EcoStruxure IT forum
A support forum for Data Center Operation, Data Center Expert, and EcoStruxure IT product users to share knowledge on installation, configuration, and general product use.
Posted: 2020-07-06 12:01 AM
This question was originally posted on DCIM Support by Chris Gray on 2019-12-06
In short, we had a working group using an LDAP bind to our AD, this connection was made to a single AD server. This server was then retired, I was not informed about it's retirement. I was then unable to log in using my AD credentials.
I've established a new LDAP connection, and have added 'different' AD groups and have assigned them rights and I'm able to log in using my AD credentials.
The issue I'm seeing, is the AD group that was bound from the old domain controller that was retired can not be removed from the System > Users and Device Group access. When attempting to delete the group I get a message stating that there was 'An error attempting to delete this group'. When viewing this group, it's not showing any information in the 'type' column, unlike all of the other groups. This is likely a result of the rug being pulled out from the DCE server's LDAP connection, is there a way to delete this group?
(CID:152568250)
Posted: 2020-07-06 12:01 AM
This answer was originally posted on DCIM Support by Steven Marchetti on 2019-12-06
Hi Chris,
Yes, that's a known issue. There are 2 ways to get rid of the old bind listing, neither of them really simple.
1: you can re-add your AD server at the old IP (in the same configuration) for just a short period of time so that DCE can connect and subsequently delete that listing.
2: you'll need to contact tech support directly. If they're allowed remote access to your system, they should be able to remove that listing. Sorry but root access is restricted and that is required to remove these entries.
Thanks,
Steve
(CID:152568254)
Posted: 2020-07-06 12:01 AM
This answer was originally posted on DCIM Support by Steven Marchetti on 2019-12-06
Hi Chris,
Yes, that's a known issue. There are 2 ways to get rid of the old bind listing, neither of them really simple.
1: you can re-add your AD server at the old IP (in the same configuration) for just a short period of time so that DCE can connect and subsequently delete that listing.
2: you'll need to contact tech support directly. If they're allowed remote access to your system, they should be able to remove that listing. Sorry but root access is restricted and that is required to remove these entries.
Thanks,
Steve
(CID:152568254)
Posted: 2020-07-06 12:01 AM
This comment was originally posted on DCIM Support by Chris Gray on 2019-12-09
Thanks Steve, I've contacted support and will reconnect with them later in the week.
(CID:152568667)
Posted: 2020-07-06 12:01 AM
This comment was originally posted on DCIM Support by Steven Marchetti on 2019-12-09
Thanks for the update!
(CID:152568669)
Posted: 2020-07-06 12:01 AM
This question is closed for comments. You're welcome to start a new topic if you have further comments on this issue.
Create your free account or log in to subscribe to the forum - and gain access to more than 10,000+ support articles along with insights from experts and peers.