Unsolved
This post is more than 5 years old
5 Posts
0
1647
December 4th, 2018 11:00
OpenManage Enterprise Directory Service Certificate
Recently upgraded from OM Enterprise tech release to version 3. Unable to log in with AD creds now.
Old config: AD, domain name, DNS pointing to a specific DC, Port 3268, no AD cert
New config: AD, domain name, Manual (because DNS would not connect) pointing to IP, domain points to dc=domain,dc=suffix, port 3269, domain root certificate.
New config presents error when testing: CSEC1527 - Unable to add/modify or perform Test connection for the account provider because an invalid certificate is uploaded.
Have tried a myriad of different things to get this to work. I took a snap of the appliance and if I revert back, all works fine. I can only log in with the local account after the upgrade. My root CA server is an offline CA. Is that an issue for OME? I tried the subordinate CA as well, but that did not work either. I've tried DER encoded, Base64 encoded, and the entire chain. I am able to upload the root cert, but not test or authenticate against it in OME.


esouthwick
5 Posts
0
December 6th, 2018 05:00
As it turns out, there were some security features enabled during the upgrade that were preventing us from logging in with our AD credentials:
Application Settings/Security/Settings
Login IP Range - Uncheck 'Enable IP Range' or set to proper range
Login Lockout Policy - Uncheck 'By IP Range' or set to proper range