HPE OneView
1753762 Members
4941 Online
108799 Solutions
New Discussion юеВ

AD Authentication

 
SOLVED
Go to solution
GYoung
Occasional Advisor

AD Authentication

I have sucessfully configured the appliance to connect to our AD but then cannot login to the appliance or add a domain group using AD credentials. I'm using the appliance in trial mode until my licenses come in. Is this as limitation of the trial license mode?

11 REPLIES 11
ChrisLynch
HPE Pro

Re: AD Authentication

Hello, and welcome to the HP OneView Community forums.

 

AD/LDAP authentication is not a licenseable feature to HP OneView, which means a trial license or purchased license would have no impact on the feature.

 

Remember, OneView only supports Cononical Name (CN) account names for Active Directory.  Did you use the same account you used to configure AD in the appliance when you tried to add a Directory Group?


I am an HPE employee

Accept or Kudo

GYoung
Occasional Advisor

Re: AD Authentication

I did use the same account. That's the puzzling part. The configuration to AD was sucessful but then I can't use that same AD account to login to the VM or connect to AD and add a CN group.

 

I have also started over and rebuilt the VM from a new import with the same result. I have opened a case with HP Support so maybe they can help figure this out.

 

Thanks for your reply. I will update this post with any helpful solution to this problem.

 

Cheers

ChrisLynch
HPE Pro

Re: AD Authentication

Is the user account you used in the Search Context(OU container) you provided?  Please note that the AD/LDAP implementation does not support Subtree search yet, and you must specify the OU where your user account and groups are located.  You can add up to 4 Search Contexts.  E.g.: OU=users,OU=corp,dc=domain,dc=com+OU=groups,OU=corp,dc=domain,dc=com+OU=Admins,OU=corp,dc=domain,dc=com+OU=ops,OU=corp,dc=domain,dc=com


I am an HPE employee

Accept or Kudo

GYoung
Occasional Advisor

Re: AD Authentication

Short answer to your question is, Yes. What I haven't done is create a computer account for the VM and put in that configuration. Do I need that part? I thought that was optional.

 

Cheers

GYoung
Occasional Advisor
Solution

Re: AD Authentication

Ok. I figured it out.

Looks like the User Accounts & Groups need to be in the same OU.

My users are in cn=users and my groups are in cn=groups. 

 

The model OU=users,OU=corp,dc=domain,dc=com+OU=groups,OU=corp,dc=domain,dc=com did not work.

 

When i built a group (OneViewAdmins) in the same OU with the users (gary) it started working..

 

Ataboy to   for pointing in this direction.

 

ChrisLynch
HPE Pro

Re: AD Authentication

What version of the OneView appliance are you using?  We introduced the multiple search contexts in the 1.05 release, and I have plenty of customers using multiple search contexts without issue.  CN=Users is the default container object for User Accounts in Active Directory, but there is no CN=Groups default conatiner.  If you created an OU in the root of your domain, and are using the default Users container (remember, this is not an OU), then your search context should be:

 

CN=users,DC=domain,DC=com+OU=groups,DC=domain,DC=com


I am an HPE employee

Accept or Kudo

GYoung
Occasional Advisor

Re: AD Authentication

I'm building a new install of v1.10

 

I used an hasty (inaccurate) example in my thread because I didn't want to publish my AD onto this forum. You are correct the group I was looking to use was in the default container object for User Accounts in Active Directory, which as you pointed out is NOT an OU. The User account was off in a different OU container. I was concatenating the two together with the "+" and it didn't work. It started working when I created a group in the same OU where the user account was located and set that context into the configuration.  I've worked with AD since 2000 and forgot that NOT an OU technicality lol

 

Thanks again

 

Cheers

ChrisLynch
HPE Pro

Re: AD Authentication

Hmmm...  That certainly should not be the case.  I would suggest you open a support case with (800) HPINVENT.


I am an HPE employee

Accept or Kudo

ChrisLynch
HPE Pro

Re: AD Authentication

I need a bit of more data from you.  What version of the appliance did you deploy?  You can get it from Top Level Menu -> Settings and the Appliance panel.  We do have a patch coming that addresses some LDAP issues with 1.10.05.


I am an HPE employee

Accept or Kudo