Server Management - Systems Insight Manager
1833588 Members
4199 Online
110061 Solutions
New Discussion

Re: Single sign-on doesn't work anymore from cms

 
Kevin Kelling
Super Advisor

Re: Single sign-on doesn't work anymore from cms

Here is one more quirky symptom.

I created several lists for hardware type.

For example one list for all servers with an ILO board, one for all servers with a Smart 6i, etc.

These lists were working yesterday.

Today if I go to them EVERY SINGELE DEVICE known by SIM shows up in the list.

The SQL queries would not have changes so perhaps there are some issues in the datbase?
Daniel Smith_7
Frequent Advisor

Re: Single sign-on doesn't work anymore from cms

Yup I have the problem as well. I had an upgraded 4.2 to 5.0 which was working fine, but rebuilt a fresh copy of 5.0 onto a new server and now have this issue. Does anyone have a fix/workaround for it yet?
Paul Nolette
Occasional Advisor

Re: Single sign-on doesn't work anymore from cms

Has anyone found a resolution to this issue?
Thank you,
Steven J. Marty_2
Frequent Advisor

Re: Single sign-on doesn't work anymore from cms

I was going to ask the same question. Nothing here. Still working with AET and Engineering.

-Steve
Kevin Kelling
Super Advisor

Re: Single sign-on doesn't work anymore from cms

Still working with engineering also. Since they are based in Houston, I think Rita may have pushed things back a bit.
Steven J. Marty_2
Frequent Advisor

Re: Single sign-on doesn't work anymore from cms

Kevin,

You may want to touch base with David. I have been actively working with Engineering today and I think they want debug data from multiple customers. Thanks.

-Steve
Steven J. Marty_2
Frequent Advisor

Re: Single sign-on doesn't work anymore from cms

I just tested a fix I got from Engineering and all appears to be working so far. Details to follow...

-Steve
Daniel Smith_7
Frequent Advisor

Re: Single sign-on doesn't work anymore from cms

Has this fix been released yet?
Steven J. Marty_2
Frequent Advisor

Re: Single sign-on doesn't work anymore from cms

Not publically. The AET engineer said it would be released in v5.0.2.

You could call and reference my case (Case #3212110114) and state that you need that same fix.

-Steve
Daniel Smith_7
Frequent Advisor

Re: Single sign-on doesn't work anymore from cms

Thanks Steve, will do.
Steven Laux
Frequent Advisor

Re: Single sign-on doesn't work anymore from cms

Any idea when 5.02 will be publicly available?
Steven J. Marty_2
Frequent Advisor

Re: Single sign-on doesn't work anymore from cms

He said no ETA.
pedro-chicago
Advisor

Re: Single sign-on doesn't work anymore from cms

I had a similar problem where everything would run fine for a week or so and then single sign-on wouldn't work. The other thing I noticed was that the trust to the VCRM, which was running on the same server, had failed.

While investigating and troubleshooting, I found the following error in C:\hp\hpsmh\logs\smh.log:

This certificate has a Common Name (CN) that doesn't match the server's name

This error would occur when restarting the HP SIM server's SMH service while all of the SIM related services (SIM, PMP, VCRM, etc.) were stopped, so I was pretty sure it wasn't completely an HP SIM problem.

I tried creating new certificates via HP SIM using just the HP SIM server's host name and its FQDN. Neither fixed the problem. Since the trust to the VCRM (running on the same server) had failed, I tried uninstall/reinstall. Single sign-on worked once after the uninstall, but eventually failed again, even before the reinstall.

Finally, I ran Sysinternals RegMon and FileMon while restarting the SMH service, and found several registry reads to the following registry values:

HKLM\SYSTEM\CurrentControlSet\Control\ComputerName\ComputerName\Computername
HKLM\SYSTEM\CurrentControlSet\Control\ComputerName\ActiveComputerName\Computername
HKLM\SYSTEM\CurrentControlSet001\Control\ComputerName\ComputerName\Computername
HKLM\SYSTEM\CurrentControlSet001\Control\ComputerName\ActiveComputerName\Computername

The timing of these reads was just before the entry above to smh.log.

It turned out that all of the registry vales were the SIM server's host name, but were ALL CAPS! Given the HP SIM certificate has the server's FQDN in all lowercase, and the error I found in smh.log, I thought this might be a problem (not 100% sure if SSL is case sensitive or not - any comments?). Once I changed these registry values to all lowercase, I stopped getting the errors in smh.log. I reset the HP SIM certificate one last time and uninstalled/reinstalled VCRM for good measure.

Everything (single sign-on and trust to VCRM) has been working for a few days now. Since it initially worked for a few days before the problem began, I don't know if this is a long-term fix or not. Also, since the registry values were always ALL CAPS, why did the problem only occur after about a week?

I tried correlating the timing of the problem to some event on the server, either OS or HP SIM related. I cannot remember the exact sequence of events, but I think it may have happened just after the first reboot after the initial install of HP SIM (not including the required reboots during the install process), which was about one week after the install of HP SIM.

Again, don't know if this is a long-term solution or if it would help any one else. It would be interesting to hear what HP has to say and find out what their fix fixes.

Pete
Kevin Kelling
Super Advisor

Re: Single sign-on doesn't work anymore from cms

Late last week HP engineering gave me a new JAR file to put in the patches directory. Once I did this, the trusts (and all functions dependent on them) started working again.
jim goodman
Trusted Contributor

Re: Single sign-on doesn't work anymore from cms

My customer just had the patch applied to theirs and it appears to have rectified the problem. Will have to give some burn in time for a definitive.

Aces to AET and Dev for finding a solution. I really like this new version and can't wait to see things get ironed out with the update.

- Jim
Steven Laux
Frequent Advisor

Re: Single sign-on doesn't work anymore from cms

Any updates on the forthcoming 5.02 patch? I am patiently waiting, as are a lot of folks, I suppose.
AaronK
Frequent Advisor

Re: Single sign-on doesn't work anymore from cms

We have had the exact same issues. First with upgrade from 4.2. Then we did a fresh build, worked for about a month, then we lost all trust information again. We just reinstalled fresh and it is working for now.
Steven J. Marty_2
Frequent Advisor

Re: Single sign-on doesn't work anymore from cms

See above...

Until the release of v5.0.2, you should call and reference my case (Case #3212110114) and state that you need that same fix.

I believe they officially called it mxtrust.jar.

-Steve
Scott White_5
Advisor

Re: Single sign-on doesn't work anymore from cms

I ran into this issue this morning on a SIM 5.0 installation that has been running in our production environment for 1 month.

When I logged in this morning, single sign on was no longer working. Also, several custom collections had lost their rules and were now showing all systems.

I called HP and referenced the case above. I was originally given the trustmx.jar patch which did not resolve my problem. On the return call my support person contacted the engineer on the original case who stated that the trustmx.jar apparently did not work in all cases. They provided a newer patch HOTFIX50_001.jar which solved all my problems.

My case # was 3212762815.

Thanks to those of you who escalated this early on and thanks to HP for letting us get the patch prior to the 5.02 release.

Scott
Rich Purvis
Honored Contributor

Re: Single sign-on doesn't work anymore from cms

If you are monitoring this thread you may find this post from David interesting:

http://forums1.itrc.hp.com/service/forums/questionanswer.do?threadId=970801

FYI,

-Rich
Why does my tivo keep recording Nickelodeon?