Data Protection Central:為 Data Domain 設定 SSO 時,無法進行設定。

Summary: 本文說明如何解決從 Data Protection Central (DPC) 設定單一登入 (SSO) 至 Data Domain 時的問題。

This article applies to This article does not apply to This article is not tied to any specific product. Not all product versions are identified in this article.

Symptoms

在 DPC UI 中,您按一下 Data Domain 伺服器的 重新註冊 SSO
SSO 重新註冊
單擊 “重新註冊 SSO”後,檢查“ 審核 ”選項卡,並看到註冊失敗。展開故障,您會看到以下錯誤:
展開故障
檢查 elg.log 檔案時發現以下錯誤:
2020-06-29 13:49:36,424 WARN OkHttp https://<DD hostname>:3009/... c.e.c.t.TaskServiceImpl Reregistration of SSO client for <DD hostname> failed
java.util.concurrent.CompletionException: com.emc.clp.spi.ForbiddenException: Administrator credentials required for the SSO registration
    at java.util.concurrent.CompletableFuture.encodeThrowable(CompletableFuture.java:273)
    at java.util.concurrent.CompletableFuture.completeThrowable(CompletableFuture.java:280)
    at java.util.concurrent.CompletableFuture.uniHandle(CompletableFuture.java:838)
    at java.util.concurrent.CompletableFuture$UniHandle.tryFire(CompletableFuture.java:811)
    at java.util.concurrent.CompletableFuture.postComplete(CompletableFuture.java:488)
    at java.util.concurrent.CompletableFuture.completeExceptionally(CompletableFuture.java:1990)
    at com.emc.edp.http.OkHttpHttpClient.fail(OkHttpHttpClient.java:677)
    at com.emc.edp.http.OkHttpHttpClient.access$400(OkHttpHttpClient.java:34)
    at com.emc.edp.http.OkHttpHttpClient$3.onResponse(OkHttpHttpClient.java:555)
    at okhttp3.RealCall$AsyncCall.execute(RealCall.java:174)
    at okhttp3.internal.NamedRunnable.run(NamedRunnable.java:32)
    at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1149)
    at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:624)
    at java.lang.Thread.run(Thread.java:748)
Caused by: com.emc.clp.spi.ForbiddenException: Administrator credentials required for the SSO registration
    at com.emc.clp.plugin.datadomain.DataDomainElementalHandler.lambda$handleClientRegistration$3(DataDomainElementalHandler.java:281)
    at com.emc.dpc.common.util.CompletableFutureUtils.lambda$convertException$0(CompletableFutureUtils.java:110)
    at java.util.concurrent.CompletableFuture.uniHandle(CompletableFuture.java:836)
    ... 11 common frames omitted
Caused by: com.emc.edp.http.HttpException: [500] Internal Server Error
    at com.emc.edp.http.OkHttpHttpClient.createHttpException(OkHttpHttpClient.java:670)
    at com.emc.clp.plugin.datadomain.http.DataDomainHttpClient.createHttpException(DataDomainHttpClient.java:314)
    ... 6 common frames omitted
Caused by: com.emc.edp.http.OkHttpHttpClient$OriginalRequest: POST https://<DD hostname>:3009/rest/v1.0/trust
    at com.emc.edp.http.OkHttpHttpClient.startRequest(OkHttpHttpClient.java:502)
    at com.emc.edp.http.OkHttpHttpClient.startRequest(OkHttpHttpClient.java:474)
    at com.emc.clp.plugin.datadomain.http.DataDomainHttpClient.post(DataDomainHttpClient.java:155)
    at com.emc.clp.plugin.datadomain.DataDomainElementalHandler.handleClientRegistration(DataDomainElementalHandler.java:279)
    at com.emc.clp.security.sso.SsoElementalRegistrationService.sendSsoRegistrationRequestToElemental(SsoElementalRegistrationService.java:333)
    at com.emc.clp.security.sso.SsoElementalRegistrationService.lambda$getRegisterSubTasks$4(SsoElementalRegistrationService.java:154)
    at java.util.concurrent.CompletableFuture.uniCompose(CompletableFuture.java:966)
    at java.util.concurrent.CompletableFuture$UniCompose.tryFire(CompletableFuture.java:940)
    at java.util.concurrent.CompletableFuture.postComplete(CompletableFuture.java:488)
    at java.util.concurrent.CompletableFuture.completeExceptionally(CompletableFuture.java:1990)
    at com.emc.edp.http.OkHttpHttpClient.fail(OkHttpHttpClient.java:677)
    at com.emc.edp.http.OkHttpHttpClient.access$400(OkHttpHttpClient.java:34)
    ... 6 common frames omitted

Cause

sysadmin 帳戶是唯一可以在 Data Domain 中註冊 SSO 的帳戶。

在這種情況下,您會收到需要系統管理員認證的錯誤。使用 sysadmin 以外的使用者在 DPC 中探索到 Data Domain,導致此作業失敗。

Resolution

在記錄中,您會看到下列導致註冊失敗的認證錯誤:

Caused by: com.emc.clp.spi.ForbiddenException: Administrator credentials required for the SSO registration
  • 若要註冊 SSO,您必須使用 sysadmin 帳戶,因為這是唯一可以註冊 SSO 的帳戶。甚至其他管理員帳戶也沒有該許可權。 
  • 在 DPC 中探索到 Data Domain 時,可能並未使用 sysadmin 帳戶。在 DPC 系統管理頁面中編輯 Data Domain,然後輸入 sysadmin 帳戶和該帳戶的密碼。 
  • 嘗試從 DPC UI 再次註冊 SSO。
註冊應會成功。

如有進一步問題,請聯絡 Dell 支援

Affected Products

Data Protection Central
Article Properties
Article Number: 000173543
Article Type: Solution
Last Modified: 26 Mar 2025
Version:  7
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.