EcoStruxure IT forum
Schneider Electric support forum about installation and configuration for DCIM including EcoStruxure IT Expert, IT Advisor, Data Center Expert, and NetBotz
Link copied. Please paste this link to share this article on your social media post.
Posted: 2020-07-02 10:12 AM . Last Modified: 2024-04-10 12:58 AM
Hi
We are having an issue binding DCE to Active Directory. We are using DCE 7.2.2 on a physical appliance, device is on our network and can 'see' the Domain Controller. The account configured can successfully login to the domain from any workstation so it is not a user name password issue.
Bind User DN string is copied from AD.
I have read the manual and looked at the APC knowledge base article 'Tips for configuring Active Directory Integration' but am still getting the error message. The only issue I can think of is DCE does not like spaces in the DN
Bind User DN is
CN=username,OU=Admin,OU=Aneurin Bevan Health Board (ABB-7A6),OU=NHS Wales Organisations,DC=cymru,DC=nhs,DC=uk
(CID:93914143)
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: 2020-07-02 10:13 AM . Last Modified: 2024-04-10 12:58 AM
Looks like I have resolved the issue, the Bind User DN and Search Base are case sensitive which I knew from previous reading however I had the username in lower case when it wasn't
I used an LDAP browser to search the AD Domain and copied and pasted the results into the boxes and it worked
(CID:93914195)
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: 2020-07-02 10:12 AM . Last Modified: 2024-04-10 12:58 AM
Hi Chris,
Thanks for the post.
First of all, I would delete any current configuration you have set up for your Active Directory in the DCE client and start again (sometimes modifying what you have configured already in the DCE client may cause problems).
This is the search bind I have in my current setup: (apc1 is a user in my AD in the Users folder in AD, and the Bind Password is the password for the user apc1). Please also make sure that port 389 is open and you have chosen Active Directory:
Once I click on next, I get the following screen: (I am able to see my OU's (bredas test, bredas test 2)):
I would try something like the following search bind in your setup: (apc123 being a new user set up in your AD in the Users folder) .
CN=apc123, cn=Users, DC=cymru,DC=nhs,DC=uk
DC=cymru,DC=nhs,DC=uk
Let me know if this helps.
If it doesn't we may need to get the logs from you to analyse further. After trying to bind the settings again, go to your web browser and type in the following
Regards,
Breda
(CID:93914148)
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: 2020-07-02 10:12 AM . Last Modified: 2024-04-10 12:58 AM
Just to make sure you don't have the same issue I did. You still need to add each user or user group and assign permissions. You can just link it to the AD and try to automatically login.
In the above example, you need to check "breda" and then "Finish". Then go and assign that user permissions.
Just ignore me if you knew this already.
J
(CID:93914188)
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: 2020-07-02 10:12 AM . Last Modified: 2024-04-10 12:58 AM
Hi John If only I could get to the stage where I could add users, at the moment it is the AD binding that is causing me a headache Thanks Chris
(CID:93914193)
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: 2020-07-02 10:12 AM . Last Modified: 2024-04-10 12:58 AM
Hi, thanks for the posts
Breda, it is after entering the information in your 2nd screenshot and clicking 'Next' that the process fails. This is the 1st Authentication Server we are adding to DCE.
We are not permitted to create user accounts in the Users container but I have created an account in a root OU and tested this and I still get the same error message. The OU is called Leavers and my Bind User DN is
CN=abb_dceadmin, OU=Leavers, DC=Cymru, DC=nhs, DC=uk
My Search Base is
DC=cymru, DC=nhs, DC=uk
I have copied the logs off the appliance and stored in Dropbox, can you let me have your email so I can share them with you
Thanks
Chris
(CID:93914192)
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: 2020-07-02 10:13 AM . Last Modified: 2024-04-10 12:58 AM
for the user name CN , I have tried login name ( cn=abraish) it failed , I have used my display name (cn=Allan Braish) and it worked
(CID:96043675)
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: 2020-07-02 10:13 AM . Last Modified: 2024-04-10 12:58 AM
Looks like I have resolved the issue, the Bind User DN and Search Base are case sensitive which I knew from previous reading however I had the username in lower case when it wasn't
I used an LDAP browser to search the AD Domain and copied and pasted the results into the boxes and it worked
(CID:93914195)
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: 2020-07-02 10:13 AM . Last Modified: 2024-04-10 12:58 AM
I also have been fighting with the "Bind was unsuccessful. Check your settings." message. Similarly to the original poster, I used an LDAP browser to get the distinguished name and then just copy/pasted it into Struxureware. I used the free Softerra LDAP browser, but others would probably work the same.
(CID:105466027)
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: 2020-07-02 10:13 AM . Last Modified: 2023-10-31 10:13 PM
This question is closed for comments. You're welcome to start a new topic if you have further comments on this issue.
Link copied. Please paste this link to share this article on your social media post.
Create your free account or log in to subscribe to the board - and gain access to more than 10,000+ support articles along with insights from experts and peers.