Users must have view privileges (at minimum) on a managed object to see that object in the user interface.
Cause
You do not have proper authorization or you entered invalid parameters.
Action
-
Log in to the appliance as the Infrastructure administrator.
-
Try to add, edit, or delete the user account again.
For more information, see Add or Edit User screen details.
Each user is authenticated on login to the appliance by the authentication service that confirms the user name and password. The Edit Authentication screen enables you to configure authentication settings on the appliance; the default values are initially populated during first time setup of the appliance.
| Symptom | Possible cause and recommendation |
|---|---|
|
Unable to configure a directory user or group |
Configure authentication settings
|
| Symptom | Possible cause and recommendation |
|---|---|
|
User public key does not work or is not accepted |
Hidden characters introduced during a copy/paste operation change the key code
|
The server for the directory service cannot be accessed.
Cause
Either the server for the directory service or the network is down.
Action
-
Run the
pingcommand on the directory server IP address or host name to determine if it is online. -
Contact the directory service administrator to determine if the server is down.
Cause
Configuration errors prevent the directory service from being reached
Action
-
Verify that the name of the directory service is unique and entered correctly. Duplicate names are not accepted.
-
Ensure that the Base DN fields and, for OpenLDAP, the User naming attribute field, and Organizational unit fields are correct.
For more information, see .Add/Edit Directory screen details.
-
Verify that the credentials of the authentication directory service administrator are correct.
-
Verify that the group is configured in the directory service.
-
Ensure that the role assigned to the group is correct.
For more information, see Add/Edit Directory Group screen details
Cause
An external problem disconnected the directory server host.
Action
-
Verify that the settings for the directory service host are accurate.
-
Locally run the
pingcommand on the directory server’s IP address or host name to determine if it is on-line. -
Verify that the port for LDAP communication with the directory service is port 636.
-
Verify that the port (default port 636) you are using for communication is not blocked by any firewalls.
-
Determine that the appliance is functioning properly and that there are enough resources.
Cause
The directory server host is refusing to authenticate the appliance because the certificate has expired.
Action
Cause
The directory server host cannot authenticate the appliance because the credentials are invalid.
Action
Cause
The appliance lost connection with the directory service, but that connection was lost.
Action
-
Verify that the settings for the directory service host are accurate.
-
Verify that the correct port is used for the directory service.
-
Verify that the port (default port 636) you are using for communication is not blocked by any firewalls.
-
Locally run the
pingcommand on the directory service host’s IP address or host name to determine if it is on-line. -
[Conditionalized for TBunsupported] If the appliance is hosted on a virtual machine, determine that it is functioning properly and there are enough resources.
Cause
There are incorrect parameters when the directory service was configured.
Action
-
Verify that the name of the directory service is unique and entered correctly. Duplicate names are not accepted.
-
Ensure that the Base DN fields and, for OpenLDAP, the User naming attribute field, and Organizational unit fields are correct.
For more information, see Add/Edit Directory screen details
-
Verify that the credentials of the authentication directory service administrator are correct.
-
Verify that the group is configured in the directory service.
Cause
The specified authentication directory and group specified already exist. Groups must be unique.
Action
Cause
An external problem disconnected the directory server host.
Action
-
Verify that the settings for the directory service host are accurate.
-
Verify that the correct port is used for the directory service.
-
Verify that the port (default port 636) you are using for communication is not blocked by any firewalls.
-
Locally run the
pingcommand on the directory service host IP address or host name to determine if it is online. -
If the appliance is hosted on a virtual machine, determine that the virtual machine is functioning properly and enough resources are allocated to it.
Cause
Either the group is not configured in the authentication directory service or the search parameters contained an error.
Action
-
Verify the credentials for the authentication directory service.
-
Contact the directory service administrator to verify that the group account is configured in the directory service.
-
For more information, see About directory service authentication.
Cause
The directory type was incorrectly specified. For example, an Active Directory service might have be specified as OpenLDAP.
Action
-
Verify that the settings for the directory service are accurate.
Cause
The specified search of the authentication directory service does not contain any groups.
Action
-
Verify the directory server configuration.
-
For OpenLDAP, ensure that the directory server user has read privileges (
rscdx) so that HPE OneView can read the search results. -
For OpenLDAP, add all search contexts to retrieve the wanted group or groups. Use the Add button to generate additional multiple organizational units, with which to specify the
UIDorCN.For more information, see Add/Edit Directory screen details
Cause
An error occurred while accessing directory groups. Directory service servers could not be reached.
Action
-
Verify the directory server configuration.
-
For OpenLDAP, add all search contexts to retrieve the wanted group or groups. Use the Add button to generate additional multiple organizational units, with which to specify the
UIDorCN.For more information, see Add/Edit Directory screen details
Cause
An external problem prevented the appliance from reaching the server configured for the directory service.
Action
-
Verify the connection to the directory server host. See Cannot add server for a directory service .
-
Verify the directory server configuration.