SPC-OCA-10486 - Can't login in OneClick web page after CA EEM 12.51 integration

Document ID:  TEC1037224
Last Modified Date:  08/01/2017
{{active ? 'Hide' : 'Show'}} Technical Document Details

Products

  • CA Spectrum

Releases

  • CA Spectrum:Release:10.2
  • CA Spectrum:Release:10.1.1
  • CA Spectrum:Release:10.1.2
  • CA Spectrum:Release:10.2.1
  • CA Spectrum:Release:10.1

Components

  • INTEGRATIONS:SPCINT
Issue:

After upgrading to CA Spectrum 10.2.1 and enabling the CA EEM 12.51 integration, unable to login in OneClick web page, keeping asking for username and password.

 

The following error was found in the $SPECROOT/tomcat/logs/sdtout.log file:

Jul 28, 2017 10:14:55.892 - SPC-OCA-10486: Error: CA Spectrum user model not found for user <domain>\<user>.

Example:  SPC-OCA-10486: Error: CA Spectrum user model not found for user ad1.ca.com\user1

 

The following error was found the CA EEM debug log:

[2017-07-28 10:14:55.877] [EEMSSOContext::authenticateWithPassword] EEM password authentication successful. [/spectrum/][<user>] 

[2017-07-28 10:14:55.877] [EEMSSOContext::authenticateWithPassword] [/spectrum/][<user>][UserSession;Version-1.0;dd71c8d592f2115a37d1f7826a619a86-597b1913-cc82b00-4] returned. 

[2017-07-28 10:14:55.877] [ExternalSSOAuth::authenticate] Successfully authenticated user/pass with SSO Server ["GET /spectrum/"]["0:0:0:0:0:0:0:1"]["<user>"][authenticated="true"][authorized="false"] 

[2017-07-28 10:14:55.877] [ExternalSSOAuth::authenticate] usernameFromToken <domain>\<user> 

[2017-07-28 10:14:55.892] [ExternalSSOAuth::authenticate] Could not authorize request for resource. ["GET /spectrum/"]["0:0:0:0:0:0:0:1"]["<domain>\<user>"][authenticated="true"][authorized="false"] 

Environment:
CA Spectrum 10.2.x, 10.1.x and CA EEM 12.51
Cause:

Customer has configured the CA EEM for Multiple Microsoft Active Directory Domains, but he has just one Active Directory.

The CA EEM is appending the domain in the account name, like: ad1.ca.com\user1, instead of only user1.

EEM_Multiple_Microsoft_Active_Directory_Domains.png

Resolution:

 

Configure the CA EEM for Basic LDAP Directory.

 

Delete the setting for Multiple Microsoft Active Directory Domains and configure for Basic LDAP Directory.

EEM_Basic_LDAP_Directory.png

Login will succeed.

Please help us improve!

Will this information enable you to resolve your issue?

Please tell us what we can do better.

{{feedbackText.length ? feedbackText.length : '0'}}/255

{{status}}

Not what you were looking for?

Search Again >

Product Information

Support by Product >

Communities

Join a Community >