<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: LDAP authentication not matching user groups in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-authentication-not-matching-user-groups/m-p/37035#M27185</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Where do I do that? As far as I know, it is, but I followed a rather old document based on V3 PA software in setting this up, so I could have done something wrong somewhere.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 21 Nov 2012 03:59:15 GMT</pubDate>
    <dc:creator>darren_g</dc:creator>
    <dc:date>2012-11-21T03:59:15Z</dc:date>
    <item>
      <title>LDAP authentication not matching user groups</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-authentication-not-matching-user-groups/m-p/37025#M27175</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've got LDAP authentication configured to allow users into a Global protect portal. I'm 100% sure it works OK, because I can authenticate against it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Trouble is, I *can't* get it to authenticate against an Active Directory group. if I add individual usernames into the authentication profile used by the Global Protect setup, they work - which is how I know the LDAP is working/&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I add an AD user GROUP to the allow list, it simply doesn't match any users - Global Protect authentication fails with a "user not in allow list" error.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any suggestions on how I can best troubleshoot/fix this? I don't want to have to modify the Firewall config every time I need to add a new VPN user - especially when other admins can modify the AD groups much more easily.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 31 Oct 2012 00:57:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-authentication-not-matching-user-groups/m-p/37025#M27175</guid>
      <dc:creator>darren_g</dc:creator>
      <dc:date>2012-10-31T00:57:58Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP authentication not matching user groups</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-authentication-not-matching-user-groups/m-p/37026#M27176</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Darren,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Which version of PAN OS are you running? &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Nov 2012 00:05:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-authentication-not-matching-user-groups/m-p/37026#M27176</guid>
      <dc:creator>zarina</dc:creator>
      <dc:date>2012-11-21T00:05:09Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP authentication not matching user groups</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-authentication-not-matching-user-groups/m-p/37027#M27177</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Also make sure the login name has nothing appended to it and matched the username in the group.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From CLI:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; show user group name "nameofgroup"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt;&amp;gt; Make sure the name is listed there&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;tail follow yes mp-log authd.log&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then attempt to login and see if the username that is being received matches the same as the way it is displayed in the group listing. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dominic&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Nov 2012 01:59:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-authentication-not-matching-user-groups/m-p/37027#M27177</guid>
      <dc:creator>dburns</dc:creator>
      <dc:date>2012-11-21T01:59:21Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP authentication not matching user groups</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-authentication-not-matching-user-groups/m-p/37028#M27178</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;4.1.9 now - was 4.1.7 at the time I posted the question&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Nov 2012 02:03:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-authentication-not-matching-user-groups/m-p/37028#M27178</guid>
      <dc:creator>darren_g</dc:creator>
      <dc:date>2012-11-21T02:03:19Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP authentication not matching user groups</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-authentication-not-matching-user-groups/m-p/37029#M27179</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;
&lt;P&gt;Dominic Burns wrote:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Also make sure the login name has nothing appended to it and matched the username in the group.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;From CLI:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; show user group name "nameofgroup"&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&amp;gt;&amp;gt; Make sure the name is listed there&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;tail follow yes mp-log authd.log&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Then attempt to login and see if the username that is being received matches the same as the way it is displayed in the group listing.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Dominic&lt;/P&gt;

