<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic iLO2 no longer authenticating AD users in Server Management - Remote Server Management</title>
    <link>https://community.hpe.com/t5/server-management-remote-server/ilo2-no-longer-authenticating-ad-users/m-p/5234184#M6707</link>
    <description>&lt;!--!*#--&gt;We have upgraded to iLO firmware 1.81 recently, using firmware boot CD 7.9 in around 230 HP servers and blades.&lt;BR /&gt;Now we can no longer authenticate against AD and can only authenticate with either a local iLO user or the AD Display name of a user.&lt;BR /&gt;We used to be able to log in with;&lt;BR /&gt;&lt;BR /&gt;DOMAIN\username&lt;BR /&gt;Username@domain.com&lt;BR /&gt;Username&lt;BR /&gt;&lt;BR /&gt;And now it results in failure for each of these valid logins, and the only way we can authenticate is with;&lt;BR /&gt;&lt;BR /&gt;Surname\, Firstname - Job role&lt;BR /&gt;&lt;BR /&gt;which is the AD Name (not even the display name).&lt;BR /&gt;So, I know that LDAP authentication is working (because I can log in with the above name), but I cannot authenticate with any "usable" username.&lt;BR /&gt;We have an AD structure that organises accounts under location and type, so I have entered the following search contexts;&lt;BR /&gt;&lt;BR /&gt;ou=Users,OU=Site1,OU=City1,OU=State1,OU=Country,DC=Domain,DC=com&lt;BR /&gt;ou=Users,OU=Site2,OU=City2,OU=State2,OU=Country,DC=Domain,DC=com&lt;BR /&gt;@domain.com&lt;BR /&gt;DOMAIN&lt;BR /&gt;CN=AdminGroup,OU=Groups,OU=Site1,OU=City1,OU=State1,OU=Country,DC=Domain,DC=com&lt;BR /&gt;&lt;BR /&gt;And my account exists in four of these search contexts. I can authenticate OK, but not with a normal format to the same account - I get "User Object Cannot be Found" when I test the settings. I have checked capitalisation and spacing, and tried every combination I can think of, but the only one that works is the Name in AD (which is not the same as the Outlook/Exchange "Display Name").&lt;BR /&gt;&lt;BR /&gt;I have tried this with IE6,7 and 8&lt;BR /&gt;AD is Windows 2003 &lt;BR /&gt;This worked before...&lt;BR /&gt;&lt;BR /&gt;Can anyone help?</description>
    <pubDate>Fri, 09 Apr 2010 03:15:17 GMT</pubDate>
    <dc:creator>ChristianWickham</dc:creator>
    <dc:date>2010-04-09T03:15:17Z</dc:date>
    <item>
      <title>iLO2 no longer authenticating AD users</title>
      <link>https://community.hpe.com/t5/server-management-remote-server/ilo2-no-longer-authenticating-ad-users/m-p/5234184#M6707</link>
      <description>&lt;!--!*#--&gt;We have upgraded to iLO firmware 1.81 recently, using firmware boot CD 7.9 in around 230 HP servers and blades.&lt;BR /&gt;Now we can no longer authenticate against AD and can only authenticate with either a local iLO user or the AD Display name of a user.&lt;BR /&gt;We used to be able to log in with;&lt;BR /&gt;&lt;BR /&gt;DOMAIN\username&lt;BR /&gt;Username@domain.com&lt;BR /&gt;Username&lt;BR /&gt;&lt;BR /&gt;And now it results in failure for each of these valid logins, and the only way we can authenticate is with;&lt;BR /&gt;&lt;BR /&gt;Surname\, Firstname - Job role&lt;BR /&gt;&lt;BR /&gt;which is the AD Name (not even the display name).&lt;BR /&gt;So, I know that LDAP authentication is working (because I can log in with the above name), but I cannot authenticate with any "usable" username.&lt;BR /&gt;We have an AD structure that organises accounts under location and type, so I have entered the following search contexts;&lt;BR /&gt;&lt;BR /&gt;ou=Users,OU=Site1,OU=City1,OU=State1,OU=Country,DC=Domain,DC=com&lt;BR /&gt;ou=Users,OU=Site2,OU=City2,OU=State2,OU=Country,DC=Domain,DC=com&lt;BR /&gt;@domain.com&lt;BR /&gt;DOMAIN&lt;BR /&gt;CN=AdminGroup,OU=Groups,OU=Site1,OU=City1,OU=State1,OU=Country,DC=Domain,DC=com&lt;BR /&gt;&lt;BR /&gt;And my account exists in four of these search contexts. I can authenticate OK, but not with a normal format to the same account - I get "User Object Cannot be Found" when I test the settings. I have checked capitalisation and spacing, and tried every combination I can think of, but the only one that works is the Name in AD (which is not the same as the Outlook/Exchange "Display Name").&lt;BR /&gt;&lt;BR /&gt;I have tried this with IE6,7 and 8&lt;BR /&gt;AD is Windows 2003 &lt;BR /&gt;This worked before...&lt;BR /&gt;&lt;BR /&gt;Can anyone help?</description>
