- Community Home
- >
- Servers and Operating Systems
- >
- HPE ProLiant
- >
- Server Management - Remote Server Management
- >
- iLO2 no longer authenticates AD users through user...
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Discussions
Discussions
Discussions
Forums
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО04-08-2010 08:17 PM
тАО04-08-2010 08:17 PM
Now we can no longer authenticate against AD and can only authenticate with either a local iLO user or the AD Name of a user.
We used to be able to log in with;
DOMAIN\username
Username@domain.com
Username
And now it results in failure for each of these valid logins, and the only way we can authenticate is with;
Surname\, Firstname - Job role
which is the AD Name (not even the display name).
So, I know that LDAP authentication is working (because I can log in with the above name), but I cannot authenticate with any "usable" username.
We have an AD structure that organises accounts under location and type, so I have entered the following search contexts;
ou=Users,OU=Site1,OU=City1,OU=State1,OU=Country,DC=Domain,DC=com
ou=Users,OU=Site2,OU=City2,OU=State2,OU=Country,DC=Domain,DC=com
@domain.com
DOMAIN
CN=AdminGroup,OU=Groups,OU=Site1,OU=City1,OU=State1,OU=Country,DC=Domain,DC=com
And my account exists in four of these search contexts. I can authenticate OK, but not with a normal format to the same account - I get "User Object Cannot be Found" when I test the settings. I have checked capitalisation and spacing, and tried every combination I can think of, but the only one that works is the Name in AD (which is not the same as the Outlook/Exchange "Display Name").
I have tried this with IE6,7 and 8
AD is Windows 2003
This worked before...
Can anyone help?
Solved! Go to Solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО04-12-2010 10:32 PM
тАО04-12-2010 10:32 PM
SolutionFor schemaless Directory configuration, please ensure that the following settings are modified as required so that user can logon with Email format and Netbios formats successfully:
1. DIR_SERVER_ADDRESS value need to be set todirectory server DNS Name or FQDN(Full qualified Domain Name)
2. Please check and update the following iLO Network Settings.
2a. The domain name of iLO should match the domain of the directory server.
2b. One of the primary, secondary or teritiary DNS server must have the same IP address as the Directory server.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО04-12-2010 11:30 PM
тАО04-12-2010 11:30 PM
Re: iLO2 no longer authenticates AD users through username
Our AD domain is "COMPANYNAME"
The DNS namespace is "companyname.com.au"
The LDAP server specified in "Directory Server Address" is DCSERVER3.companyname.com.au - this matches the capitalisation of the DC/GC server's SSL certificate. We have also tried dcserver2.companyname.com.au and this matches the capitalisation of that DC/GC.
The DNS suffix for the iLO in network is set to match our DNS namespace.
The DNS server specified in the iLO configuration is the IP for DCSERVER3, and the secondary DNS server is the IP for dcserver2.
Thanks, anything else we can try?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО05-02-2010 10:05 PM
тАО05-02-2010 10:05 PM
Re: iLO2 no longer authenticates AD users through username
I used to be able to log in as;
DOMAIN\username
Username@domain.com
username
but now I can only log in as
Surname\, Firstname - Job role
with iLO 1.82, I get more LDAP search contexts, but this has not helped. I have however managed to trust SSO with HP SIM and so now I can access iLO through a link in HP Systems Insight Manager for each server - and it states in the top right hand corner that my username is DOMAIN\Username and authenticated with LDAP - but why can I not log in through the web interface directly?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО05-12-2010 10:56 AM
тАО05-12-2010 10:56 AM
Re: iLO2 no longer authenticates AD users through username
http://forums11.itrc.hp.com/service/forums/questionanswer.do?threadId=1005787
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО05-16-2010 09:11 PM
тАО05-16-2010 09:11 PM
Re: iLO2 no longer authenticates AD users through username
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО05-17-2010 11:30 PM
тАО05-17-2010 11:30 PM
Re: iLO2 no longer authenticates AD users through username
I made the change in Local Intranet zone, but all my iLOs are on a different subnet to me.
So, I changed my Internet Zone configuration to prompt to initialise and run ActiveX controls, and it all started working again!
Thanks for your help.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО05-17-2010 11:48 PM
тАО05-17-2010 11:48 PM
Re: iLO2 no longer authenticates AD users through username
Parameter тАЬInitialize and script ActiveX controls not marked as safe for scriptingтАЭ
Change from тАЬDisableтАЭ
Change to тАЬPromptтАЭ