HP StorageWorks 2/16V Brocade Fabric Manager Administrator's Guide (53-1000019 - Page 342

Account Lockout, Changing Authentication Method

Page 342 highlights

26 Checking the Client Side • Fabric Manager server running under Solaris or Linux when using NIS authentication: NIS yourdomain.com "your_NISServer" • Fabric Manager server running under Solaris or Linux when using local password authentication: File • Fabric Manager server running under Windows, Solaris, or Linux when using RADIUS authentication: RADIUS yourRADIUSserver RADIUSportnumbers CHAP;PAP; your_sharedsecret Note If you are using the local password authentication, the DomainName attribute is missing from the XML file. Also, if you are using the NIS authentication, there is an extra parameter in the XML file called NISServer. 3. Check the Fabric Manager server log for any errors: /server/server/fmserver/log/server.log Example 2006-05-27 17:11:19,256 INFO [com.brocade.fabman.auth.server.FMAuthRemoteServer] Creating New Login Session: user = [stsun], client host = [192.168.42.139], session id= [2] 2006-05-27 17:11:19,272 INFO [com.brocade.fabman.auth.server.WinNTLoginModule] Authenticating user [stsun] using [brocade] domain 2006-05-27 17:11:20,272 ERROR [com.brocade.fabman.auth.server.WinNTLoginModule] Authentication failed for [brocade/stsun] Account Lockout For switches running Fabric OS v5.1.x or later, if the Fabric Manager server is using switch-based authentication while the password policies are enabled on the switch and the lockout threshold is set, then unsuccessful Fabric Manager client login attempts might lock out the switch password. The error message given is: Login failed for . Invalid userid/password. No indication is given that the switch password is locked out. Changing Authentication Method If you change the authentication method from Windows domain to either RADIUS or switch-based authentication, and then revert back to Windows domain authentication, subsequent Fabric Manager client logins fail with "java.lang.UnsatisfiedLinkError" or "java.lang.NoClassDefFoundError." 26-4 Fabric Manager Administrator's Guide Publication Number: 53-1000196-01-HP

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401
  • 402
  • 403
  • 404
  • 405
  • 406

26-4
Fabric Manager Administrator’s Guide
Publication Number: 53-1000196-01-HP
Checking the Client Side
26
Fabric Manager server running under Solaris or Linux when using NIS authentication:
<attribute name="LoginModule">NIS</attribute>
<attribute name="DomainName">
yourdomain.com
</attribute>
<attribute name="NISServer">"
your_NISServer
"</attribute>
Fabric Manager server running under Solaris or Linux when using local password
authentication:
<attribute name="LoginModule">File</attribute>
Fabric Manager server running under Windows, Solaris, or Linux when using RADIUS
authentication:
<attribute name="LoginModule">RADIUS</attribute>
<attribute name="RADIUSServerIP">
yourRADIUSserver
</attribute>
<attribute name="RADIUSServerPort">
RADIUSportnumbers
</attribute>
<attribute name="AuthenticationType">CHAP;PAP;</attribute>
<attribute name="SharedSecret">
your_sharedsecret
</attribute>
3.
Check the Fabric Manager server log for any errors:
<installdir>/server/server/fmserver/log/server.log
Example
Account Lockout
For switches running Fabric OS v5.1.x or later, if the Fabric Manager server is using switch-based
authentication while the password policies are enabled on the switch and the lockout threshold is set,
then unsuccessful Fabric Manager client login attempts might lock out the switch password. The error
message given is:
Login failed for <username>. Invalid userid/password.
No indication is given that the switch password is locked out.
Changing Authentication Method
If you change the authentication method from Windows domain to either RADIUS or switch-based
authentication, and then revert back to Windows domain authentication, subsequent Fabric Manager
client logins fail with “java.lang.UnsatisfiedLinkError” or “java.lang.NoClassDefFoundError.”
Note
If you are using the local password authentication, the
DomainName
attribute is missing
from the XML file. Also, if you are using the NIS authentication, there is an extra
parameter in the XML file called
NISServer
.
2006-05-27 17:11:19,256 INFO
[com.brocade.fabman.auth.server.FMAuthRemoteServer] Creating New Login
Session: user = [stsun], client host = [192.168.42.139], session id= [2]
2006-05-27 17:11:19,272 INFO
[com.brocade.fabman.auth.server.WinNTLoginModule] Authenticating user
[stsun] using [brocade] domain
2006-05-27 17:11:20,272 ERROR
[com.brocade.fabman.auth.server.WinNTLoginModule] Authentication failed
for [brocade/stsun]