&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The first command definitely shows all users in the group concerned.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[abbreviated and offuscated list]&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/mailto:darren@Gate(active/"&gt;darren@Gate(active&lt;/A&gt;)&amp;gt; show user group name domain\vpn-users&lt;/P&gt;&lt;P&gt;group short name: domain\vpn-users&lt;/P&gt;&lt;P&gt;[...]&lt;/P&gt;&lt;P&gt;[15&amp;nbsp;&amp;nbsp;&amp;nbsp; ] domain\darren.gibbs&lt;/P&gt;&lt;P&gt;[...]&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, you can see I am in the group, and the firewall recognises I am in the group.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Doing the second (I removed myself from the individual allow-list configuration and relied on the AD group membership) got me this&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Nov 21 13:16:15 pan_authd_service_req(pan_authd.c:2683): Authd:Trying to remote authenticate user: darren.gibbs&lt;/P&gt;&lt;P&gt;Nov 21 13:16:15 pan_authd_service_auth_req(pan_authd.c:1174): AUTH Request &amp;lt;'vsys1','VPNUsers','darren.gibbs'&amp;gt;&lt;/P&gt;&lt;P&gt;Nov 21 13:16:15 Error: pan_authd_get_sysd_multivsys(pan_authd.c:3606): failed to fetch: NO_MATCHES&lt;/P&gt;&lt;P&gt;Nov 21 13:16:15 panauth:user &amp;lt;darren.gibbs,VPNUsers,vsys1&amp;gt; is not allowed&lt;/P&gt;&lt;P&gt;Nov 21 13:16:15 pan_authd_process_authresult(pan_authd.c:1318): pan_authd_process_authresult: darren.gibbs authresult not auth'ed&lt;/P&gt;&lt;P&gt;Nov 21 13:16:15 pan_authd_process_authresult(pan_authd.c:1342): Alarm generation set to: False.&lt;/P&gt;&lt;P&gt;Nov 21 13:16:15 User 'darren.gibbs' failed authentication.&amp;nbsp; Reason: User is not in allowlist From: 110.142.210.164.&lt;/P&gt;&lt;P&gt;Nov 21 13:16:15 pan_get_system_cmd_output(pan_cfg_utils.c:3056): executing: /usr/local/bin/sdb -n -r cfg.operational-mode&lt;/P&gt;&lt;P&gt;Nov 21 13:16:15 pan_authd_generate_system_log(pan_authd.c:897): CC Enabled=False&lt;/P&gt;&lt;P&gt;Nov 21 13:16:15 pan_get_system_cmd_output(pan_cfg_utils.c:3056): executing: /usr/local/bin/sdb -n -r cfg.operational-mode&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any further suggestions welcomed.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Nov 2012 02:22:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-authentication-not-matching-user-groups/m-p/37029#M27179</guid>
      <dc:creator>darren_g</dc:creator>
      <dc:date>2012-11-21T02:22:14Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP authentication not matching user groups</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-authentication-not-matching-user-groups/m-p/37030#M27180</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Darren,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the allow list is the group listed in the "domain\groupname" format or as a DN string?&amp;nbsp; In 4.1.9 when you add an allow list entry the drop down is populated with the DN string representing the group, we have seen issues where this format doesn't match to the group lists on the firewall.&amp;nbsp; Could you try to enter the group to the allow list in the "domain\groupname" format and see if there is a change?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;-- Kevin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Nov 2012 02:48:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-authentication-not-matching-user-groups/m-p/37030#M27180</guid>
      <dc:creator>kfindlen</dc:creator>
      <dc:date>2012-11-21T02:48:21Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP authentication not matching user groups</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-authentication-not-matching-user-groups/m-p/37031#M27181</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Currently, it's configured as a DN string. I will change to "domain\groupname" format and see how it goes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Nov 2012 02:54:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-authentication-not-matching-user-groups/m-p/37031#M27181</guid>
      <dc:creator>darren_g</dc:creator>
      <dc:date>2012-11-21T02:54:33Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP authentication not matching user groups</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-authentication-not-matching-user-groups/m-p/37032#M27182</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Kevin.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No good. Same result. Authentication failed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Darren&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Nov 2012 02:59:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-authentication-not-matching-user-groups/m-p/37032#M27182</guid>
      <dc:creator>darren_g</dc:creator>
