HPE OneView
cancel
Showing results for 
Search instead for 
Did you mean: 

AD Authentication

SOLVED
Go to solution
GYoung
Occasional Advisor

AD Authentication

I have sucessfully configured the appliance to connect to our AD but then cannot login to the appliance or add a domain group using AD credentials. I'm using the appliance in trial mode until my licenses come in. Is this as limitation of the trial license mode?

11 REPLIES
ChrisLynchHPE
Neighborhood Moderator

Re: AD Authentication

Hello, and welcome to the HP OneView Community forums.

 

AD/LDAP authentication is not a licenseable feature to HP OneView, which means a trial license or purchased license would have no impact on the feature.

 

Remember, OneView only supports Cononical Name (CN) account names for Active Directory.  Did you use the same account you used to configure AD in the appliance when you tried to add a Directory Group?

GYoung
Occasional Advisor

Re: AD Authentication

I did use the same account. That's the puzzling part. The configuration to AD was sucessful but then I can't use that same AD account to login to the VM or connect to AD and add a CN group.

 

I have also started over and rebuilt the VM from a new import with the same result. I have opened a case with HP Support so maybe they can help figure this out.

 

Thanks for your reply. I will update this post with any helpful solution to this problem.

 

Cheers

ChrisLynchHPE
Neighborhood Moderator

Re: AD Authentication

Is the user account you used in the Search Context(OU container) you provided?  Please note that the AD/LDAP implementation does not support Subtree search yet, and you must specify the OU where your user account and groups are located.  You can add up to 4 Search Contexts.  E.g.: OU=users,OU=corp,dc=domain,dc=com+OU=groups,OU=corp,dc=domain,dc=com+OU=Admins,OU=corp,dc=domain,dc=com+OU=ops,OU=corp,dc=domain,dc=com

GYoung
Occasional Advisor

Re: AD Authentication

Short answer to your question is, Yes. What I haven't done is create a computer account for the VM and put in that configuration. Do I need that part? I thought that was optional.

 

Cheers

GYoung
Occasional Advisor
Solution

Re: AD Authentication

Ok. I figured it out.

Looks like the User Accounts & Groups need to be in the same OU.

My users are in cn=users and my groups are in cn=groups. 

 

The model OU=users,OU=corp,dc=domain,dc=com+OU=groups,OU=corp,dc=domain,dc=com did not work.

 

When i built a group (OneViewAdmins) in the same OU with the users (gary) it started working..

 

Ataboy to   for pointing in this direction.

 

ChrisLynchHPE
Neighborhood Moderator

Re: AD Authentication

What version of the OneView appliance are you using?  We introduced the multiple search contexts in the 1.05 release, and I have plenty of customers using multiple search contexts without issue.  CN=Users is the default container object for User Accounts in Active Directory, but there is no CN=Groups default conatiner.  If you created an OU in the root of your domain, and are using the default Users container (remember, this is not an OU), then your search context should be:

 

CN=users,DC=domain,DC=com+OU=groups,DC=domain,DC=com

GYoung
Occasional Advisor

Re: AD Authentication

I'm building a new install of v1.10

 

I used an hasty (inaccurate) example in my thread because I didn't want to publish my AD onto this forum. You are correct the group I was looking to use was in the default container object for User Accounts in Active Directory, which as you pointed out is NOT an OU. The User account was off in a different OU container. I was concatenating the two together with the "+" and it didn't work. It started working when I created a group in the same OU where the user account was located and set that context into the configuration.  I've worked with AD since 2000 and forgot that NOT an OU technicality lol

 

Thanks again

 

Cheers

ChrisLynchHPE
Neighborhood Moderator

Re: AD Authentication

Hmmm...  That certainly should not be the case.  I would suggest you open a support case with (800) HPINVENT.

ChrisLynchHPE
Neighborhood Moderator

Re: AD Authentication

I need a bit of more data from you.  What version of the appliance did you deploy?  You can get it from Top Level Menu -> Settings and the Appliance panel.  We do have a patch coming that addresses some LDAP issues with 1.10.05.

GYoung
Occasional Advisor

Re: AD Authentication

I'm at 1.10.03-103740, Jun 26, 2014. But I had re-installed the App so I have had the problem with both 1.10.03 and 1.10.05. I have worked around the problem by having the groups in with the user accounts so I've moved on.

 

I just installed the 1.10.05 update, thanks for the minder... :-P

 

Cheers

ChrisLynchHPE
Neighborhood Moderator

Re: AD Authentication

Please know that there are additional LDAP/AD issues with 1.10.05 that we are addressing in a future patch.  I do not have an ETA on its release right now, but do know that it is in testing and qualification.  Once it is available, an announcement will be made.