Data Protection Central:为 Data Domain 配置 SSO 时,配置失败。

Summary: 本文介绍如何解决设置从 Data Protection Central (DPC) 到 Data Domain 的单点登录 (SSO) 时遇到的问题。

This article applies to This article does not apply to This article is not tied to any specific product. Not all product versions are identified in this article.

Symptoms

在 DPC UI 中,单击 Reregister SSO for a Data Domain server。
SSO 重新注册
单击 “重新注册 SSO”后,检查 “审核 ”选项卡,发现注册失败。展开失败,您会看到以下错误:
展开故障范围
检查 elg.log 文件,您会发现以下错误:
2020-06-29 13:49:36,424 WARN OkHttp https://<DD hostname>:3009/... c.e.c.t.TaskServiceImpl Reregistration of SSO client for <DD hostname> failed
java.util.concurrent.CompletionException: com.emc.clp.spi.ForbiddenException: Administrator credentials required for the SSO registration
    at java.util.concurrent.CompletableFuture.encodeThrowable(CompletableFuture.java:273)
    at java.util.concurrent.CompletableFuture.completeThrowable(CompletableFuture.java:280)
    at java.util.concurrent.CompletableFuture.uniHandle(CompletableFuture.java:838)
    at java.util.concurrent.CompletableFuture$UniHandle.tryFire(CompletableFuture.java:811)
    at java.util.concurrent.CompletableFuture.postComplete(CompletableFuture.java:488)
    at java.util.concurrent.CompletableFuture.completeExceptionally(CompletableFuture.java:1990)
    at com.emc.edp.http.OkHttpHttpClient.fail(OkHttpHttpClient.java:677)
    at com.emc.edp.http.OkHttpHttpClient.access$400(OkHttpHttpClient.java:34)
    at com.emc.edp.http.OkHttpHttpClient$3.onResponse(OkHttpHttpClient.java:555)
    at okhttp3.RealCall$AsyncCall.execute(RealCall.java:174)
    at okhttp3.internal.NamedRunnable.run(NamedRunnable.java:32)
    at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1149)
    at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:624)
    at java.lang.Thread.run(Thread.java:748)
Caused by: com.emc.clp.spi.ForbiddenException: Administrator credentials required for the SSO registration
    at com.emc.clp.plugin.datadomain.DataDomainElementalHandler.lambda$handleClientRegistration$3(DataDomainElementalHandler.java:281)
    at com.emc.dpc.common.util.CompletableFutureUtils.lambda$convertException$0(CompletableFutureUtils.java:110)
    at java.util.concurrent.CompletableFuture.uniHandle(CompletableFuture.java:836)
    ... 11 common frames omitted
Caused by: com.emc.edp.http.HttpException: [500] Internal Server Error
    at com.emc.edp.http.OkHttpHttpClient.createHttpException(OkHttpHttpClient.java:670)
    at com.emc.clp.plugin.datadomain.http.DataDomainHttpClient.createHttpException(DataDomainHttpClient.java:314)
    ... 6 common frames omitted
Caused by: com.emc.edp.http.OkHttpHttpClient$OriginalRequest: POST https://<DD hostname>:3009/rest/v1.0/trust
    at com.emc.edp.http.OkHttpHttpClient.startRequest(OkHttpHttpClient.java:502)
    at com.emc.edp.http.OkHttpHttpClient.startRequest(OkHttpHttpClient.java:474)
    at com.emc.clp.plugin.datadomain.http.DataDomainHttpClient.post(DataDomainHttpClient.java:155)
    at com.emc.clp.plugin.datadomain.DataDomainElementalHandler.handleClientRegistration(DataDomainElementalHandler.java:279)
    at com.emc.clp.security.sso.SsoElementalRegistrationService.sendSsoRegistrationRequestToElemental(SsoElementalRegistrationService.java:333)
    at com.emc.clp.security.sso.SsoElementalRegistrationService.lambda$getRegisterSubTasks$4(SsoElementalRegistrationService.java:154)
    at java.util.concurrent.CompletableFuture.uniCompose(CompletableFuture.java:966)
    at java.util.concurrent.CompletableFuture$UniCompose.tryFire(CompletableFuture.java:940)
    at java.util.concurrent.CompletableFuture.postComplete(CompletableFuture.java:488)
    at java.util.concurrent.CompletableFuture.completeExceptionally(CompletableFuture.java:1990)
    at com.emc.edp.http.OkHttpHttpClient.fail(OkHttpHttpClient.java:677)
    at com.emc.edp.http.OkHttpHttpClient.access$400(OkHttpHttpClient.java:34)
    ... 6 common frames omitted

Cause

sysadmin 帐户是唯一可以在 Data Domain 中注册 SSO 的帐户。

在这种情况下,您会收到管理员凭据要求错误。在 DPC 中以 sysadmin 以外的用户身份发现 Data Domain,这导致此作失败。

Resolution

在日志中,您会看到以下导致注册失败的凭据错误:

Caused by: com.emc.clp.spi.ForbiddenException: Administrator credentials required for the SSO registration
  • 要向 SSO 注册,您必须使用 sysadmin 帐户,因为这是唯一可以注册 SSO 的帐户。即使是其他管理员帐户也没有该权限。 
  • 在 DPC 中发现 Data Domain 时,可能尚未为其提供 sysadmin 帐户。在 DPC 系统管理页面中编辑 Data Domain,然后输入 sysadmin 帐户和该帐户的密码。 
  • 尝试从 DPC UI 再次注册 SSO。
注册应成功。

如有其他问题,请联系 戴尔支持

Affected Products

Data Protection Central
Article Properties
Article Number: 000173543
Article Type: Solution
Last Modified: 26 Mar 2025
Version:  7
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.