VMware Cloud Community
sanoopku
Contributor
Contributor

Integration with Active Directory

I have Log Insight 3.3.1 deployed, when trying to integrate it with AD with the following params

Default Domain: FQDN for the AD Domain

Connection Type: Standard

I get the following error:

Unable to validate Active Directory credentials. Please check your Active Directory DNS name, port, and SSL settings as well as your username and password.

Details:

LoginException: Client not found in Kerberos database (6);

Asn1Exception: Identifier doesn't match expected value (906)

Are there any additional steps to be performed, ex: Joining the log insight server to the domain?

0 Kudos
1 Reply
admin
Immortal
Immortal

Hi,

What kind of AD setup do you have? Do you have parent and child domains? What kind of trust do you have setup between them?

And have you had a chance to check these few things we recommend - ?

The most common causes are expired passwords, incorrect credentials, connectivity problems, or lack of synch between the vRealize Log Insight virtual appliance and Active Directory clocks.

The most common causes are expired passwords, incorrect credentials, connectivity problems, or lack of synch between the vRealize Log Insight virtual appliance and Active Directory clocks.

Solution

■ Verify that your credentials are valid, your password has not expired, and your Active Directory account is not locked.

■ If you have not specified a domain to use with Active Directory authentication, verify that you have an account on the default domain stored in the latest vRealize Log Insight configuration at /storage/core/loginsight/config/loginsight-config.xml#[number] where [number] is the largest.

■ Find the latest configuration file: /storage/core/loginsight/config/loginsight-config.xml#[number] where [number] is the largest.

■ Verify vRealize Log Insight has connectivity to the Active Directory server.

   ■ Go to the Authentication section of the Administration page of the vRealize Log Insight Web user interface, fill in your user credentials, and click the Test Connection button.

   ■ Check the vRealize Log Insight /storage/var/loginsight/runtime.log for messages related to DNS problems.

■ Verify that the vRealize Log Insight and Active Directory clocks are in synch.

   ■ Check the vRealize Log Insight /storage/var/loginsight/runtime.log for messages related to clock skew.

   ■ Use an NTP server to synchronize the vRealize Log Insight and Active Directory clocks.

0 Kudos