Problèmes de droits et de connexion à distance

Bonjour à tous,

Voilà une dizaine de jours (depuis la version 4.2.12) que je planche sur mon problème de connexion via eu.jeedom.link, et je ne trouve pas. Pire, je sens que le problème est plus profond :

Syndrome principal : « Mot de passe ou nom d’utilisateur incorrect » (quelque soit le compte utilisé)


Bref, plus de connexion à distance et redémarrer le DNS ne change rien. En local, pas de problème.

Le truc bizarre repéré : Je ne peux plus éditer les droits sur la page « Utilisateurs »

Coté santé, rien de suspect :

Actions réalisées : MAJ en 4.2.14, update et upgrade Rasp.

Je suis preneur d’idées là ! :slight_smile:

Merci ! :pray:

Bonjour,

Si la page jeedom s’affiche le DNS ne doit pas être le problème

Bonjour,

Sans log c’est compliqué de deviner.
De mémoire il y a un log connection mais je ne suis plus trop sur.

Il faudrait aussi plus d’info sur le type de box (box physique ? VM ?..), sur le réseau local
Regardez les sessions, si votre ip n’est pas bloquée (à priori cela ne semble pas être là source du problème mais vérifiez tout de même)…

Ce n’est pas bizarre. Il n’y a aucun droit plus granulaire possible pour ces profils (admin et utilisateurs), le bouton n’est donc pas actif.
C’est listé dans le changelog.

Bonjour Mips,
Je tourne sur un RPI4 + SSD
Ci dessous les logs récupérés de OpenVPN :

