<?xml version="1.0" encoding="UTF-8" ?>

<bugzilla version="5.2"
          urlbase="https://bugzilla.altlinux.org/"
          
          maintainer="jenya@basealt.ru"
>

    <bug>
          <bug_id>37247</bug_id>
          
          <creation_ts>2019-09-20 16:28:50 +0300</creation_ts>
          <short_desc>Не работает &quot;из коробки&quot; NetworkManager-openconnect</short_desc>
          <delta_ts>2025-02-20 21:46:36 +0300</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>4</classification_id>
          <classification>Development</classification>
          <product>Sisyphus</product>
          <component>NetworkManager-openconnect</component>
          <version>unstable</version>
          <rep_platform>all</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>NEW</bug_status>
          <resolution></resolution>
          
          <see_also>https://bugzilla.altlinux.org/show_bug.cgi?id=39203</see_also>
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords></keywords>
          <priority>P3</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="AEN">aen</reporter>
          <assigned_to name="Alexey Shabalin">shaba</assigned_to>
          <cc>boyarsh</cc>
    
    <cc>lav</cc>
    
    <cc>lkanter</cc>
    
    <cc>sem</cc>
    
    <cc>shaba</cc>
    
    <cc>xecoder</cc>
          
          <qa_contact>qa-sisyphus</qa_contact>

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>184435</commentid>
    <comment_count>0</comment_count>
    <who name="AEN">aen</who>
    <bug_when>2019-09-20 16:28:50 +0300</bug_when>
    <thetext>Сообщение Лени Кантера:
&quot;А кто у Вас занимается плагинами NetworkManager
Поставил 9-ю платформу оценить пригодность, сразу столкнулся с проблемой
Server &apos;xxxx&apos; requested Basic authentication which is disabled by default

из командной стороки openconnect подключается молча, так что это точно с плагином связана ошибка</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>184490</commentid>
    <comment_count>1</comment_count>
    <who name="AEN">aen</who>
    <bug_when>2019-09-23 12:28:55 +0300</bug_when>
    <thetext>Алексей, прошу проверить.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>184541</commentid>
    <comment_count>2</comment_count>
    <who name="Leonid Kanter">lkanter</who>
    <bug_when>2019-09-23 22:54:24 +0300</bug_when>
    <thetext>На сервере стоит пакет ocserv из CentOS 7. Протокол подключения из командной строки с включенным дампом до запроса пароля:

# openconnect -vvv --dump https://vpn-atm.corp.cloudlinux.com/
POST https://vpn-atm.corp.cloudlinux.com/
Attempting to connect to server 77.79.198.23:443
Connected to 77.79.198.23:443
SSL negotiation with vpn-atm.corp.cloudlinux.com
Connected to HTTPS on vpn-atm.corp.cloudlinux.com
&gt; POST / HTTP/1.1
&gt; Host: vpn-atm.corp.cloudlinux.com
&gt; User-Agent: Open AnyConnect VPN Agent v8.05
&gt; Accept: */*
&gt; Accept-Encoding: identity
&gt; X-Transcend-Version: 1
&gt; X-Aggregate-Auth: 1
&gt; X-AnyConnect-Platform: linux-64
&gt; X-Support-HTTP-Auth: true
&gt; X-Pad: 00000000000000000000000000000000000
&gt; Content-Type: application/x-www-form-urlencoded
&gt; Content-Length: 221
&gt; 
&gt; &lt;?xml version=&quot;1.0&quot; encoding=&quot;UTF-8&quot;?&gt;
&gt; &lt;config-auth client=&quot;vpn&quot; type=&quot;init&quot;&gt;&lt;version who=&quot;vpn&quot;&gt;v8.05&lt;/version&gt;&lt;device-id&gt;linux-64&lt;/device-id&gt;&lt;group-access&gt;https://vpn-atm.corp.cloudlinux.com&lt;/group-access&gt;&lt;/config-auth&gt;
Got HTTP response: HTTP/1.1 401 Unauthorized
X-HTTP-Auth-Support: fallback
WWW-Authenticate: Negotiate
Content-Length: 0
HTTP body length:  (0)
Error generating GSSAPI response:
gss_init_sec_context(): Unspecified GSS failure.  Minor code may provide more information
gss_init_sec_context(): SPNEGO cannot find mechanisms to negotiate
Server &apos;vpn-atm.corp.cloudlinux.com&apos; requested Basic authentication which is disabled by default
GET https://vpn-atm.corp.cloudlinux.com/
Attempting to connect to server 77.79.198.23:443
Connected to 77.79.198.23:443
SSL negotiation with vpn-atm.corp.cloudlinux.com
Connected to HTTPS on vpn-atm.corp.cloudlinux.com
&gt; GET / HTTP/1.1
&gt; Host: vpn-atm.corp.cloudlinux.com
&gt; User-Agent: Open AnyConnect VPN Agent v8.05
&gt; Accept: */*
&gt; Accept-Encoding: identity
&gt; X-Transcend-Version: 1
&gt; X-Support-HTTP-Auth: true
&gt; 
Got HTTP response: HTTP/1.1 401 Unauthorized
X-HTTP-Auth-Support: fallback
WWW-Authenticate: Negotiate
Content-Length: 0
HTTP body length:  (0)
No more authentication methods to try
GET https://vpn-atm.corp.cloudlinux.com/
&gt; GET / HTTP/1.1
&gt; Host: vpn-atm.corp.cloudlinux.com
&gt; User-Agent: Open AnyConnect VPN Agent v8.05
&gt; Accept: */*
&gt; Accept-Encoding: identity
&gt; X-Transcend-Version: 1
&gt; 
Got HTTP response: HTTP/1.1 200 OK
Set-Cookie: webvpncontext=; expires=Thu, 01 Jan 1970 22:00:00 GMT; path=/; Secure
Content-Type: text/xml
Content-Length: 306
X-Transcend-Version: 1
HTTP body length:  (306)
&lt; &lt;?xml version=&quot;1.0&quot; encoding=&quot;UTF-8&quot;?&gt;
&lt; &lt;config-auth client=&quot;vpn&quot; type=&quot;auth-request&quot;&gt;
&lt; &lt;version who=&quot;sg&quot;&gt;0.1(1)&lt;/version&gt;
&lt; &lt;auth id=&quot;main&quot;&gt;
&lt; &lt;message&gt;Please enter your username.&lt;/message&gt;
&lt; &lt;form method=&quot;post&quot; action=&quot;/auth&quot;&gt;
&lt; &lt;input type=&quot;text&quot; name=&quot;username&quot; label=&quot;Username:&quot; /&gt;
&lt; &lt;/form&gt;&lt;/auth&gt;
&lt; &lt;/config-auth&gt;
Please enter your username.
Username:</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>184556</commentid>
    <comment_count>3</comment_count>
    <who name="Mikhail Efremov">sem</who>
    <bug_when>2019-09-24 14:45:15 +0300</bug_when>
    <thetext>Могу предположить, что мешает первая попытка использовать Basic authentication, видимо плагин не умеет обрабатывать такую ситуацию.
Возможно если на сервере выключить Basic authentication, то заработает.
Но надо проверять.</thetext>
  </long_desc>
      
      

    </bug>

</bugzilla>