<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Help configuring LDAP integration for BladeSystem OA login in BladeSystem - General</title>
    <link>https://community.hpe.com/t5/bladesystem-general/help-configuring-ldap-integration-for-bladesystem-oa-login/m-p/5147022#M15243</link>
    <description>Thank you, so, the Search contect should be in the form of OU= (not CN=) and point to the OU where the GROUPS are located. Check :)&lt;BR /&gt;&lt;BR /&gt;And I've added the actual groups in that OU that I want to grant access. &lt;BR /&gt;&lt;BR /&gt;But I still can't get things to work, I only get authentication success and authorization failure. So I must still be doing something wrong somewhere ?</description>
    <pubDate>Fri, 19 Dec 2008 15:26:29 GMT</pubDate>
    <dc:creator>Mikael Rönnbäck</dc:creator>
    <dc:date>2008-12-19T15:26:29Z</dc:date>
    <item>
      <title>Help configuring LDAP integration for BladeSystem OA login</title>
      <link>https://community.hpe.com/t5/bladesystem-general/help-configuring-ldap-integration-for-bladesystem-oa-login/m-p/5147015#M15236</link>
      <description>I am trying to configure LDAP integration for logging into our Blades using our AD-keys instead of a local user.&lt;BR /&gt;&lt;BR /&gt;I have read a few threads here, for example this, &lt;A href="http://forums11.itrc.hp.com/service/forums/questionanswer.do?threadId=1277300" target="_blank"&gt;http://forums11.itrc.hp.com/service/forums/questionanswer.do?threadId=1277300&lt;/A&gt;&lt;BR /&gt;but cannot seem to get everything in order.&lt;BR /&gt;&lt;BR /&gt;What happens is that when I run the LDAP tests I get a status of authentication = success but authorization = failed.&lt;BR /&gt;&lt;BR /&gt;In addition I can use HP SIM as single sign-on and get logged in with my AD-key, but that's not completely what I want.&lt;BR /&gt;&lt;BR /&gt;So obviously I have the servers in place and these settings correctly configured, but I am missing something in regards to actual access.&lt;BR /&gt;&lt;BR /&gt;So, what should I actually put into each field, I am not sure after reading the manual ( &lt;A href="http://h20000.www2.hp.com/bc/docs/support/SupportManual/c00705292/c00705292.pdf" target="_blank"&gt;http://h20000.www2.hp.com/bc/docs/support/SupportManual/c00705292/c00705292.pdf&lt;/A&gt; ) what should actually be in each field.&lt;BR /&gt;&lt;BR /&gt;Here's what I have&lt;BR /&gt;Directory Server address: myserver.mydomain.net&lt;BR /&gt;Directory Server SSL Port: 636&lt;BR /&gt;Search Context 1: OU=My  OU,CN=Admin,CN=MainOU,DC=mydomain,DC=net&lt;BR /&gt;&lt;BR /&gt;This is my first question, should the search context point to the path where the USER is or the path where the GROUP in which the user is a member is ?&lt;BR /&gt;&lt;BR /&gt;And in which case should CN= be used or OU= be used ? is CN= only for users or groups and OU= for OU's ? (As you can guess I am more comfortable with the ILO authentication settings and config syntax... :-))&lt;BR /&gt;&lt;BR /&gt;Additionally I have enabled the "Use NT Account Name Mapping (DOMAIN\username)" setting, is this only for easy login or for account lookup as well ?&lt;BR /&gt;&lt;BR /&gt;On top of this I have added two domain groups, using their AD names, and granted the groups Administrator access, and I am member of the groups.&lt;BR /&gt;&lt;BR /&gt;Still I get authorization failed ?</description>
      <pubDate>Thu, 18 Dec 2008 14:08:58 GMT</pubDate>
      <guid>https://community.hpe.com/t5/bladesystem-general/help-configuring-ldap-integration-for-bladesystem-oa-login/m-p/5147015#M15236</guid>
      <dc:creator>Mikael Rönnbäck</dc:creator>
      <dc:date>2008-12-18T14:08:58Z</dc:date>
    </item>
    <item>
      <title>Re: Help configuring LDAP integration for BladeSystem OA login</title>
