<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AD issues in HPE OneView</title>
    <link>https://community.hpe.com/t5/hpe-oneview/ad-issues/m-p/7079618#M5005</link>
    <description>&lt;P&gt;Keep in mind that 636/TCP is the LDAP port for local Active Directory requests.&amp;nbsp; 3269/TCP is to initiate an LDAP query to the Active Directory Global Catelog service.&amp;nbsp; The GC role for a DC indexes all resources within the forest, regardless the number of domains, or tree structure.&amp;nbsp; As for the length of time, I'mnot sure what is causing that.&amp;nbsp; It could be the number of objects you have within your enterprise forest, or the type of LDAP query OneView is making to the GC service.&amp;nbsp; Do you experience the same delay when authenticating to the appliance?&lt;/P&gt;</description>
    <pubDate>Tue, 18 Feb 2020 19:53:22 GMT</pubDate>
    <dc:creator>ChrisLynch</dc:creator>
    <dc:date>2020-02-18T19:53:22Z</dc:date>
    <item>
      <title>AD issues</title>
      <link>https://community.hpe.com/t5/hpe-oneview/ad-issues/m-p/7057638#M4434</link>
      <description>&lt;P&gt;I can't seem to figure where and why it's causing the bottle neck. It also doesn't help the situation I don't have domain admin credentails, so I can't troubleshoot the AD issues.&lt;/P&gt;&lt;P&gt;Domain: Company.com (Parent)&lt;/P&gt;&lt;P&gt;Domain forest USA.Company.com (Child)&lt;/P&gt;&lt;P&gt;Domain forest CANADA.Company.com (Child)&lt;/P&gt;&lt;P&gt;I created a US secuirty group. All the USA users can login in just fine. However all the people who are a CANADA user and part of the US secuirty group has a hard time logging into HPe OneView.&lt;/P&gt;&lt;P&gt;The couple of ways I tried to get it to work.&lt;/P&gt;&lt;P&gt;Created a Company.com "&lt;SPAN&gt;Directories&lt;/SPAN&gt;" then linked that directories in user and groups to a USA secuirty group, then had the user login as CA/username, sometimes able to login but mostly failure due to time out failure.&lt;/P&gt;&lt;P&gt;Created an USA.Company.com in "&lt;SPAN&gt;Directories&lt;/SPAN&gt;" then linked that directories in the user and groups to a USA secuirty group, then had the user login as CA/username, failed.&lt;/P&gt;&lt;P&gt;Created an CANADA.Company.com in "Directories" however could not link it to the "USA secuirty group"&lt;/P&gt;&lt;P&gt;Any suggestions?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Aug 2019 17:27:45 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-oneview/ad-issues/m-p/7057638#M4434</guid>
      <dc:creator>JayFromIT</dc:creator>
      <dc:date>2019-08-05T17:27:45Z</dc:date>
    </item>
    <item>
      <title>Re: AD issues</title>
      <link>https://community.hpe.com/t5/hpe-oneview/ad-issues/m-p/7057658#M4436</link>
      <description>&lt;P&gt;I would recommend creating a unique directory for each AD domain you have.&amp;nbsp; I would name them the exact same as the NT Domain Name.&amp;nbsp; So, if your USA.domain.com's NT Domain Name is &lt;FONT face="courier new,courier"&gt;USA&lt;/FONT&gt;, then create a &lt;FONT face="courier new,courier"&gt;USA&lt;/FONT&gt; auth directory in OneView.&amp;nbsp; Then, your users can type in &lt;FONT face="courier new,courier"&gt;USA\MyUsername&lt;/FONT&gt; without needing to change the auth directory on the OneView login console to authenticate to the correct directory.&lt;/P&gt;</description>
      <pubDate>Mon, 05 Aug 2019 21:08:32 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-oneview/ad-issues/m-p/7057658#M4436</guid>
      <dc:creator>ChrisLynch</dc:creator>
      <dc:date>2019-08-05T21:08:32Z</dc:date>
    </item>
    <item>
      <title>Re: AD issues</title>
      <link>https://community.hpe.com/t5/hpe-oneview/ad-issues/m-p/7058348#M4468</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.hpe.com/t5/user/viewprofilepage/user-id/1951548"&gt;@JayFromIT&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Were you able to get this issue resolved using the suggestions from Chris Lynch?&lt;BR /&gt;Let us know.&lt;/P&gt;&lt;P&gt;Regards,&lt;BR /&gt;Bhaskar&lt;/P&gt;</description>
