Service Operations Insight

 View Only

Tech Tip: Cannot logon to SOI UI with AD users 

Dec 10, 2015 09:04 AM

Environment:

SOI 3.3

EEM 12.51

 

Problem:

EEM is integrated with Microsoft Active Directory, this configuration is working as expected. In the SOI Console, added couple of AD users to Administrator group.

But none of the AD users are unable to access SOI UI and getting Authentication failure errors.

 

In the \SOI\SamUI\logs\soiuis-debug.log shows below exceptions...

 

     eem.EEMSSOContext.authenticateWithPassword(283)  - [Authenticate Error: Authentication Failed, Identity Attempted: <DomainName\UserFirstname.LName] com.ca.eiam.SafePasswordException: EE_AUTHFAILED Authentication Failed

     eem.EEMSSOContext.authenticateWithPassword(299)  - EEMSSOContext::authenticateWithPassword - EEM Exception while authenticating...

     EE_BADOBJECT Bad Object[resource=/sam/ui/index.jsp][username=<DomainName\UserFirstname.LName]

     eem.EEMSSOContext.authenticateWithPassword(303)  - [] com.ca.eiam.SafeException: EE_BADOBJECT Bad Object

 

Resolution:

1) Logon to EEM UI -> Configure -> User Store -> "Reference from an external LDAP Directory"

2) If "Microsoft Active Directory Forest" option is selected, then SOI users cannot be authenticated (see attached screenshot)

3) Change this option to "Basic LDAP Directory" (see attached screenshot)

4) Now, all AD users will be able to access SOI UI

Statistics
0 Favorited
8 Views
2 Files
0 Shares
10 Downloads
Attachment(s)
jpg file
EEM_MultiDomainForest.jpg   113 KB   1 version
Uploaded - May 29, 2019
jpg file
EEM_BasicLdap.jpg   85 KB   1 version
Uploaded - May 29, 2019

Tags and Keywords

Comments

Mar 07, 2017 02:48 PM

Is SOI going to be enabled for multi-domain to benefit large companies that have this working environment?

Is there an open Idea for this?

Related Entries and Links

No Related Resource entered.