madcult
Enthusiast
Enthusiast

Searching for users in active directory fails

Hello,

I seem to have a problem with my Virtualcenter (2.5 Update 3) server and access to active directory. I've searched in this forum but haven't found anything close to my problem.

Due to migration there is a trust of two domains in our environment. I have granted access for some users of the first domain and for some users of the second domain on our Virtualcenter server. It worked fine for months. Time by time we revoked access for all users of the second domain and everything still worked well.

Yesterday I tried to add a new user from the second domain to our Virtualcenter server but the list where I can "select user" or group is empty. I cannot search for any user and group. Result is always empty but I can select the domain to search in. If I select the first domain everything works fine. Only the second domain seems to have trouble.

ADS works, I can log in to different systems by using users of the second domain. No changes had been made to the second domain.

Any ideas?

0 Kudos
5 Replies
AndreTheGiant
Immortal
Immortal

Seems to be some Group Policy restriction (to block users enum).

VC is not one of the DC (I hope it isn't)?

Do you have a 2008 AD?

Andre

**if you found this or any other answer useful please consider allocating points for helpful or correct answers

Andre | http://about.me/amauro | http://vinfrastructure.it/ | @Andrea_Mauro
0 Kudos
mpalijan
Contributor
Contributor

Hello,

did you fix your problem? I have the same issue right now and no idea how to solve it.

My VirtualCenter is Version 2.5 U6.

0 Kudos
alefestaedist
Hot Shot
Hot Shot

Can you validate the trust between domain sucessfully?  Seems that  your trust it doesnt' work correctly. Sometimes I've observed the same issue when one of the DC I used doesent work correctly or got some restriction (i.e.: firewall, policy).

Is there any error/warining on the DC?

0 Kudos
mpalijan
Contributor
Contributor

The trust works correctly. For example, our sharepoint on a different server in the same zone is able to show all objects from the other domain.

0 Kudos
alefestaedist
Hot Shot
Hot Shot

Do this test:

  1. From the vCenter open a command prompt and type %logonserver%
  2. From one of the server that works correctly do the same and check you are using the same DC. If everything looks correctly go to the step 3
  3. From the vCenter create a folder and in the security tab try to add users from the other domain and look if you got the same issue.

If you reproduce the problem double check  all the "standard" settings, like firewall, gateway, dns.

Double check tat in vCenter windows eventid you dont' have any warning or error.

If the DC are different could be that you have a replication issue with one of your DC.

0 Kudos