      <pubDate>Mon, 12 Aug 2019 05:15:17 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-oneview/ad-issues/m-p/7058348#M4468</guid>
      <dc:creator>BhaskarV</dc:creator>
      <dc:date>2019-08-12T05:15:17Z</dc:date>
    </item>
    <item>
      <title>Re: AD issues</title>
      <link>https://community.hpe.com/t5/hpe-oneview/ad-issues/m-p/7079431#M4995</link>
      <description>&lt;P&gt;Hi Chris,&lt;/P&gt;&lt;P&gt;This task was put into the back burner as the oneview was more of a POC at the time.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyways my Current Setup&lt;/P&gt;&lt;P&gt;-US.COMPANY.COM&lt;/P&gt;&lt;P&gt;--- US_User_1&lt;/P&gt;&lt;P&gt;--- US_Security_Group&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;CANADA.COMPANY.COM&lt;/P&gt;&lt;P&gt;--- CANADA_User_1 (is a member of US_Secuirty_Group)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In HPEONEVIEW&lt;/P&gt;&lt;P&gt;US.COMPANY.COM is in “Settings/Security/Directories”&lt;/P&gt;&lt;P&gt;-US_Security_Group added to US.COMPANY.COM directory in users and groups&lt;/P&gt;&lt;P&gt;--US_User_1 can login&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;CANADA.COMPANY.COM is in “Settings/Security/Directories”&lt;/P&gt;&lt;P&gt;--CANADA_User_1 just &lt;STRONG&gt;stalls for a long time&lt;/STRONG&gt; then a login failure&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tried adding “US_Secuirty_Group” to the CANADA directory but it could not find US_Secuirty_Group.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I get something like “An invalid search input CN=groupname, OU= OU PATH, DC=&lt;STRONG&gt;&lt;U&gt;us&lt;/U&gt;&lt;/STRONG&gt;,DC=company,DC=com was not provided with the request to search on directory &lt;STRONG&gt;&lt;U&gt;CANADA&lt;/U&gt;&lt;/STRONG&gt;.COMPANY.COM&lt;/P&gt;&lt;P&gt;I assume HPe recommendation/wants&lt;/P&gt;&lt;P&gt;-US.COMPANY.COM&lt;/P&gt;&lt;P&gt;-- US_Security_Group&lt;/P&gt;&lt;P&gt;--- US_User_1&lt;/P&gt;&lt;P&gt;CANADA.COMPANY.COM&lt;/P&gt;&lt;P&gt;-- CANADA_Security_Group&lt;/P&gt;&lt;P&gt;--- CANADA_User_1&lt;/P&gt;&lt;P&gt;Due to company requirements, is there a way not to use this setup but try to get it to work in the first example? Because that example does work within iLO. Users in the Canada domain can login to ilo even though the security group is in the US domain.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;EDIT: also some other few things I have noticed. I can not add CANADA.COMPANY.COM with my US account in &lt;SPAN&gt;“Settings/Security/Directories”.&lt;/SPAN&gt; I had to have someone with a CANADA NT account add the CANADA Directory. It says "Invalid Credentials or Base DN" I did try login "us\username"&lt;/P&gt;</description>
      <pubDate>Mon, 17 Feb 2020 21:06:27 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-oneview/ad-issues/m-p/7079431#M4995</guid>
      <dc:creator>JayFromIT</dc:creator>
      <dc:date>2020-02-17T21:06:27Z</dc:date>
    </item>
    <item>
      <title>Re: AD issues</title>
      <link>https://community.hpe.com/t5/hpe-oneview/ad-issues/m-p/7079476#M4997</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;What you have is a cross-domain authentication requirement, and OneView supports it. All you need is configure the baseDN as the top/parent&amp;nbsp;domain and port as the global catalog port.&lt;/P&gt;&lt;P&gt;Can you try the below configuration?&lt;/P&gt;&lt;P&gt;BaseDN: dc=company,dc=com&lt;/P&gt;&lt;P&gt;Port: 3269 (default global catalog port)&lt;/P&gt;&lt;P&gt;and group: us_security_group&lt;/P&gt;&lt;P&gt;With this both the US and Canada users should be able to login. Can you try and let us know how it goes?&lt;/P&gt;&lt;P&gt;The documentation on this is available in the OneView 5.0 user guide as a separate section 'cross-domain authentication'.&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Poongkodi&lt;/P&gt;</description>
      <pubDate>Tue, 18 Feb 2020 06:55:33 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-oneview/ad-issues/m-p/7079476#M4997</guid>
      <dc:creator>Poongkodi</dc:creator>
      <dc:date>2020-02-18T06:55:33Z</dc:date>