0000|Sat Mar  5 15:29:16 2022 WARNING: file '/tmp/jeedom/openvpn/openvpn_auth_IFUc8RCpkfZlidvIZOOSYykmOKW0ZX.conf' is group or others accessible
0001|Sat Mar  5 15:29:16 2022 OpenVPN 2.4.7 arm-unknown-linux-gnueabihf [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [PKCS11] [MH/PKTINFO] [AEAD] built on Apr 28 2021
0002|Sat Mar  5 15:29:16 2022 library versions: OpenSSL 1.1.1d  10 Sep 2019, LZO 2.10
0003|Sat Mar  5 15:29:16 2022 WARNING: No server certificate verification method has been enabled.  See http://openvpn.net/howto.html#mitm for more info.
0004|Sat Mar  5 15:29:16 2022 WARNING: normally if you use --mssfix and/or --fragment, you should also set --tun-mtu 1500 (currently it is 1300)
0005|Sat Mar  5 15:29:16 2022 TCP/UDP: Preserving recently used remote address: [AF_INET]135.125.10.213:1200
0006|Sat Mar  5 15:29:16 2022 UDP link local: (not bound)
0007|Sat Mar  5 15:29:16 2022 UDP link remote: [AF_INET]135.125.10.213:1200
0008|Sat Mar  5 15:29:16 2022 WARNING: this configuration may cache passwords in memory -- use the auth-nocache option to prevent this
0009|Sat Mar  5 15:29:16 2022 VERIFY OK: depth=1, C=FR, ST=IDF, L=Paris, O=jeedom.com, OU=jeedom.com, CN=jeedom.com CA, name=jeedom, emailAddress=postmaster@jeedom.com
0010|Sat Mar  5 15:29:16 2022 VERIFY OK: depth=0, C=FR, ST=IDF, L=Paris, O=jeedom.com, OU=jeedom.com, CN=server, name=jeedom, emailAddress=postmaster@jeedom.com
0011|Sat Mar  5 15:29:16 2022 Control Channel: TLSv1.3, cipher TLSv1.3 TLS_AES_256_GCM_SHA384, 1024 bit RSA
0012|Sat Mar  5 15:29:16 2022 [server] Peer Connection Initiated with [AF_INET]135.125.10.213:1200
0013|Sat Mar  5 15:29:17 2022 Data Channel: using negotiated cipher 'AES-256-GCM'
0014|Sat Mar  5 15:29:17 2022 Outgoing Data Channel: Cipher 'AES-256-GCM' initialized with 256 bit key
0015|Sat Mar  5 15:29:17 2022 Incoming Data Channel: Cipher 'AES-256-GCM' initialized with 256 bit key
0016|Sat Mar  5 15:29:17 2022 TUN/TAP device tun0 opened
0017|Sat Mar  5 15:29:17 2022 /sbin/ip link set dev tun0 up mtu 1300
0018|Sat Mar  5 15:29:17 2022 /sbin/ip addr add dev tun0 local 10.15.6.198 peer 10.15.6.197
0019|Sat Mar  5 15:29:17 2022 Initialization Sequence Completed
0020|Sat Mar  5 17:37:09 2022 VERIFY OK: depth=1, C=FR, ST=IDF, L=Paris, O=jeedom.com, OU=jeedom.com, CN=jeedom.com CA, name=jeedom, emailAddress=postmaster@jeedom.com
0021|Sat Mar  5 17:37:09 2022 VERIFY OK: depth=0, C=FR, ST=IDF, L=Paris, O=jeedom.com, OU=jeedom.com, CN=server, name=jeedom, emailAddress=postmaster@jeedom.com
0022|Sat Mar  5 17:37:09 2022 Outgoing Data Channel: Cipher 'AES-256-GCM' initialized with 256 bit key
0023|Sat Mar  5 17:37:09 2022 Incoming Data Channel: Cipher 'AES-256-GCM' initialized with 256 bit key
0024|Sat Mar  5 17:37:09 2022 Control Channel: TLSv1.3, cipher TLSv1.3 TLS_AES_256_GCM_SHA384, 1024 bit RSA
0025|Sat Mar  5 18:37:10 2022 VERIFY OK: depth=1, C=FR, ST=IDF, L=Paris, O=jeedom.com, OU=jeedom.com, CN=jeedom.com CA, name=jeedom, emailAddress=postmaster@jeedom.com
0026|Sat Mar  5 18:37:10 2022 VERIFY OK: depth=0, C=FR, ST=IDF, L=Paris, O=jeedom.com, OU=jeedom.com, CN=server, name=jeedom, emailAddress=postmaster@jeedom.com
0027|Sat Mar  5 18:37:10 2022 Outgoing Data Channel: Cipher 'AES-256-GCM' initialized with 256 bit key
0028|Sat Mar  5 18:37:10 2022 Incoming Data Channel: Cipher 'AES-256-GCM' initialized with 256 bit key
0029|Sat Mar  5 18:37:10 2022 Control Channel: TLSv1.3, cipher TLSv1.3 TLS_AES_256_GCM_SHA384, 1024 bit RSA
0030|Sat Mar  5 19:37:11 2022 VERIFY OK: depth=1, C=FR, ST=IDF, L=Paris, O=jeedom.com, OU=jeedom.com, CN=jeedom.com CA, name=jeedom, emailAddress=postmaster@jeedom.com
0031|Sat Mar  5 19:37:11 2022 VERIFY OK: depth=0, C=FR, ST=IDF, L=Paris, O=jeedom.com, OU=jeedom.com, CN=server, name=jeedom, emailAddress=postmaster@jeedom.com
0032|Sat Mar  5 19:37:11 2022 Outgoing Data Channel: Cipher 'AES-256-GCM' initialized with 256 bit key
0033|Sat Mar  5 19:37:11 2022 Incoming Data Channel: Cipher 'AES-256-GCM' initialized with 256 bit key
0034|Sat Mar  5 19:37:11 2022 Control Channel: TLSv1.3, cipher TLSv1.3 TLS_AES_256_GCM_SHA384, 1024 bit RSA
0035|Sat Mar  5 20:37:11 2022 VERIFY OK: depth=1, C=FR, ST=IDF, L=Paris, O=jeedom.com, OU=jeedom.com, CN=jeedom.com CA, name=jeedom, emailAddress=postmaster@jeedom.com
0036|Sat Mar  5 20:37:11 2022 VERIFY OK: depth=0, C=FR, ST=IDF, L=Paris, O=jeedom.com, OU=jeedom.com, CN=server, name=jeedom, emailAddress=postmaster@jeedom.com
0037|Sat Mar  5 20:37:11 2022 Outgoing Data Channel: Cipher 'AES-256-GCM' initialized with 256 bit key
0038|Sat Mar  5 20:37:11 2022 Incoming Data Channel: Cipher 'AES-256-GCM' initialized with 256 bit key
0039|Sat Mar  5 20:37:11 2022 Control Channel: TLSv1.3, cipher TLSv1.3 TLS_AES_256_GCM_SHA384, 1024 bit RSA
0040|Sat Mar  5 21:37:12 2022 NOTE: --mute triggered...

