@xxxxxxxxxxxxx,dc=com))))
Nov 22 13:41:31 auth: Error: LDAP: binding failed (dn cn=vmail,dc=xxxxxxxxxxxxx,dc=com): Invalid credentials
Nov 22 13:41:35 auth: Info: ldap(postmaster@dc=xxxxxxxxxxxxx,dc=com,127.0.0.1,<oAEUEN5Bgod/AAAB>): Aborting (timeout), we're not connected to LDAP server

11 (edited by pattanotai 2016-11-24 10:20:04)

Re: Migrate 0.8.7 to 0.9.5-1 can't login

how I open ticket

Case Migrate  Migrate 0.8.7 to 0.9.5-1   and 6 domain in site

How much ?

12

Re: Migrate 0.8.7 to 0.9.5-1 can't login

pattanotai wrote:

Nov 22 13:41:31 auth: Error: LDAP: binding failed (dn cn=vmail,dc=xxxxxxxxxxxxx,dc=com): Invalid credentials

Still incorrect LDAP bind dn or password.