I've been trying to configure AD Auth for the CMC GUI and have been running into this issue:
[check]: (system) Verify needed system resources: PASSED [check]: (setup) Validate AD configuration: PASSED INFO - (setup) Using standard schema [check]: (setup) Verify SSL certificate files exist: PASSED [check]: (dns) Acquire LDAP and GC SRV records: PASSED [check]: (authen) Acquire user privileges: FAILED ERROR - (authen) AD INVALID CREDENTIAL 0x00006007 RESULT - Unable to acquire user privileges TEST FAILED
I saw in another thread that the user had a section for "common settings" and he was able to uncheck Certificate Validation and it worked for him, but I do not have that setting in CMC. The only place I see that setting is in the Generic LDAP section, which I would think wouldn't be applicable to setting up AD Auth.
I know my username/password are definitely correct so I'm not sure what the issue is and the logs aren't very help:
Aug 23 15:13:44 RCHASSIS01 webcgi: SRV.0 has hostname=dcblah, ipaddr.0=10.3.48.4, port=389 Aug 23 15:13:44 RCHASSIS01 webcgi: SRV.1 has hostname=dcblah, ipaddr.0=10.200.120.171, port=389 Aug 23 15:13:44 RCHASSIS01 webcgi: SRV.2 has hostname=dcblah, ipaddr.0=10.200.120.172, port=389 Aug 23 15:13:44 RCHASSIS01 webcgi: SRV.3 has hostname=dcblah, ipaddr.1=10.3.32.3, port=389 Aug 23 15:13:44 RCHASSIS01 webcgi: SRV.3 has hostname=dcblah, ipaddr.0=10.3.48.3, port=389 Aug 23 15:13:44 RCHASSIS01 webcgi: *** Started AD Test *** Aug 23 15:13:44 RCHASSIS01 webcgi: ActiveDirectoryAuthenticate: User: blah, Domain: blahdomain Aug 23 15:13:44 RCHASSIS01 webcgi: ActiveDirectoryAuthenticate: AD type: Standard Aug 23 15:13:45 RCHASSIS01 webcgi: At least one DC or GC Server must pass connection test Aug 23 15:13:45 RCHASSIS01 webcgi: *** Completed AD Test *** Aug 23 15:13:45 RCHASSIS01 webcgi: getDirSvcsTest() - [check]: (system) Verify needed system resources: PASSED\n[check]: (setup) Validate AD configuration: PASSED\nINFO - (setup) Using standard schema\n[check]: (setup) Verify SSL certificate files exist: PASSED\n[check]: (dns) Acquire LDAP and GC SRV records: PASSED\n[check]: (authen) Acquire user privileges: FAILED\nERROR - (authen) AD INVALID CREDENTIAL 0x00006007\nRESULT - Unab
It looks like that was failing on the SSL validation and not on getting the user privileges. What version of the CMC firmware are you on? What type of objects are you using?
For all references to Remote_Management_Advanced tou should use Remote_Management. For all references to Remote Management Object Advanced, you should use Remote Management Object.
My CMC firmware version is 1.32.200.201601210012. I'm not sure what you mean by what objects I'm using? I'm using the Standard Schema for AD if that's what you're referring to?
I saw that documentation too but couldn't find a way to add any AD groups in CMC. The only section I see that you can do that for is under the LDAP configs. I already have an existing group that I want to add as the admins for CMC, but all I can configure under Directory Services > AD is the SSL cert and the Kerberos Keytab which we are not using.
This is all I see. If there is a place to configure the Groups, can you direct me?
DELL-Josh Cr
Community Manager
•
9694 Posts
•
43679 Points
3253
0
Posted August 23rd, 2016 18:00
Hi,
It looks like that was failing on the SSL validation and not on getting the user privileges. What version of the CMC firmware are you on? What type of objects are you using?
For all references to Remote_Management_Advanced tou should use Remote_Management.
For all references to Remote Management Object Advanced, you should use Remote Management Object.