Depuis ce week-end, j’ai récupéré une connexion externe fonctionnelle à 100%, mais je ne sais pas pourquoi au final puisque je n’ai pas changé grand chose en lien avec ce problème. :thinking:

Je bascule de ma box 4G vers ma box ADSL généralement en fin de mois (forfait 4G épuisé) - Tout mon réseau LAN est géré par un système ORBI donc mes adresses IP ne sont pas impactées.Cependant mon adresse IP externe change forcément.
Est ce que cela pourrait générer des problèmes avec OpenVPN ? Sachant que j’effectue cette opération régulièrement depuis 1 an et que cela n’a jamais posé de problème dans le passé.

PS : Merci pour la note sur les droits, j’étais passé au travers.

Ce n’est pas le log openvpn qu’il faut regarder, comme dit par @SWR

Vérifiez dans la config jeedom, onglet sécurité, s’il y a des ip bannies la prochaine fois que cela arrive.
Mais votre ip publique ne devrait pas avoir d’influence la-dessus, c’est bien l’ip client qui s’y trouverait.

Vérifiez aussi que vous n’avez pas un addon sur le navigateur qui causerait un problème, comme un bloqueur de pub.

D’après moi le changement d’ip externe ne cause aucun soucis.

Bonjour,
Bon ça recommence depuis ce matin…
Coté IP Bannies, c’est vide :

Piste bloqueur de pub : Pas mieux avec Chrome, et je suis bloqué aussi via l’application Jeedom sur mon mobile donc on peut écarter je pense. De plus cela a parfaitement fonctionné cette semaine.

Coté Log, j’ai juste une trace dans http.error , les autres logs sont cleans.