      <dc:date>2012-11-21T02:59:40Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP authentication not matching user groups</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-authentication-not-matching-user-groups/m-p/37033#M27183</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In my previous (now deleted) reply, I've spoken too soon.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;when I hit the web portal (where you can download the GlobalProtect client from), it authenticates, and appears to work fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I actually use the GlobalProtect *client*, the authentication fails.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is what happens when I hit the web portal&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Nov 21 14:22:34 pan_get_ldap_ip(pan_authd_passwd.c:120): Reading file /etc/openldap/pan_ldap_vsys1_:v:p:n:users_0&lt;/P&gt;&lt;P&gt;Nov 21 14:22:34 pan_authd_bind(pan_authd_passwd.c:244): binding with binddn CN=Administrator,CN=Users,DC=domain,DC=corp&lt;/P&gt;&lt;P&gt;Nov 21 14:22:34 pan_authd_ldap_search_result(pan_authd_passwd.c:357): searching base 'DC=domain,DC=corp' for (sAMAccountName=darren.gibbs) (userAccountControl)&lt;/P&gt;&lt;P&gt;Nov 21 14:22:34 pan_authd_ldap_search_result(pan_authd_passwd.c:380): DN in entry CN=Darren Gibbs,OU=T,OU=BO,OU=AU,DC=domain,DC=corp&lt;/P&gt;&lt;P&gt;Nov 21 14:22:34 process_ad_usracct(pan_authd_passwd.c:496): AD :Got value userAccountControl : 66048&lt;/P&gt;&lt;P&gt;Nov 21 14:22:34 pan_get_ad_passwd_expiry(pan_authd_passwd.c:687): userAccountControl = 66048&lt;/P&gt;&lt;P&gt;Nov 21 14:22:34 pan_get_ad_passwd_expiry(pan_authd_passwd.c:689): Password doesn't expire for username darren.gibbs&lt;/P&gt;&lt;P&gt;Nov 21 14:22:34 authentication succeeded for user &amp;lt;vsys1,VPNUsers,domain\darren.gibbs&amp;gt;&lt;/P&gt;&lt;P&gt;Nov 21 14:22:34 pan_authd_process_authresult(pan_authd.c:1318): pan_authd_process_authresult: domain\darren.gibbs authresult auth'ed&lt;/P&gt;&lt;P&gt;Nov 21 14:22:34 Request received to unlock vsys1/VPNUsers/domain\darren.gibbs&lt;/P&gt;&lt;P&gt;Nov 21 14:22:34 User 'aicorp\darren.gibbs' authenticated.&amp;nbsp;&amp;nbsp; From: xxx.www.yyy.zzz.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, when I use the GlobalProtect CLIENT, this is what I get&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Nov 21 14:23:42 authd_sysd_localprofile_callback(pan_authd.c:3659): localprofile sync triggered via sysd&lt;/P&gt;&lt;P&gt;Nov 21 14:23:42 authd_sysd_localprofile_callback(pan_authd.c:3679): get local info for vsys1/VPNUsers&lt;/P&gt;&lt;P&gt;Nov 21 14:24:57 pan_authd_service_req(pan_authd.c:2683): Authd:Trying to remote authenticate user: darren.gibbs&lt;/P&gt;&lt;P&gt;Nov 21 14:24:57 pan_authd_service_auth_req(pan_authd.c:1174): AUTH Request &amp;lt;'vsys1','VPNUsers','darren.gibbs'&amp;gt;&lt;/P&gt;&lt;P&gt;Nov 21 14:24:57 Error: pan_authd_get_sysd_multivsys(pan_authd.c:3606): failed to fetch: NO_MATCHES&lt;/P&gt;&lt;P&gt;Nov 21 14:24:57 panauth:user &amp;lt;darren.gibbs,VPNUsers,vsys1&amp;gt; is not allowed&lt;/P&gt;&lt;P&gt;Nov 21 14:24:57 pan_authd_process_authresult(pan_authd.c:1318): pan_authd_process_authresult: darren.gibbs authresult not auth'ed&lt;/P&gt;&lt;P&gt;Nov 21 14:24:57 pan_authd_process_authresult(pan_authd.c:1342): Alarm generation set to: False.&lt;/P&gt;&lt;P&gt;Nov 21 14:24:57 User 'darren.gibbs' failed authentication.&amp;nbsp; Reason: User is not in allowlist From: xxx.www.yyy.zzz&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So what gives? Why does it work with one authentication (via the web portal), and not with the actual VPN client??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyone?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Nov 2012 03:26:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-authentication-not-matching-user-groups/m-p/37033#M27183</guid>
      <dc:creator>darren_g</dc:creator>
      <dc:date>2012-11-21T03:26:12Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP authentication not matching user groups</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-authentication-not-matching-user-groups/m-p/37034#M27184</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you verify in your LDAP profile that the domain is specified?&amp;nbsp; It appears that when you login via GP your user is recognized as just "darren.gibbs", without the domain.&amp;nbsp; If the domain is not appended to the username then the group matching will fail since the firewall will compare the user string against the member list which all have the domain included.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Nov 2012 03:56:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-authentication-not-matching-user-groups/m-p/37034#M27184</guid>
      <dc:creator>kfindlen</dc:creator>
      <dc:date>2012-11-21T03:56:31Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP authentication not matching user groups</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-authentication-not-matching-user-groups/m-p/37035#M27185</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Where do I do that? As far as I know, it is, but I followed a rather old document based on V3 PA software in setting this up, so I could have done something wrong somewhere.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Nov 2012 03:59:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-authentication-not-matching-user-groups/m-p/37035#M27185</guid>
      <dc:creator>darren_g</dc:creator>
      <dc:date>2012-11-21T03:59:15Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP authentication not matching user groups</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-authentication-not-matching-user-groups/m-p/37036#M27186</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yee Ha! Found it! And what's more, it works! Login via the web portal *and* the GlobalProtect client works!! You're a legend, Kevin! Thanks so much for your input!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Nov 2012 04:06:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-authentication-not-matching-user-groups/m-p/37036#M27186</guid>
      <dc:creator>darren_g</dc:creator>
      <dc:date>2012-11-21T04:06:07Z</dc:date>
    </item>
  </channel>
</rss>

