PowerFlex LDAP user unable to GUI, but the same user can log in using scli command line

Summary: PowerFlex LDAP user unable to GUI, but same users can log in using scli command line.

This article applies to This article does not apply to This article is not tied to any specific product. Not all product versions are identified in this article.

Symptoms

LDAP users can login using CLI but are unable to login using GUI. 

mosLdap_BindS:00268: User test@fqdn11.com was successfully binded to LDAP service
mosLdap_BindS:00268: User test@fqdn11.com was successfully binded to LDAP service
ldapAuthMgr_Login:00166: Could not find LDAP service with FQDN: fqdn11
ldapAuthMgr_Login:00166: Could not find LDAP service with FQDN: fqdn11
mosEventLog_PostInternal:00590: New event added. Message: "Command login was not successful. Error code: Could not find LDAP service. [6974115]". Additional info: "" Severity: Warning
ldapAuthMgr_GetUserInfoFromToken:01742: Failed to find session for authentication. rc=INVALID_SESSION
0:mosLdap_Initialize:00231: Connection was successfully established to ldap://testhost.fqdn1.com:389 ldap service

Cause

As per the LDAP Configuration Guide, 
All LDAP groups must be assigned the Monitor role if they want those LDAP users to be able to use the GUI/plug-in.

Resolution

Assign the LDAP groups to roles.

After the LDAP service is configured, use the --assign_ldap_groups_to_roles command to map the LDAP groups to PowerFlex user roles. Assign an LDAP group to each PowerFlex role. The same LDAP group can be assigned to multiple roles. For an explanation of the different user roles, see PowerFlex authentication and user roles.

The following considerations should be made when assigning groups to roles when LDAP authentication is used:

  • If you want LDAP users to be able to use the PowerFlex GUI or query the system, you must assign an LDAP group to the Monitor role.
NOTE: If an LDAP user role is changed, users must log out of PowerFlex and log back in with the updated permissions.

Additional Information

Affected Products

PowerFlex Software

Products

PowerFlex Software, VxFlex Product Family, VxFlex Ready Node, ScaleIO Ready Node-PowerEdge 13G
Article Properties
Article Number: 000055908
Article Type: Solution
Last Modified: 20 Nov 2024
Version:  3
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.