      <link>https://community.hpe.com/t5/bladesystem-general/help-configuring-ldap-integration-for-bladesystem-oa-login/m-p/5147016#M15237</link>
      <description>Have you seen the threads on the iLO forum?&lt;BR /&gt;&lt;A href="http://forums11.itrc.hp.com/service/forums/categoryhome.do?categoryId=298" target="_blank"&gt;http://forums11.itrc.hp.com/service/forums/categoryhome.do?categoryId=298&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;There are a lot more on the ILO/OA AD integration.</description>
      <pubDate>Thu, 18 Dec 2008 15:16:02 GMT</pubDate>
      <guid>https://community.hpe.com/t5/bladesystem-general/help-configuring-ldap-integration-for-bladesystem-oa-login/m-p/5147016#M15237</guid>
      <dc:creator>Adrian Clint</dc:creator>
      <dc:date>2008-12-18T15:16:02Z</dc:date>
    </item>
    <item>
      <title>Re: Help configuring LDAP integration for BladeSystem OA login</title>
      <link>https://community.hpe.com/t5/bladesystem-general/help-configuring-ldap-integration-for-bladesystem-oa-login/m-p/5147017#M15238</link>
      <description>Do you have any specific thread in mind, since from when I look the threads in the ILO forum mainly seems to concern AD integration of ILO, not AD integration of OA ?</description>
      <pubDate>Fri, 19 Dec 2008 06:59:33 GMT</pubDate>
      <guid>https://community.hpe.com/t5/bladesystem-general/help-configuring-ldap-integration-for-bladesystem-oa-login/m-p/5147017#M15238</guid>
      <dc:creator>Mikael Rönnbäck</dc:creator>
      <dc:date>2008-12-19T06:59:33Z</dc:date>
    </item>
    <item>
      <title>Re: Help configuring LDAP integration for BladeSystem OA login</title>
      <link>https://community.hpe.com/t5/bladesystem-general/help-configuring-ldap-integration-for-bladesystem-oa-login/m-p/5147018#M15239</link>
      <description>Did you upload the Certificates from Active directory on your OA-card? you need thoose to get access to your AD.&lt;BR /&gt;&lt;BR /&gt;And for the questions about wich ou to point out. You need to point to the OU where the users are as 2.31 and down doesn't support nested groups. Thats a new feature in 2.32&lt;BR /&gt;&lt;BR /&gt;ou=Users,dc=MyCompany,dc=com</description>
      <pubDate>Fri, 19 Dec 2008 07:29:46 GMT</pubDate>
      <guid>https://community.hpe.com/t5/bladesystem-general/help-configuring-ldap-integration-for-bladesystem-oa-login/m-p/5147018#M15239</guid>
      <dc:creator>Cederberg</dc:creator>
      <dc:date>2008-12-19T07:29:46Z</dc:date>
    </item>
    <item>
      <title>Re: Help configuring LDAP integration for BladeSystem OA login</title>
      <link>https://community.hpe.com/t5/bladesystem-general/help-configuring-ldap-integration-for-bladesystem-oa-login/m-p/5147019#M15240</link>
      <description>Yes, the test result status says certificates are successfully read, and all tests pass (including authentication), except actual authorization.&lt;BR /&gt;&lt;BR /&gt;I thought that would be related to membership in groups specified to allow access ?</description>
      <pubDate>Fri, 19 Dec 2008 09:23:48 GMT</pubDate>
      <guid>https://community.hpe.com/t5/bladesystem-general/help-configuring-ldap-integration-for-bladesystem-oa-login/m-p/5147019#M15240</guid>
      <dc:creator>Mikael Rönnbäck</dc:creator>
      <dc:date>2008-12-19T09:23:48Z</dc:date>
    </item>
    <item>
      <title>Re: Help configuring LDAP integration for BladeSystem OA login</title>
      <link>https://community.hpe.com/t5/bladesystem-general/help-configuring-ldap-integration-for-bladesystem-oa-login/m-p/5147020#M15241</link>
      <description>Btw, I have the 2.32 OA firmware in place.</description>
      <pubDate>Fri, 19 Dec 2008 09:24:21 GMT</pubDate>
