PowerVM

Power Virtualization

Learn about the virtualization technologies designed specifically for IBM Power including #PowerVM, #PowerVC, #VM Recovery Manager#HCM/CMC, and more.


#Power
#TechXchangeConferenceLab

 View Only
  • 1.  LDAP authentication in 2.0.3

    Posted Mon July 11, 2022 01:39 PM
    I'm setting up a brand new instance of PowerVC 2.0.3.  Install worked great, Ops Mgr and node on one Rhel 8.6 VM.  I see the DS8000 issue I was having with 2.0.2 has been fixed in 2.0.3  (THANK YOU!!).
    My question/problem is now dealing with LDAP authentication.  I am using the "powervc-config identity repository" command and it seems to accept all my parameters and configures but when everything restarts I cannot log in.  I get an error 500.Unknown Error.  

    I have verified the settings are identical to my PowerVC 2.0.1 system that we are currently using.

    The keystone.Default.conf file at /etc/keystone/domains doesn't seem to contain any of my settings though.

    Suggestions of which logs to be looking in?

    ------------------------------
    Tom Komadowski
    ------------------------------

    #PowerVC


  • 2.  RE: LDAP authentication in 2.0.3

    Posted Wed January 25, 2023 01:44 PM
    Just an update in case anyone runs into this issue in 2.0.3 with LDAP.  

    I was never able to track down why LDAP was failing for me in 2.0.3.  I worked on this as I had time but gave up when 2.1.0 was released.  Rolled out a 2.1.0 clean install and LDAP configuration worked properly for me first try.

    ------------------------------
    Tom Komadowski
    Principal DevOps Engineer
    Fortra, LLC.
    Eden Prairie MN
    ------------------------------



  • 3.  RE: LDAP authentication in 2.0.3

    Posted Wed August 02, 2023 06:00 PM

    Tom, I am having a similar issue: the command we use to setup ldap worked fine on 1.4 / 2.0.1.1 and 2.1.1 but will not work on 2.0.3..

    In working with support so far no resolution. 

    I am noticing that the date timestamp on the keystone.Default.conf file is not changing and if i change the information it does not seem to take my changes. 

    I changed mail to email just to see if it modified the file and it did not and there was not a new timestamp on it.



    ------------------------------
    Karen Van Gogh
    Jack Henry and Associates
    kvangogh@jackhenry.com
    ------------------------------



  • 4.  RE: LDAP authentication in 2.0.3

    Posted Wed August 02, 2023 06:51 PM

    I was able to fix my 2.0.3 issues i had to manually modify the keystone.default.conf file it was not updating that file at all. It had driver = local instead of driver = ldap the 2nd half of the information was missing so luckily i have a bunch of powerVC going so i was able to copy what i needed into the failing ldap config. I then re-ran the setup just to be safe and its not authenticating properly on 2.0.3.

    Good times!



    ------------------------------
    Karen Van Gogh
    Jack Henry and Associates
    kvangogh@jackhenry.com
    ------------------------------



  • 5.  RE: LDAP authentication in 2.0.3

    Posted Thu August 03, 2023 09:15 AM

    Correction to my previous reply:::::

    I was able to fix my 2.0.3 issues i had to manually modify the keystone.default.conf file it was not updating that file at all. It had driver = local instead of driver = ldap the 2nd half of the information was missing so luckily i have a bunch of powerVC going so i was able to copy what i needed into the failing ldap config. I then re-ran the setup just to be safe and its now authenticating properly on 2.0.3.

    The issues seemed to be in the setup that touched that file. It was taking a really long time to get past that point which was not the norm.



    ------------------------------
    Karen Van Gogh
    Jack Henry and Associates
    kvangogh@jackhenry.com
    ------------------------------