    </item>
    <item>
      <title>Re: AD issues</title>
      <link>https://community.hpe.com/t5/hpe-oneview/ad-issues/m-p/7079615#M5004</link>
      <description>&lt;P&gt;Hi Poongkodi,&lt;/P&gt;&lt;P&gt;I swore I tried that before but for some reason, when I follow your instructions it's working, maybe it's the port? I always used 636 however to follow your instructions, I used 3269. The only issue I have is once the Directory has been added in security, in users and groups it takes about 1-2 minutes to find the group, even though I put the full DN path. Is that normal?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Feb 2020 19:43:03 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-oneview/ad-issues/m-p/7079615#M5004</guid>
      <dc:creator>JayFromIT</dc:creator>
      <dc:date>2020-02-18T19:43:03Z</dc:date>
    </item>
    <item>
      <title>Re: AD issues</title>
      <link>https://community.hpe.com/t5/hpe-oneview/ad-issues/m-p/7079618#M5005</link>
      <description>&lt;P&gt;Keep in mind that 636/TCP is the LDAP port for local Active Directory requests.&amp;nbsp; 3269/TCP is to initiate an LDAP query to the Active Directory Global Catelog service.&amp;nbsp; The GC role for a DC indexes all resources within the forest, regardless the number of domains, or tree structure.&amp;nbsp; As for the length of time, I'mnot sure what is causing that.&amp;nbsp; It could be the number of objects you have within your enterprise forest, or the type of LDAP query OneView is making to the GC service.&amp;nbsp; Do you experience the same delay when authenticating to the appliance?&lt;/P&gt;</description>
      <pubDate>Tue, 18 Feb 2020 19:53:22 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-oneview/ad-issues/m-p/7079618#M5005</guid>
      <dc:creator>ChrisLynch</dc:creator>
      <dc:date>2020-02-18T19:53:22Z</dc:date>
    </item>
    <item>
      <title>Re: AD issues</title>
      <link>https://community.hpe.com/t5/hpe-oneview/ad-issues/m-p/7079620#M5006</link>
      <description>&lt;P&gt;Right now when I try to login with the new parent directory it was in the "acceptable/usable" (5-10 second) range. I am in the process to ask people outside my domain to login.&lt;/P&gt;&lt;P&gt;@ Chris Lync&lt;/P&gt;&lt;P&gt;In Users and Groups\Add Group\Group box&lt;/P&gt;&lt;P&gt;When I enter the full DN path and press "select group" on the back end is it searching for that exact path or just trying to login to pull the GC? because after waiting a long time, when it's "done" it starts me off in a pop-up window with DC=Company, DC=com not the full path I entered earlier.&lt;/P&gt;&lt;P&gt;EDIT: I have confirmation users outside of the domain, who has never logged in before it took about 5 seconds for them to log in. I think the port did help. However, I still have an issue where I try to add a DN it takes a long time for it to load. I guess not a big issue as, because I only have to do it one time, which I can wait for.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Feb 2020 22:00:19 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-oneview/ad-issues/m-p/7079620#M5006</guid>
      <dc:creator>JayFromIT</dc:creator>
      <dc:date>2020-02-18T22:00:19Z</dc:date>
    </item>
    <item>
      <title>Re: AD issues</title>
      <link>https://community.hpe.com/t5/hpe-oneview/ad-issues/m-p/7079654#M5007</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.hpe.com/t5/user/viewprofilepage/user-id/1951548"&gt;@JayFromIT&lt;/a&gt;&lt;/P&gt;&lt;P&gt;During group add if you are entering the group DN (or the group name) then "Add" action can be clicked directly. The "Select group" action is needed only when you want to navigate the directory and select the group. Entering the group DN and clicking "Add" directly should save you time. Could you pl try and confirm?&lt;/P&gt;</description>
      <pubDate>Wed, 19 Feb 2020 05:55:03 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-oneview/ad-issues/m-p/7079654#M5007</guid>
      <dc:creator>Poongkodi</dc:creator>
      <dc:date>2020-02-19T05:55:03Z</dc:date>
    </item>
  </channel>
</rss>