0935|[Fri Mar 04 20:32:29.729894 2022] [core:notice] [pid 6429] AH00052: child pid 1114 exit signal Segmentation fault (11)
0936|[Fri Mar 04 20:32:29.730318 2022] [mpm_prefork:notice] [pid 6429] AH00169: caught SIGTERM, shutting down
0937|[Fri Mar 04 20:32:30.030979 2022] [mpm_prefork:notice] [pid 2814] AH00163: Apache/2.4.38 (Raspbian) configured -- resuming normal operations
0938|[Fri Mar 04 20:32:30.031161 2022] [core:notice] [pid 2814] AH00094: Command line: '/usr/sbin/apache2'
0939|warning: commands will be executed using /bin/sh
0940|job 3222 at Fri Mar  4 20:36:00 2022
0941|[Sat Mar 05 13:17:09.005103 2022] [mpm_prefork:notice] [pid 627] AH00163: Apache/2.4.38 (Raspbian) configured -- resuming normal operations
0942|[Sat Mar 05 13:17:09.005980 2022] [core:notice] [pid 627] AH00094: Command line: '/usr/sbin/apache2'
0943|warning: commands will be executed using /bin/sh
0944|job 3223 at Sat Mar  5 15:00:00 2022
0945|Failed to set wall message, ignoring: Message recipient disconnected from message bus without replying
0946|[Sat Mar 05 15:28:35.596348 2022] [core:notice] [pid 627] AH00052: child pid 31554 exit signal Segmentation fault (11)
0947|[Sat Mar 05 15:28:35.683591 2022] [core:notice] [pid 627] AH00052: child pid 682 exit signal Segmentation fault (11)
0948|[Sat Mar 05 15:28:35.683803 2022] [core:notice] [pid 627] AH00052: child pid 31517 exit signal Segmentation fault (11)
0949|[Sat Mar 05 15:28:35.683952 2022] [core:notice] [pid 627] AH00052: child pid 8803 exit signal Segmentation fault (11)
0950|[Sat Mar 05 15:28:36.686352 2022] [mpm_prefork:notice] [pid 627] AH00169: caught SIGTERM, shutting down
0951|[Sat Mar 05 15:28:44.293935 2022] [mpm_prefork:notice] [pid 677] AH00163: Apache/2.4.38 (Raspbian) configured -- resuming normal operations
0952|[Sat Mar 05 15:28:44.294423 2022] [core:notice] [pid 677] AH00094: Command line: '/usr/sbin/apache2'
0953|[Fri Mar 11 13:02:21.824338 2022] [access_compat:error] [pid 31614] [client 10.0.0.105:57765] AH01797: client denied by server configuration: /var/www/html/"soundbank:, referer: http://10.0.0.100/index.php?v=d&p=log
0954|[Fri Mar 11 13:02:21.836816 2022] [access_compat:error] [pid 10325] [client 10.0.0.105:57864] AH01797: client denied by server configuration: /var/www/html/"soundbank:, referer: http://10.0.0.100/index.php?v=d&p=log
0955|[Fri Mar 11 13:02:21.838037 2022] [access_compat:error] [pid 9485] [client 10.0.0.105:57863] AH01797: client denied by server configuration: /var/www/html/"soundbank:, referer: http://10.0.0.100/index.php?v=d&p=log
0956|[Fri Mar 11 13:02:21.838050 2022] [access_compat:error] [pid 9454] [client 10.0.0.105:57865] AH01797: client denied by server configuration: /var/www/html/"soundbank:, referer: http://10.0.0.100/index.php?v=d&p=log
0957|[Fri Mar 11 13:02:21.838792 2022] [access_compat:error] [pid 31176] [client 10.0.0.105:57866] AH01797: client denied by server configuration: /var/www/html/"soundbank:, referer: http://10.0.0.100/index.php?v=d&p=log
0958|[Fri Mar 11 13:02:21.839061 2022] [access_compat:error] [pid 31614] [client 10.0.0.105:57765] AH01797: client denied by server configuration: /var/www/html/"soundbank:, referer: http://10.0.0.100/index.php?v=d&p=log
0959|[Fri Mar 11 13:02:21.843241 2022] [access_compat:error] [pid 10325] [client 10.0.0.105:57864] AH01797: client denied by server configuration: /var/www/html/"soundbank:, referer: http://10.0.0.100/index.php?v=d&p=log
0960|[Fri Mar 11 13:02:21.843703 2022] [access_compat:error] [pid 31614] [client 10.0.0.105:57765] AH01797: client denied by server configuration: /var/www/html/"soundbank:, referer: http://10.0.0.100/index.php?v=d&p=log
0961|[Fri Mar 11 13:02:21.844088 2022] [access_compat:error] [pid 9485] [client 10.0.0.105:57863] AH01797: client denied by server configuration: /var/www/html/"soundbank:, referer: http://10.0.0.100/index.php?v=d&p=log
0962|[Fri Mar 11 13:02:22.959766 2022] [access_compat:error] [pid 31614] [client 10.0.0.105:57765] AH01797: client denied by server configuration: /var/www/html/"soundbank:, referer: http://10.0.0.100/index.php?v=d&p=log