      <guid>https://community.hpe.com/t5/bladesystem-general/help-configuring-ldap-integration-for-bladesystem-oa-login/m-p/5147020#M15241</guid>
      <dc:creator>Mikael Rönnbäck</dc:creator>
      <dc:date>2008-12-19T09:24:21Z</dc:date>
    </item>
    <item>
      <title>Re: Help configuring LDAP integration for BladeSystem OA login</title>
      <link>https://community.hpe.com/t5/bladesystem-general/help-configuring-ldap-integration-for-bladesystem-oa-login/m-p/5147021#M15242</link>
      <description>This is my first question, should the search context point to the path where the USER is or the path where the GROUP in which the user is a member is ?&lt;BR /&gt;&lt;BR /&gt;It should Point to the group in which user is member.&lt;BR /&gt;&lt;BR /&gt;Try the below search Context:&lt;BR /&gt;Search Context 1: OU=My OU,OU=Admin,OU=MainOU,DC=mydomain,DC=net&lt;BR /&gt;&lt;BR /&gt;If the Groups are directly under Users in Domain, Use CN otherwise use OU.&lt;BR /&gt;</description>
      <pubDate>Fri, 19 Dec 2008 15:23:15 GMT</pubDate>
      <guid>https://community.hpe.com/t5/bladesystem-general/help-configuring-ldap-integration-for-bladesystem-oa-login/m-p/5147021#M15242</guid>
      <dc:creator>Raghuarch</dc:creator>
      <dc:date>2008-12-19T15:23:15Z</dc:date>
    </item>
    <item>
      <title>Re: Help configuring LDAP integration for BladeSystem OA login</title>
      <link>https://community.hpe.com/t5/bladesystem-general/help-configuring-ldap-integration-for-bladesystem-oa-login/m-p/5147022#M15243</link>
      <description>Thank you, so, the Search contect should be in the form of OU= (not CN=) and point to the OU where the GROUPS are located. Check :)&lt;BR /&gt;&lt;BR /&gt;And I've added the actual groups in that OU that I want to grant access. &lt;BR /&gt;&lt;BR /&gt;But I still can't get things to work, I only get authentication success and authorization failure. So I must still be doing something wrong somewhere ?</description>
      <pubDate>Fri, 19 Dec 2008 15:26:29 GMT</pubDate>
      <guid>https://community.hpe.com/t5/bladesystem-general/help-configuring-ldap-integration-for-bladesystem-oa-login/m-p/5147022#M15243</guid>
      <dc:creator>Mikael Rönnbäck</dc:creator>
      <dc:date>2008-12-19T15:26:29Z</dc:date>
    </item>
    <item>
      <title>Re: Help configuring LDAP integration for BladeSystem OA login</title>
      <link>https://community.hpe.com/t5/bladesystem-general/help-configuring-ldap-integration-for-bladesystem-oa-login/m-p/5147023#M15244</link>
      <description>Try logging to OA with the directory User.&lt;BR /&gt;Don't use the test LDAP Test Page. Does it work?&lt;BR /&gt;</description>
      <pubDate>Fri, 19 Dec 2008 15:32:38 GMT</pubDate>
      <guid>https://community.hpe.com/t5/bladesystem-general/help-configuring-ldap-integration-for-bladesystem-oa-login/m-p/5147023#M15244</guid>
      <dc:creator>Raghuarch</dc:creator>
      <dc:date>2008-12-19T15:32:38Z</dc:date>
    </item>
    <item>
      <title>Re: Help configuring LDAP integration for BladeSystem OA login</title>
      <link>https://community.hpe.com/t5/bladesystem-general/help-configuring-ldap-integration-for-bladesystem-oa-login/m-p/5147024#M15245</link>
      <description>RÃ¶nnbÃ¤ck,&lt;BR /&gt;&lt;BR /&gt;Try the attachment, is it same as your directory structure? &lt;BR /&gt;try the search context if it matches.&lt;BR /&gt;</description>
      <pubDate>Fri, 19 Dec 2008 15:50:11 GMT</pubDate>
      <guid>https://community.hpe.com/t5/bladesystem-general/help-configuring-ldap-integration-for-bladesystem-oa-login/m-p/5147024#M15245</guid>
      <dc:creator>Raghuarch</dc:creator>
      <dc:date>2008-12-19T15:50:11Z</dc:date>
    </item>
    <item>
      <title>Re: Help configuring LDAP integration for BladeSystem OA login</title>