      <pubDate>Fri, 09 Apr 2010 03:15:17 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-remote-server/ilo2-no-longer-authenticating-ad-users/m-p/5234184#M6707</guid>
      <dc:creator>ChristianWickham</dc:creator>
      <dc:date>2010-04-09T03:15:17Z</dc:date>
    </item>
    <item>
      <title>Re: iLO2 no longer authenticating AD users</title>
      <link>https://community.hpe.com/t5/server-management-remote-server/ilo2-no-longer-authenticating-ad-users/m-p/5234185#M6708</link>
      <description>Christian, &lt;BR /&gt;&lt;BR /&gt;First check your iLo2 networking configuration and ensure that they have at least one DNS server listed.  &lt;BR /&gt;&lt;BR /&gt;Login to iLO2, Administration tab, Network link, DHCP/DNS tab, Primary DNS Server. &lt;BR /&gt;&lt;BR /&gt;CHris H. &lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Fri, 09 Apr 2010 14:21:24 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-remote-server/ilo2-no-longer-authenticating-ad-users/m-p/5234185#M6708</guid>
      <dc:creator>Chris Hasler</dc:creator>
      <dc:date>2010-04-09T14:21:24Z</dc:date>
    </item>
    <item>
      <title>Re: iLO2 no longer authenticating AD users</title>
      <link>https://community.hpe.com/t5/server-management-remote-server/ilo2-no-longer-authenticating-ad-users/m-p/5234186#M6709</link>
      <description>&lt;!--!*#--&gt;Yes, there are three fully functioning DNS servers configured in each of the iLO systems that we have been testing with (tried 4 iLO systems in 2 sites).&lt;BR /&gt;I have tested that other LDAP enabled systems work (we also have OA for Blades configured the same way, and it works perfectly), I have also verified that I get a certificate when I hit https://domain:636&lt;BR /&gt;&lt;BR /&gt;As I said before, it works fine every time if I use the LDAP CN name, even if the account is buried deep in an OU structure, so the search contexts are correct and the access to the DC is correct - iLO is just not accepting login in the format we want to use of &lt;BR /&gt;DOMAIN\username&lt;BR /&gt;Username@domain.com&lt;BR /&gt;Username&lt;BR /&gt;We can't use the CN name of a user because of the way they are named - too easy to make a mistake.&lt;BR /&gt;&lt;BR /&gt;I see from other postings that people have a similar problem, but no answers - is this a bug that has been accepted by HP as needing to be fixed?</description>
      <pubDate>Fri, 09 Apr 2010 21:30:32 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-remote-server/ilo2-no-longer-authenticating-ad-users/m-p/5234186#M6709</guid>
      <dc:creator>ChristianWickham</dc:creator>
      <dc:date>2010-04-09T21:30:32Z</dc:date>
    </item>
    <item>
      <title>Re: iLO2 no longer authenticating AD users</title>
      <link>https://community.hpe.com/t5/server-management-remote-server/ilo2-no-longer-authenticating-ad-users/m-p/5234187#M6710</link>
      <description>The change is in Internet Options, under the Internet zone, within “ActiveX Controls and Plug-ins” - if your iLOs are in the same subnet as you, then this change should be in Intranet zone&lt;BR /&gt;&lt;BR /&gt;Parameter “Initialize and script ActiveX controls not marked as safe for scripting”&lt;BR /&gt;Change from “Disable”&lt;BR /&gt;Change to “Prompt”&lt;BR /&gt;</description>
      <pubDate>Tue, 18 May 2010 06:49:56 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-remote-server/ilo2-no-longer-authenticating-ad-users/m-p/5234187#M6710</guid>
      <dc:creator>ChristianWickham</dc:creator>
      <dc:date>2010-05-18T06:49:56Z</dc:date>
    </item>
  </channel>
</rss>

