# Setting Up - ldap \[Empty password reported\]

**URL:** <https://discourse.openondemand.org/t/setting-up-ldap-empty-password-reported/3957>\
**Category:** Get Help\
**Created:** [January 11, 2025, 2:41am UTC](https://discourse.openondemand.org/t/setting-up-ldap-empty-password-reported/3957 "2025-01-11T02:41:01Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![ChrisPWelsh](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/chrispwelsh/32/2555_2.png) [@ChrisPWelsh](https://discourse.openondemand.org/u/ChrisPWelsh)\
**Post date:** [January 11, 2025, 2:41am UTC](https://discourse.openondemand.org/t/setting-up-ldap-empty-password-reported/3957/1 "2025-01-11T02:41:01Z")

</div>

Hi All,

Installing OOD with Dex and am missing something at this stage as I get the login screen but /var/log/messages complains that I am sending an empty passwd.

Note: I have set the bindPW below, it has no special characters to escape and also tried switching to using a working certificate and re-run the update script and restarted dex.

Any help welcom. So close.

**Here is the error from login screen:**  
"

##### Internal Server Error

Login error: ldap: initial bind for user “CN=svcMK4WebLDAPBind,OU=Service,OU=Accounts,OU=MYWORKPLACE,DC=mcri,DC=edu,DC=au” failed: LDAP Result Code 206 “ **Empty password not allowed by the client": ldap: empty password not allowed by the client** ”

**from /var/log/messages:**  
Jan 11 13:22:50 login001 ondemand-dex[598867]: time=“2025-01-11T02:22:50Z” level=error msg=“Failed to login user: ldap: initial bind for user "CN=svcMK4WebLDAPBind,OU=Service,OU=Accounts,OU=MYWORKPLACE,DC=myworkplace,DC=edu,DC=au" failed: LDAP Result Code 206 "Empty password not allowed by the client": ldap: empty password not allowed by the client”

Here is my "/etc/ood/config/ood\_portal.yml file and Dex stuff. No other setting as I read it defaults to auth: opened…???

servername: ‘research-cluster.myworkplace.edu.au’  
port: ‘443’  
client\_secret: blahblah from Dex dir  
ssl:

- ‘SSLCertificateFile /etc/httpd/ssl/myworkplace/myworkplace.edu.au.cer’
- ‘SSLCertificateKeyFile /etc/httpd/ssl/myworkplace/myworkplace.edu.au.nopass.key’
- ‘SSLCertificateChainFile /etc/httpd/ssl/myworkplace/CACertificate.chain.cer’

dex:  
connectors:  
- type: ldap  
id: ldap  
name: LDAP  
config:  
host: myldapserverv.myworkplace.edu.au:636  
#tlsConfig:caCert: “/etc/ssl/certs/ldap-ca.crt”  
insecureSkipVerify: false  
bindDN: CN= ,OU=Service,OU=Accounts,OU=MYWORKPLACE,DC=mcri,DC=edu,DC=au  
userSearch:  
baseDN: OU=USERS,OU=HEADQUARTERS,DC=myworkplace,DC=edu,DC=au  
bindPW: \<my\_svcMK4WebLDAPBindPW\>  
filter: “(objectClass=posixAccount)”  
username: uid  
idAttr: uid  
emailAttr: mail  
nameAttr: gecos  
preferredUsernameAttr: uid  
groupSearch:  
baseDN: OU=Groups,OU=MYWORKPLACE,DC=mcri,DC=edu,DC=au  
filter: “(objectClass=posixGroup)”  
userMatchers:  
- userAttr: DN  
groupAttr: member  
nameAttr: cn  
frontend:  
theme: ondemand  
dir: /usr/share/ondemand-dex/web

---

<div class="post-metadata">

**Author:** ![jeff.ohrstrom](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/jeff.ohrstrom/32/136_2.png) [@jeff.ohrstrom](https://discourse.openondemand.org/u/jeff.ohrstrom)\
**Post date:** [January 13, 2025, 2:43pm UTC](https://discourse.openondemand.org/t/setting-up-ldap-empty-password-reported/3957/2 "2025-01-13T14:43:37Z")

</div>

Can you confirm the bind password has made it to the dex configuration in `/ood/dex/config.yml`?

---

<div class="post-metadata">

**Author:** ![ChrisPWelsh](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/chrispwelsh/32/2555_2.png) [@ChrisPWelsh](https://discourse.openondemand.org/u/ChrisPWelsh)\
**Post date:** [January 13, 2025, 10:51pm UTC](https://discourse.openondemand.org/t/setting-up-ldap-empty-password-reported/3957/3 "2025-01-13T22:51:44Z")

</div>

Hi Jeff,

Yep the password made it. Is there ac command line thing I can do to execute the Dex part only as a test?

---

<div class="post-metadata">

**Author:** ![ChrisPWelsh](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/chrispwelsh/32/2555_2.png) [@ChrisPWelsh](https://discourse.openondemand.org/u/ChrisPWelsh)\
**Post date:** [January 14, 2025, 4:12am UTC](https://discourse.openondemand.org/t/setting-up-ldap-empty-password-reported/3957/4 "2025-01-14T04:12:04Z")

</div>

File: /etc/ood/dex/config.yaml  
[root@login001 dex]# ls -l  
total 188  
-rw-------. 1 ondemand-dex ondemand-dex 1145 Jan 11 14:47 config.yaml

issuer: [https://login001.myworkplace.edu.au/dex](https://login001.myworkplace.edu.au/dex)  
storage:  
type: sqlite3  
config:  
file: “/etc/ood/dex/dex.db”  
web:  
http: localhost:5556  
telemetry:  
http: 0.0.0.0:5558  
staticClients:

- id: login001.myworkplace.edu.au  
redirectURIs:
  - [https://login001.myworkplace.edu.au/oidc](https://login001.myworkplace.edu.au/oidc)  
name: OnDemand  
secret: DEX Secret  
connectors:

- type: ldap  
id: ldap  
name: LDAP  
config:  
host: pkmpadsdc02v.myworkplace.edu.au:636  
insecureSkipVerify: false  
bindDN: CN=MYBINDACCOUNT,OU=Service,OU=Accounts,OU=MYWORKPLACE,DC=myworkplace,DC=edu,DC=au  
userSearch:  
baseDN: OU=USERS,OU=HEADQUARTERS,DC=myworkplace,DC=edu,DC=au  
bindPW:" I can confirm password was here"  
filter: “(objectClass=posixAccount)”  
.

