Unsolved

1 Rookie

 • 

2 Posts

56

August 21st, 2025 09:19

LDAP lookups on OneFS 9

I have a Dell Isilon which I am trying to get SMB shares working on. I have AD and RedHat IdM LDAP. AD is not set to return UID or GID, instead we use IdM for that.

If I add AD as the authentication provider on the zone, and use the ISI AUTH USERS VIEW command, it returns data, albeit the UID and GID are wrong (by design)

If I remove AD and use LDAP for authentication on the zone, ISI AUTH USERS VIEW returns "User not found".

If I then run LDAPSEARCH from the CLI with the same BIND and account and password setup in the Isilon, it returns good data with the correct UID and GID from the Red Hat IdM. That makes me believe the LDAP settings are correct!

If I then add AD so both AD and LDAP are authentication providers on the Zone, ISI AUTH returns information but again its the wrong GID and UID, so I'm confident the IdM LDAP provider isnt working.

If I remove AD and leave LDAP, and run ISI_AUTH_EXPERT, it says the LDAP connection as working, but it also shows AD is working also. Even though I removed it from the Zone. If I then repeate ISI_AUTH_EXPERT several times, the AD provider is shown in the results above the LDAP provider, and sometimes below. This is despite only having LDAP as the provider for the System zone.

How do I diagnose what is going on? Are there any logs that I can look at to see what the Isilon is doing when I try to run ISI AUTH USERS VIEW

Moderator

 • 

9.4K Posts

August 21st, 2025 17:47

Hi,

 

Thanks for your question.

What OneFS are you running? https://www.dell.com/support/manuals/en-us/isilon-onefs/ifs_pub_9.4.0.0_cli_command_reference/isi-audit-commands?guid=guid-2d067aa5-50fc-4226-8e15-1477f424358e&lang=en-us Maybe there is something in there to track it down. Can check the logs here too. https://infohub.delltechnologies.com/en-us/p/onefs-restricted-shell-log-viewing-and-recovery/

Let us know if you have any additional questions.

1 Rookie

 • 

2 Posts

August 22nd, 2025 07:29

Hi Josh, the box is running the latest version of OneFs (9.x) as it was patched in the last couple of months.

I turned on auditing on the box on Wednesday, so I can start to see what events are being generated.

Those links look useful, I'll have a look when I'm back in front of the device in a couple of weeks time. It should have amassed a fair amount of events by then.

(edited)

No Events found!

Top