PowerStore: Unable to login using openLDAP group permissions

Summary: Log in to PowerStore Manager using OpenLDAP accounts with group-based permissions fails on PowerStoreOS Version 4.1.0.0 and higher, if the group member atribute is memberUid.

This article applies to This article does not apply to This article is not tied to any specific product. Not all product versions are identified in this article.

Symptoms

Log in to PowerStore Manager fails for OpenLDAP users that inherit access permissions from a user group on PowerStoreOS version 4.1. Log in is allowed if access is added to the specific OpenLDAP user.

 

Verify the current Authentication configuration in the PowerStore Manager settings:

Settings, Security, Authentication -> Edit LDAP Configuration

  • Verify Server Type is OpenLDAP
  • Advanced Settings, Group Search Settings - Member Attribute is set to memberUid

 

Settings, Security, Users - LDAP

  • The assigned Permission Type is a Group permission

 

After an unsuccessful login attempt with the openLDAP user, verify Audit logs:

Settings, Security, Audit Logs

  • Filter User to the openLDAP user that tried to log in (user@domain.com)
  • Verify that password authentication was successful, but Authorization failed:
    • User "user@domain.com" logged in successfully using password authentication
    • Authorization failed for the user account: user@domain.com, while requesting....

Cause

The user is able to authenticate with the openLDAP server, but PowerStore is unable to get the user group memberships.

Resolution

There are two possible workarounds available:

  • Assign user-based access permissions on the PowerStore, in Settings, Security, Users - LDAP
  • Change the member Attribute in openLDAP and the PowerStore LDAP settings to uniqueMember instead of memberUid.
    This setting has to be changed in both
    • PowerStore, Settings, Security, Authentication -> Edit LDAP Configuration
      Advanced Settings, Group Search Settings, Member Attribute
    • The openLDAP server, in the respective user group settings

 

This issue will be fixed in a future release of PowerStoreOS

Affected Products

PowerStore 1000T, PowerStore 1200T, PowerStore 3000T, PowerStore 3200Q, PowerStore 3200T, PowerStore 5000T, PowerStore 500T, PowerStore 5200Q, PowerStore 5200T, PowerStore 7000T

Products

PowerStore 9000T, PowerStore 9200T
Article Properties
Article Number: 000379450
Article Type: Solution
Last Modified: 14 Oct 2025
Version:  1
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.