VMware Cloud Community
gkmishra
Contributor
Contributor

Active Directory Integration in Hyperic Enterprise 4.6

Hi Guys,

I am evaluating Hyperic Enterprise 4.6 for my organisation, and have successfully integrated Active Directory for authentication. However, I am not able to map Active Directory roles. When new AD user logs in, he is presented  with Guest dashboard.

I tried different attributes in Group Search Filter ((memberOf={1}), (memberOf={0}) and different attributes in  Group Search Role (dn, cn, name) etc. None of them seems to work.

Can you guys help me with right parameters for different attributes? Also, is there a way to see the log of LDAP authentication module ?

Thank you for your time, and help.

Tags (3)
Reply
0 Kudos
4 Replies
jtbilbro
Contributor
Contributor

Hey gkmishra-

We are trying to get AD integration setup on Hyperic Enterprise 4.6.0.1 and aren't having much luck.  Can you share your settings for LDAP properties?  Did you ever get the group mapping working?

Thanks for any pointers you can share,

-Jeff

Reply
0 Kudos
admin
Immortal
Immortal

This is our document link

http://support.hyperic.com/display/DOCS46/Configure+LDAP+Properties

Hope this will help.Please let me know if you still have problems.

Thank you,

Nipuna

Reply
0 Kudos
jtbilbro
Contributor
Contributor

I have tried several different combinations for the LDAP properties and still can't seem to get an LDAP user authenticated. 

Current settings:

LDAP URL:  ldap://foo-dc1.bar.com

Username:  CN=adsearch,CN=Managed Service Accounts,DC=bar,DC=com

Search Base: DC=bar,DC=com

Search Filter:  none

Login Property:  samAccountName

Group Search Base:  DC=bar,DC=com

Group Search Filter:  (member={1})

Search Subtree:  Yes

Group Search Role Attribute:  cn

Anyone got any insight as to what I might be doing wrong?  I am under the impression that I should be able to login with ANY AD user, enter their additional information (email address, etc.) and then that user should show up under Users in Hyperic HQ so I can map them to a role.  Is that accurate?

Thanks,

-Jeff

Reply
0 Kudos
hqpso
Enthusiast
Enthusiast

A couple of things.
1. There were issues with earlier 4.6 versions and LDAP. I recommend moving to 4.6.5.1 to avoid them.
2. Group Search Filter will depend on what overlays are installed and what order they are installed.
You can search directly without an overlay by using the full DN. Something like:
Group Search Base = OU=Tools, OU=Administrators, DC=bar, DC=com
Group Search Filter = (cn=Hyperic)
3. The Role you are trying to use from AD must be preconfigured in Hyperic and match in AD. Hyperic will not create the role for you.
4. The Group (or OU) must have the memberOf object declaring which sAMAccountNames belong to it.
Without knowing your exact schema YMMV.....  Smiley Wink
Reply
0 Kudos