This post is more than 5 years old
4 Posts
0
2548
August 12th, 2015 13:00
403 Forbidden with LDAP Authentication
Hello all,
I have a VNXe3200 running v3.1.1.5395470. I have LDAP Authentication configured per the documentation and have added LDAP users with the Administrator Role. Whenever one of my LDAP users authenticates, I get a 403 Forbidden error from Unisphere. This problem does not occur if I authenticate with the generic admin account or with a local account.
Not sure if anyone has seen this before or knows why Unisphere might be throwing this error. Any help with this would be greatly appreciated.
Thanks,
Jim



Jyothi_P_Bharat
317 Posts
0
August 13th, 2015 02:00
Hi Jim,
Please have a look on this kb:
kb192360
Thanks
Jyothi
sansjim
4 Posts
0
August 13th, 2015 05:00
Jyothi,
That looks exactly like what I have. Unfortunately it doesn't work whether I use just the systemname or systemname.domain. I guess they haven't gotten around to fixing it in the 5395470 version either so I guess I'll just keep an eye out for a future version that addresses the issue.
Thanks again,
Jim
Rainer_EMC
4 Operator
•
8.6K Posts
0
August 13th, 2015 06:00
I would suggest to open a service request so that this gets properly diagnosed and tracked
sansjim
4 Posts
0
August 13th, 2015 06:00
Thanks, I just did that.
sansjim
4 Posts
0
August 13th, 2015 12:00
I wanted to provide an update to this post. I was able to resolve this working with support.
In my ADUC console, my domain is shown in all uppercase (i.e. COMPANY.COM) so that is how I entered into the domain field in the Directory Services configuration. Turns out that UNISPHERE doesn't like that. Once I changed the domain to all lowercase (i.e. company.com), I was able to log in with AD accounts without an issue.
Thanks for those that responded, hopefully this will help anyone that has future issues.
Rainer_EMC
4 Operator
•
8.6K Posts
0
August 13th, 2015 14:00
Thanks for the feedback
Yes its often difficult between operating systems whether they are case sensitive / preserving or not