Unsolved

This post is more than 5 years old

1647

December 4th, 2018 11:00

OpenManage Enterprise Directory Service Certificate

Recently upgraded from OM Enterprise tech release to version 3.  Unable to log in with AD creds now.

Old config:  AD, domain name, DNS pointing to a specific DC, Port 3268, no AD cert

New config: AD, domain name, Manual (because DNS would not connect) pointing to IP, domain points to dc=domain,dc=suffix, port 3269, domain root certificate.

New config presents error when testing: CSEC1527 - Unable to add/modify or perform Test connection for the account provider because an invalid certificate is uploaded.

Have tried a myriad of different things to get this to work.  I took a snap of the appliance and if I revert back, all works fine.  I can only log in with the local account after the upgrade.  My root CA server is an offline CA.  Is that an issue for OME?  I tried the subordinate CA as well, but that did not work either.  I've tried DER encoded, Base64 encoded, and the entire chain.  I am able to upload the root cert, but not test or authenticate against it in OME.

December 6th, 2018 05:00

As it turns out, there were some security features enabled during the upgrade that were preventing us from logging in with our AD credentials:

Application Settings/Security/Settings
Login IP Range - Uncheck 'Enable IP Range' or set to proper range
Login Lockout Policy - Uncheck 'By IP Range' or set to proper range

No Events found!

Top