Authentication errors after upgrade
Issue
- After upgrade rhev-m to version 3.5 we cannot logon with active directory users. Engine log shows:
2015-03-05 12:58:37,743 ERROR [org.ovirt.engine.extensions.aaa.builtin.kerberosldap.GSSAPIDirContextAuthenticationStrategy] (ajp-/127.0.0.1:8702-10) Kerberos error: Cannot locate KDC
2015-03-05 12:58:37,746 ERROR [org.ovirt.engine.extensions.aaa.builtin.kerberosldap.DirectorySearcher] (ajp-/127.0.0.1:8702-10) Failed ldap search server ldap://SERVER:IP using user USER@DOMAIN due to Kerberos error. Please check log for further details.. We should not try the next server
2015-03-05 12:58:37,747 ERROR [org.ovirt.engine.extensions.aaa.builtin.kerberosldap.LdapAuthenticateUserCommand] (ajp-/127.0.0.1:8702-10) Failed authenticating user: USER to domain DOMAIN. Ldap Query Type is getUserByName
2015-03-05 12:58:37,748 ERROR [org.ovirt.engine.extensions.aaa.builtin.kerberosldap.LdapAuthenticateUserCommand] (ajp-/127.0.0.1:8702-10) Kerberos error. Please check log for further details.
2015-03-05 12:58:37,748 ERROR [org.ovirt.engine.extensions.aaa.builtin.kerberosldap.LdapBrokerCommandBase] (ajp-/127.0.0.1:8702-10) Failed to run command LdapAuthenticateUserCommand. Domain is DOMAIN. User is USER.
2015-03-05 12:58:37,749 INFO [org.ovirt.engine.core.bll.aaa.LoginBaseCommand] (ajp-/127.0.0.1:8702-10) Cant login user "USER" with authentication profile "DOMAIN" because the authentication failed.
2015-03-05 12:58:38,465 ERROR [org.ovirt.engine.core.dal.dbbroker.auditloghandling.AuditLogDirector] (ajp-/127.0.0.1:8702-10) Correlation ID: null, Call Stack: null, Custom Event ID: -1, Message: User USER failed to log in.
2015-03-05 12:58:38,466 WARN [org.ovirt.engine.core.bll.aaa.LoginAdminUserCommand] (ajp-/127.0.0.1:8702-10) CanDoAction of action LoginAdminUser failed. Reasons:USER_FAILED_TO_AUTHENTICATE
Environment
RedHat Enterprise Virtualization (RHEV) 3.5
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.