.  
.  
stuff deleted by me

---

<div class="post-metadata">

**Author:** ![jeff.ohrstrom](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/jeff.ohrstrom/32/136_2.png) [@jeff.ohrstrom](https://discourse.openondemand.org/u/jeff.ohrstrom)\
**Post date:** [January 14, 2025, 3:57pm UTC](https://discourse.openondemand.org/t/setting-up-ldap-empty-password-reported/3957/5 "2025-01-14T15:57:56Z")

</div>

Does your password have a $ in it? I’m finding that they’re expanding environment variables. Apparently `DEX_EXPAND_ENV=0` will stop this, but I can’t tell what release that’s in.

> <https://github.com/dexidp/dex/issues/1051>
>
> When using the ldap connector with bindPW with dollar sign (I haven't tried any …other special characters) with example-app, the initial bind does not seem to get authenticated and throws:
> 
> \`\`\`
> {"level":"error","msg":"Failed to login user: ldap: initial bind for user \\"cn=...\\" failed: LDAP Result Code 49 \\"Invalid Credentials\\": 80090308: LdapErr: DSID-0C090400, comment: AcceptSecurityContext error, data 52e, v1db1\\u0000","time":"2017-08-25T10:19:24Z"}
> \`\`\`
> 
> After digging into it, it seems the $ sign was not being passed correctly.
> e.g. using in config-ldap.yaml
> \`\`\`
> bindPW: 123$$$$45
> \`\`\`
> When I dump out what got used as bindPW, I see:
> \`"bindPW":"12345"\`
> 
> I haven't dug into to much so could be missing some escaping sequence in the yaml. I tried using double quote, single quote and \`\\\` to escape but no avail.

---

<div class="post-metadata">

**Author:** ![ChrisPWelsh](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/chrispwelsh/32/2555_2.png) [@ChrisPWelsh](https://discourse.openondemand.org/u/ChrisPWelsh)\
**Post date:** [January 14, 2025, 10:00pm UTC](https://discourse.openondemand.org/t/setting-up-ldap-empty-password-reported/3957/6 "2025-01-14T22:00:57Z")

</div>

The password is just letters and no symbols, etc. We had ruled that out.

---

<div class="post-metadata">

**Author:** ![ChrisPWelsh](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/chrispwelsh/32/2555_2.png) [@ChrisPWelsh](https://discourse.openondemand.org/u/ChrisPWelsh)\
**Post date:** [January 19, 2025, 9:05am UTC](https://discourse.openondemand.org/t/setting-up-ldap-empty-password-reported/3957/7 "2025-01-19T09:05:52Z")

</div>

Hi Jeff, I’m in AU and unfortunately(fortunately actually) OOD is on the critical path for our project. Is there any chance I could setup a teams meet and walk through this with you? I’m happy to be up when it is daytime hours for you. I’m hoping it is something silly that I have done and a second set of eyes would see it. Thx.

---

<div class="post-metadata">

**Author:** ![jeff.ohrstrom](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/jeff.ohrstrom/32/136_2.png) [@jeff.ohrstrom](https://discourse.openondemand.org/u/jeff.ohrstrom)\
**Post date:** [January 21, 2025, 2:31pm UTC](https://discourse.openondemand.org/t/setting-up-ldap-empty-password-reported/3957/8 "2025-01-21T14:31:51Z")

</div>

Sure, drop me a line at johrstrom@osc.edu.

---

<div class="post-metadata">

**Author:** ![ChrisPWelsh](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/chrispwelsh/32/2555_2.png) [@ChrisPWelsh](https://discourse.openondemand.org/u/ChrisPWelsh)\
**Post date:** [January 28, 2025, 7:39am UTC](https://discourse.openondemand.org/t/setting-up-ldap-empty-password-reported/3957/9 "2025-01-28T07:39:50Z")

</div>

Hi Jeff and all, I have gotten past this issue but onto the next.

resolution of the above issue seems to have need I had bindPW under user search rather than in the section under bindDN.

next issue I suspect may be user map issues.  
I have tried two different users names. i.e.  
“fred”  
“will.robinson”

both return the same error: i.e for “will.robinson”

Jan 28 18:04:03 loginServer ondemand-dex[2106391]: time=“2025-01-28T07:04:03Z” level=error msg=“ldap: no results returned for filter: "(&(objectClass=posixAccount)(uid=will.robinson))"”

Any thoughts?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex015/uploads/osc/original/2X/b/bae70bd0ed39a3ae769c2108155f4cb3e9da8385.png) [@system](https://discourse.openondemand.org/u/system)\
**Post date:** [July 27, 2025, 7:40am UTC](https://discourse.openondemand.org/t/setting-up-ldap-empty-password-reported/3957/10 "2025-07-27T07:40:12Z")

</div>

This topic was automatically closed 180 days after the last reply. New replies are no longer allowed.
