Data Protection Central:为 Data Domain 配置 SSO 时,配置失败。
Summary: 本文介绍如何解决设置从 Data Protection Central (DPC) 到 Data Domain 的单点登录 (SSO) 时遇到的问题。
This article applies to
This article does not apply to
This article is not tied to any specific product.
Not all product versions are identified in this article.
Symptoms
在 DPC UI 中,单击 Reregister SSO for a Data Domain server。
单击 “重新注册 SSO”后,检查 “审核 ”选项卡,发现注册失败。展开失败,您会看到以下错误:
检查 elg.log 文件,您会发现以下错误:
2020-06-29 13:49:36,424 WARN OkHttp https://<DD hostname>:3009/... c.e.c.t.TaskServiceImpl Reregistration of SSO client for <DD hostname> failed java.util.concurrent.CompletionException: com.emc.clp.spi.ForbiddenException: Administrator credentials required for the SSO registration at java.util.concurrent.CompletableFuture.encodeThrowable(CompletableFuture.java:273) at java.util.concurrent.CompletableFuture.completeThrowable(CompletableFuture.java:280) at java.util.concurrent.CompletableFuture.uniHandle(CompletableFuture.java:838) at java.util.concurrent.CompletableFuture$UniHandle.tryFire(CompletableFuture.java:811) at java.util.concurrent.CompletableFuture.postComplete(CompletableFuture.java:488) at java.util.concurrent.CompletableFuture.completeExceptionally(CompletableFuture.java:1990) at com.emc.edp.http.OkHttpHttpClient.fail(OkHttpHttpClient.java:677) at com.emc.edp.http.OkHttpHttpClient.access$400(OkHttpHttpClient.java:34) at com.emc.edp.http.OkHttpHttpClient$3.onResponse(OkHttpHttpClient.java:555) at okhttp3.RealCall$AsyncCall.execute(RealCall.java:174) at okhttp3.internal.NamedRunnable.run(NamedRunnable.java:32) at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1149) at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:624) at java.lang.Thread.run(Thread.java:748) Caused by: com.emc.clp.spi.ForbiddenException: Administrator credentials required for the SSO registration at com.emc.clp.plugin.datadomain.DataDomainElementalHandler.lambda$handleClientRegistration$3(DataDomainElementalHandler.java:281) at com.emc.dpc.common.util.CompletableFutureUtils.lambda$convertException$0(CompletableFutureUtils.java:110) at java.util.concurrent.CompletableFuture.uniHandle(CompletableFuture.java:836) ... 11 common frames omitted Caused by: com.emc.edp.http.HttpException: [500] Internal Server Error at com.emc.edp.http.OkHttpHttpClient.createHttpException(OkHttpHttpClient.java:670) at com.emc.clp.plugin.datadomain.http.DataDomainHttpClient.createHttpException(DataDomainHttpClient.java:314) ... 6 common frames omitted Caused by: com.emc.edp.http.OkHttpHttpClient$OriginalRequest: POST https://<DD hostname>:3009/rest/v1.0/trust at com.emc.edp.http.OkHttpHttpClient.startRequest(OkHttpHttpClient.java:502) at com.emc.edp.http.OkHttpHttpClient.startRequest(OkHttpHttpClient.java:474) at com.emc.clp.plugin.datadomain.http.DataDomainHttpClient.post(DataDomainHttpClient.java:155) at com.emc.clp.plugin.datadomain.DataDomainElementalHandler.handleClientRegistration(DataDomainElementalHandler.java:279) at com.emc.clp.security.sso.SsoElementalRegistrationService.sendSsoRegistrationRequestToElemental(SsoElementalRegistrationService.java:333) at com.emc.clp.security.sso.SsoElementalRegistrationService.lambda$getRegisterSubTasks$4(SsoElementalRegistrationService.java:154) at java.util.concurrent.CompletableFuture.uniCompose(CompletableFuture.java:966) at java.util.concurrent.CompletableFuture$UniCompose.tryFire(CompletableFuture.java:940) at java.util.concurrent.CompletableFuture.postComplete(CompletableFuture.java:488) at java.util.concurrent.CompletableFuture.completeExceptionally(CompletableFuture.java:1990) at com.emc.edp.http.OkHttpHttpClient.fail(OkHttpHttpClient.java:677) at com.emc.edp.http.OkHttpHttpClient.access$400(OkHttpHttpClient.java:34) ... 6 common frames omitted
Cause
sysadmin 帐户是唯一可以在 Data Domain 中注册 SSO 的帐户。
在这种情况下,您会收到管理员凭据要求错误。在 DPC 中以 sysadmin 以外的用户身份发现 Data Domain,这导致此作失败。
在这种情况下,您会收到管理员凭据要求错误。在 DPC 中以 sysadmin 以外的用户身份发现 Data Domain,这导致此作失败。
Resolution
在日志中,您会看到以下导致注册失败的凭据错误:
Caused by: com.emc.clp.spi.ForbiddenException: Administrator credentials required for the SSO registration
- 要向 SSO 注册,您必须使用 sysadmin 帐户,因为这是唯一可以注册 SSO 的帐户。即使是其他管理员帐户也没有该权限。
- 在 DPC 中发现 Data Domain 时,可能尚未为其提供 sysadmin 帐户。在 DPC 系统管理页面中编辑 Data Domain,然后输入 sysadmin 帐户和该帐户的密码。
- 尝试从 DPC UI 再次注册 SSO。
如有其他问题,请联系 戴尔支持 。
Affected Products
Data Protection CentralArticle Properties
Article Number: 000173543
Article Type: Solution
Last Modified: 26 Mar 2025
Version: 7
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.