Bug 1473450 - Configuration of LDAPS (AD integration) not working correctly.
Configuration of LDAPS (AD integration) not working correctly.
Product: Red Hat CloudForms Management Engine
Classification: Red Hat
Component: Appliance (Show other bugs)
All All
unspecified Severity high
: GA
: cfme-future
Assigned To: Joe Vlcek
Matt Pusateri
Depends On:
  Show dependency treegraph
Reported: 2017-07-20 18:40 EDT by Ryan Spagnola
Modified: 2017-08-30 10:35 EDT (History)
7 users (show)

See Also:
Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of:
Last Closed: 2017-07-28 14:40:18 EDT
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: Bug
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: CFME Core

Attachments (Terms of Use)

  None (edit)
Comment 5 Joe Vlcek 2017-07-21 11:58:47 EDT
Hello Ryan,

The basedn in the attached log looks a bit odd. It is showing up as:

  :basedn: DC=EDC,DC=DS1,DC=USDA,DC=GOV?sAMAccountName?sub

  Please provide a screen shot of the Cloudforms Configuration/Server/Authentication page
  and try setting the "Base DN" to "DC=EDC,DC=DS1,DC=USDA,DC=GOV"
  without the "?sAMAccountName?sub"

If this does not resolve the failure you are encountering please provide the following:

Please attach the output from a ping to the LDAP Hosts you have configured.

  ping oiractlpvwa13.edc.ds1.usda.gov
  ping oiractlpvwa15.edc.ds1.usda.gov
  ping oiractlpvwa16.edc.ds1.usda.gov

Please attach to this BZ file: /etc/openldap/ldap.conf

Please attach to this BZ the 3 output file generated by the following ldapsearch commands:

  ldapsearch -x -H ldaps://<your LDAP Host Name>:636 -b "<your Base DN>" -d1 > ldapsearch_output_with_basedn.txt 2>&1
  ldapsearch -x -H ldaps://<your LDAP Host Name>:636 -d1                     > ldapsearch_output_without_basedn.txt 2>&1
  ldapsearch -x -H ldaps://<your LDAP Host Name>:636 -s base -b "" -LLL "+"  > ldapsearch_output_base.txt 2>&1

  If these commands produce failures please diagnose and address the failures before proceeding.

I see you have 3 LDAP Hosts configured. Perhaps it would be best, while diagnosing the issues you are encountering, if you only configure one of them.

Please tar and attach directory /var/www/miq/vmdb/log right after a failed attempt to login to Cloudforms.

Thank you. JoeV

Note You need to log in before you can comment on or make changes to this bug.