Finally the LDAP problem was resolved. The issue, that was causing it, was that the AD account of the V-plex (In the current example "cn=sxxxvplex01"). You MUSTmark the AD-VPlex entry "password never expires" and from now on, it would be okay.
Thanks for your support here and I hope this post will be usefull for you!
in this example "useradministrative" is used as mapprincipal. You assumed that this is a group, not an ou. Does this mean, it can be a group and need not to be an OU? Documentation is only for using OU.
Tsetso
4 Posts
0
May 8th, 2012 07:00
Hello Farooq,
At first, many thanks for your responce!
We had set the custom-attributes, as it is described in the CLI guide and unfortunately the authentication is still not working...
The command that we had issued is, as follows:
############################
VPlexcli:/> authentication directory-service configure -i 53.121.xx.xx -b "dc=emea,dc=corpds,dc=net" -m "ou=usersadministrative,ou=de,dc=emea,dc=corpds,dc=net" -n "cn=sxxxvplex01,ou=unix,dc=emea,dc=corpds,dc=net" -d 2 -p -t 1 --server-name sxxxx202.emea.corpds.net -o 389 --custom-attributes
Enter sxxxvplex01's password:*****
Set value for posixAccount attribute [User]:
Set value for posixGroup attribute [Group]:
Set value for uid attribute [msSFU30Name]: samaccountname
Set value for uidNumber attribute [msSFU30UidNumber]: uidnumber
Set value for gidNumber attribute [msSFU30GidNumber]: gidnumber
Set value for loginShell attribute [msSFU30LoginShell]: loginshell
Set value for homeDirectory attribute [msSFU30HomeDirectory]:
unixhomedirectory
Connecting to authentication server (may take 3 minutes) ...
VPlexcli:/>
VPlexcli:/> authentication directory-service show
default-authentication-service: Native VPLEX
external-authentication-service: AD
ip: 53.121.xx.xx
base-dn: dc=emea,dc=corpds,dc=net
connection-type: TLS
mapped-principal: ['OU=UsersAdministrative,OU=de,DC=emea,DC=corpds,DC=net']
############################
Any other suggestions what could be wrong here? Thanks for your support!
Regards,
Tsetso
Tsetso
4 Posts
0
May 13th, 2012 23:00
Hi Farooq and all,
Yep, I can confirm the the Organizational unit, called "usersadministrative", has members in it. (OU name: usersadministrative\de\emea.corpds.net).
The thing, that is somehow blurry for me is: what should be the correct unix attributes and values? Could you advise me about that?
Thanks and kindest regards,
Tsetso
Tsetso
4 Posts
0
May 29th, 2012 15:00
Hi there,
Finally the LDAP problem was resolved. The issue, that was causing it, was that the AD account of the V-plex (In the current example "cn=sxxxvplex01"). You MUST mark the AD-VPlex entry "password never expires" and from now on, it would be okay.
Thanks for your support here and I hope this post will be usefull for you!
Cheers,
Tsetso
SW5
18 Posts
0
October 4th, 2012 08:00
Hi,
in this example "useradministrative" is used as mapprincipal. You assumed that this is a group, not an ou. Does this mean, it can be a group and need not to be an OU? Documentation is only for using OU.
Thanks
Stefan