      <link>https://community.hpe.com/t5/bladesystem-general/help-configuring-ldap-integration-for-bladesystem-oa-login/m-p/5147025#M15246</link>
      <description>Thanks for the ideas but no, logging in with the user does not work, if it had I wouldn't have tried the tests in the first place ;)&lt;BR /&gt;&lt;BR /&gt;Yes, I would say my OU structure resembles example 1, and so does my search context string, but I still can't get login to work.</description>
      <pubDate>Mon, 05 Jan 2009 12:17:41 GMT</pubDate>
      <guid>https://community.hpe.com/t5/bladesystem-general/help-configuring-ldap-integration-for-bladesystem-oa-login/m-p/5147025#M15246</guid>
      <dc:creator>Mikael Rönnbäck</dc:creator>
      <dc:date>2009-01-05T12:17:41Z</dc:date>
    </item>
    <item>
      <title>Re: Help configuring LDAP integration for BladeSystem OA login</title>
      <link>https://community.hpe.com/t5/bladesystem-general/help-configuring-ldap-integration-for-bladesystem-oa-login/m-p/5147026#M15247</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;ive just been doing a similar setup and after if figured out i should be using OU instead of CN started to get places.&lt;BR /&gt;&lt;BR /&gt;One important thing ive found is that your group is in a different OU tree to the one where the user is located you must also specifcy the OU where the accounts exist (top level will do if the actual OU is nested below)&lt;BR /&gt;so i.e i have two context searches&lt;BR /&gt;&lt;BR /&gt;1. OU=Groups,DC=domain,DC=com&lt;BR /&gt;2. OU=SiteName,DC=domain,DC=com&lt;BR /&gt;&lt;BR /&gt;the user in question is in an ou 3 levels below site name and my group is in context search 1.&lt;BR /&gt;&lt;BR /&gt;Hope this helps&lt;BR /&gt;Damien.</description>
      <pubDate>Fri, 09 Jan 2009 20:05:37 GMT</pubDate>
      <guid>https://community.hpe.com/t5/bladesystem-general/help-configuring-ldap-integration-for-bladesystem-oa-login/m-p/5147026#M15247</guid>
      <dc:creator>Damien GIll</dc:creator>
      <dc:date>2009-01-09T20:05:37Z</dc:date>
    </item>
    <item>
      <title>Re: Help configuring LDAP integration for BladeSystem OA login</title>
      <link>https://community.hpe.com/t5/bladesystem-general/help-configuring-ldap-integration-for-bladesystem-oa-login/m-p/5147027#M15248</link>
      <description>Finally, thank you ever so much!&lt;BR /&gt;&lt;BR /&gt;Quite funny though that it takes two OU searches, at least to me it's kind of natural that you don't keep all users and groups in the same OU, at least not with 50K+ users :-)&lt;BR /&gt;&lt;BR /&gt;Still, with one search context to the where groups are and one to where the users are placed things started to just work right away.</description>
      <pubDate>Mon, 12 Jan 2009 07:36:25 GMT</pubDate>
      <guid>https://community.hpe.com/t5/bladesystem-general/help-configuring-ldap-integration-for-bladesystem-oa-login/m-p/5147027#M15248</guid>
      <dc:creator>Mikael Rönnbäck</dc:creator>
      <dc:date>2009-01-12T07:36:25Z</dc:date>
    </item>
    <item>
      <title>Re: Help configuring LDAP integration for BladeSystem OA login</title>
      <link>https://community.hpe.com/t5/bladesystem-general/help-configuring-ldap-integration-for-bladesystem-oa-login/m-p/5147028#M15249</link>
      <description>You must have a search context to both the OU where the groups are and one to where the users are located in case they are not located in the same OU.</description>
      <pubDate>Mon, 12 Jan 2009 07:37:25 GMT</pubDate>
      <guid>https://community.hpe.com/t5/bladesystem-general/help-configuring-ldap-integration-for-bladesystem-oa-login/m-p/5147028#M15249</guid>
      <dc:creator>Mikael Rönnbäck</dc:creator>
      <dc:date>2009-01-12T07:37:25Z</dc:date>
    </item>
  </channel>
</rss>