0963|[Fri Mar 11 13:02:22.960717 2022] [access_compat:error] [pid 9454] [client 10.0.0.105:57865] AH01797: client denied by server configuration: /var/www/html/"soundbank:, referer: http://10.0.0.100/index.php?v=d&p=log
0964|[Fri Mar 11 13:02:22.961459 2022] [access_compat:error] [pid 31176] [client 10.0.0.105:57866] AH01797: client denied by server configuration: /var/www/html/"soundbank:, referer: http://10.0.0.100/index.php?v=d&p=log
0965|[Fri Mar 11 13:02:22.962517 2022] [access_compat:error] [pid 10325] [client 10.0.0.105:57864] AH01797: client denied by server configuration: /var/www/html/"soundbank:, referer: http://10.0.0.100/index.php?v=d&p=log
0966|[Fri Mar 11 13:02:22.963088 2022] [access_compat:error] [pid 9485] [client 10.0.0.105:57863] AH01797: client denied by server configuration: /var/www/html/"soundbank:, referer: http://10.0.0.100/index.php?v=d&p=log
0967|[Fri Mar 11 13:02:22.964462 2022] [access_compat:error] [pid 31614] [client 10.0.0.105:57765] AH01797: client denied by server configuration: /var/www/html/"soundbank:, referer: http://10.0.0.100/index.php?v=d&p=log
0968|[Fri Mar 11 13:02:22.966272 2022] [access_compat:error] [pid 9454] [client 10.0.0.105:57865] AH01797: client denied by server configuration: /var/www/html/"soundbank:, referer: http://10.0.0.100/index.php?v=d&p=log
0969|[Fri Mar 11 13:02:22.966453 2022] [access_compat:error] [pid 31176] [client 10.0.0.105:57866] AH01797: client denied by server configuration: /var/www/html/"soundbank:, referer: http://10.0.0.100/index.php?v=d&p=log
0970|[Fri Mar 11 13:02:22.968122 2022] [access_compat:error] [pid 10325] [client 10.0.0.105:57864] AH01797: client denied by server configuration: /var/www/html/"soundbank:, referer: http://10.0.0.100/index.php?v=d&p=log
0971|[Fri Mar 11 13:02:24.044768 2022] [access_compat:error] [pid 31614] [client 10.0.0.105:57765] AH01797: client denied by server configuration: /var/www/html/"soundbank:, referer: http://10.0.0.100/index.php?v=d&p=log
0972|[Fri Mar 11 13:02:24.044949 2022] [access_compat:error] [pid 9485] [client 10.0.0.105:57863] AH01797: client denied by server configuration: /var/www/html/"soundbank:, referer: http://10.0.0.100/index.php?v=d&p=log
0973|[Fri Mar 11 13:02:24.045881 2022] [access_compat:error] [pid 9454] [client 10.0.0.105:57865] AH01797: client denied by server configuration: /var/www/html/"soundbank:, referer: http://10.0.0.100/index.php?v=d&p=log
0974|[Fri Mar 11 13:02:24.046552 2022] [access_compat:error] [pid 31176] [client 10.0.0.105:57866] AH01797: client denied by server configuration: /var/www/html/"soundbank:, referer: http://10.0.0.100/index.php?v=d&p=log
0975|[Fri Mar 11 13:02:24.047908 2022] [access_compat:error] [pid 10325] [client 10.0.0.105:57864] AH01797: client denied by server configuration: /var/www/html/"soundbank:, referer: http://10.0.0.100/index.php?v=d&p=log
0976|[Fri Mar 11 13:02:24.050196 2022] [access_compat:error] [pid 27541] [client 10.0.0.105:57770] AH01797: client denied by server configuration: /var/www/html/"soundbank:, referer: http://10.0.0.100/index.php?v=d&p=log
0977|[Fri Mar 11 13:02:24.050634 2022] [access_compat:error] [pid 31614] [client 10.0.0.105:57765] AH01797: client denied by server configuration: /var/www/html/"soundbank:, referer: http://10.0.0.100/index.php?v=d&p=log
0978|[Fri Mar 11 13:02:24.051375 2022] [access_compat:error] [pid 9485] [client 10.0.0.105:57863] AH01797: client denied by server configuration: /var/www/html/"soundbank:, referer: http://10.0.0.100/index.php?v=d&p=log
0979|[Fri Mar 11 13:02:24.052572 2022] [access_compat:error] [pid 10325] [client 10.0.0.105:57864] AH01797: client denied by server configuration: /var/www/html/"soundbank:, referer: http://10.0.0.100/index.php?v=d&p=log
0980|[Fri Mar 11 13:02:25.154292 2022] [access_compat:error] [pid 31614] [client 10.0.0.105:57765] AH01797: client denied by server configuration: /var/www/html/"soundbank:, referer: http://10.0.0.100/index.php?v=d&p=log
0981|[Fri Mar 11 13:02:25.154531 2022] [access_compat:error] [pid 27541] [client 10.0.0.105:57770] AH01797: client denied by server configuration: /var/www/html/"soundbank:, referer: http://10.0.0.100/index.php?v=d&p=log
