UNSOLVED

P_Rakimanputra

updated

8 years ago

P

P_Rakimanputra

1 Rookie

2 Posts

0

4156

September 25th, 2018 07:00

Admin user locked up after playing with LDAP Unity OE 4.4

Hi People in community,

I'm facing an issue here.When I try to login using local admin., it says " The logged in user is not authorized to access unisphere."

I googled about that issue, and probably it because of LDAP (after I played around with it). But now, how to fix this issue? I can't login to admin user and unluckily, I only can login to "storage administrator" privillage. even my "Adimistrator" group in AD isn't work either. Anyway, I'm using Unity 300 and OE version 4.4


More story:

I tested connection from Unity 300 to AD. For testing purposes, I add my Domain User as an Unity Administrator. After played around and customized base User DN and Group DN, Adding Group DN and assign it to proper priviilage, it Works!! I can connect to Unity with my domain user. So next things is I logged-out my domain account and l login again with local admin to delete my Domain User. (so I could test with group account).

Disaster just began. Right after I logout, I can't login to my domain account (I had added it to Administrator Domain Group). When I was about to check, I couldn't also login using local admin. I moved my domain user to AD Group domain which mapped to "Storage Admin" in Unity. I could login. But, I can't do anything to repair.

Today I reset admin password by pressing NMI button. Local admin password backed to default setting. But still "The logged in user is not authorized to access unisphere"


Any Suggestion?

  • P_Rakimanputra

    1 Rookie

    2 Posts

    3742

    0

    Posted September 26th, 2018 09:00

    Dear All,

    I think this is a bug from Unity 4.4. Here's steps to reproduce it:

    1) Join Unity machine to Active directory server.

    2) Verify all Active directory is working.

    3) Add 1 user from your active directory, and assign role as Administrator.

    4) Login with domain user.

    5) Go to user management, and try to delete yourself (it'll error)

    6) Logout and login back with your local admin.

    7) Now delete Domain User that you've created.

    8) You'll logout Automatically and you can't login with local admin nor group Admin (if you already create group admin)

    I dig logs myself, and I find that roleMapping for local admin just Empty:

    authorityName     entityName     mappingType    roleMappingKey     roleName               systemKey

    Local                  admin              localuser          CET318****           EMPTY_STRING     CETV****

    Well, EMC support.. can you give me tricks to restore this role mapping back?

  • DELL_ChrisHolloway

    2 Intern

    125 Posts

    3742

    1

    Posted September 28th, 2018 07:00

    You should open an SR regarding this issue.  Support don't monitor the community forums.

  • bt4781

    1 Rookie

    7 Posts

    3447

    0

    Posted April 4th, 2019 11:00

    Hello. We have the same problem and the emc support has until now no solution. push nmi button to reset the passwords of admin and service not resolve the issue. Has someone a solution over his emc support case? thanks.
  • 3402

    0

    Posted April 7th, 2019 23:00

    Hi @P_Rakimanputra 

    Thank you for your post.

    After further analysis of the data provided, the issue that you are currently facing is currently related with a known issue that has been detected with OE 4.4.x code.

    Currently there is a workaround that can be used to address your issue, and for further assistance please contact Dell EMC Support or your Authorized Service Representative for further assistance.

    Further details about this issue can be found at the Knowledge Base Article 000517150.

    If you require further clarification or assistance, please feel free to message me directly and I will review the status of the Service Request on our end.

     

  • 2573

    0

    Posted June 4th, 2019 10:00

    Ricardo, We are unable to reach the links to the KB aticles you included in your response, hence, unable to access the "workaround"  Could you please direct us to a working link for the actual KB article/fix/workaround for this?  Thanks, Brian

  • 2555

    0

    Posted June 4th, 2019 23:00

    Hi @BrianGEngineer ,

    Thank you for your update.

    After reviewing the knowledge Base document, the next steps of troubleshooting to be used to resolve the account issue will require an Higher level access to the array's backend.

    As a result, I recommend that a ticket is raised with Support to further investigate this situation and implement a workaround currently available.

    Please contact Dell EMC Technical Support or your Authorized Service Representative, and quote the Knowledgebase article ID that was provided in my previous post.

    Additionally, if you have a Dell EMC Support account, the article should be accessible.

    I hope that the above details provide further insight, however if you have additional queries, please let me know.