0982|[Fri Mar 11 13:02:25.155716 2022] [access_compat:error] [pid 31176] [client 10.0.0.105:57866] AH01797: client denied by server configuration: /var/www/html/"soundbank:, referer: http://10.0.0.100/index.php?v=d&p=log
0983|[Fri Mar 11 13:02:25.158175 2022] [access_compat:error] [pid 10325] [client 10.0.0.105:57864] AH01797: client denied by server configuration: /var/www/html/"soundbank:, referer: http://10.0.0.100/index.php?v=d&p=log
0984|[Fri Mar 11 13:02:25.158175 2022] [access_compat:error] [pid 9485] [client 10.0.0.105:57863] AH01797: client denied by server configuration: /var/www/html/"soundbank:, referer: http://10.0.0.100/index.php?v=d&p=log
0985|[Fri Mar 11 13:02:25.159734 2022] [access_compat:error] [pid 31614] [client 10.0.0.105:57765] AH01797: client denied by server configuration: /var/www/html/"soundbank:, referer: http://10.0.0.100/index.php?v=d&p=log
0986|[Fri Mar 11 13:02:25.162667 2022] [access_compat:error] [pid 27541] [client 10.0.0.105:57770] AH01797: client denied by server configuration: /var/www/html/"soundbank:, referer: http://10.0.0.100/index.php?v=d&p=log
0987|[Fri Mar 11 13:02:25.163635 2022] [access_compat:error] [pid 31614] [client 10.0.0.105:57765] AH01797: client denied by server configuration: /var/www/html/"soundbank:, referer: http://10.0.0.100/index.php?v=d&p=log
0988|[Fri Mar 11 13:02:25.166537 2022] [access_compat:error] [pid 31176] [client 10.0.0.105:57866] AH01797: client denied by server configuration: /var/www/html/"soundbank:, referer: http://10.0.0.100/index.php?v=d&p=log
0989|[Fri Mar 11 13:02:26.260733 2022] [access_compat:error] [pid 31614] [client 10.0.0.105:57765] AH01797: client denied by server configuration: /var/www/html/"soundbank:, referer: http://10.0.0.100/index.php?v=d&p=log
0990|[Fri Mar 11 13:02:26.262067 2022] [access_compat:error] [pid 9454] [client 10.0.0.105:57865] AH01797: client denied by server configuration: /var/www/html/"soundbank:, referer: http://10.0.0.100/index.php?v=d&p=log
0991|[Fri Mar 11 13:02:26.263186 2022] [access_compat:error] [pid 9485] [client 10.0.0.105:57863] AH01797: client denied by server configuration: /var/www/html/"soundbank:, referer: http://10.0.0.100/index.php?v=d&p=log
0992|[Fri Mar 11 13:02:26.263850 2022] [access_compat:error] [pid 10325] [client 10.0.0.105:57864] AH01797: client denied by server configuration: /var/www/html/"soundbank:, referer: http://10.0.0.100/index.php?v=d&p=log
0993|[Fri Mar 11 13:02:26.265321 2022] [access_compat:error] [pid 31614] [client 10.0.0.105:57765] AH01797: client denied by server configuration: /var/www/html/"soundbank:, referer: http://10.0.0.100/index.php?v=d&p=log
0994|[Fri Mar 11 13:02:26.266399 2022] [access_compat:error] [pid 9454] [client 10.0.0.105:57865] AH01797: client denied by server configuration: /var/www/html/"soundbank:, referer: http://10.0.0.100/index.php?v=d&p=log
0995|[Fri Mar 11 13:02:26.267660 2022] [access_compat:error] [pid 31176] [client 10.0.0.105:57866] AH01797: client denied by server configuration: /var/www/html/"soundbank:, referer: http://10.0.0.100/index.php?v=d&p=log
0996|[Fri Mar 11 13:02:26.268649 2022] [access_compat:error] [pid 31614] [client 10.0.0.105:57765] AH01797: client denied by server configuration: /var/www/html/"soundbank:, referer: http://10.0.0.100/index.php?v=d&p=log
0997|[Fri Mar 11 13:02:26.269735 2022] [access_compat:error] [pid 9454] [client 10.0.0.105:57865] AH01797: client denied by server configuration: /var/www/html/"soundbank:, referer: http://10.0.0.100/index.php?v=d&p=log
0998|[Fri Mar 11 13:08:33.005733 2022] [access_compat:error] [pid 2891] [client 10.0.0.105:58275] AH01797: client denied by server configuration: /var/www/html/live, referer: http://10.0.0.100/index.php?v=d&p=dashboard
0999|[Fri Mar 11 13:11:06.006601 2022] [access_compat:error] [pid 31614] [client 10.0.0.105:58413] AH01797: client denied by server configuration: /var/www/html/live, referer: http://10.0.0.100/index.php?v=d&p=dashboard

Entre le 5 et le 11 mars ca marchait parfaitement.