Unsolved

This post is more than 5 years old

15972

November 1st, 2005 18:00

Install of Openmanage gives windows authentication prompts

Having problems w/ Openmanage 4.4 on a 2850.  After installation, when I try to open openmanage i'm first prompted w/ the windows authentication dialog box 3 times, which all seem to fail, then i get the openmanage login screen, which also fails.  (i'm not fat-fingering here either)
 
i've done the following:
fresh install of windows 2003 EE, no dell partition, install of windows was NOT done w/ the dell cd.  after the install i stick in the cd and install openmanage server assistant from there.
i've tried installing all MS patches and sp1 and then installing openmanage - same deal.
 
there's nothing useful in the eventlogs, and i can't find any logs for openmanage.  i've installed openmanage a bunch of times on a bunch of 2850s and other servers...i don't see what the difference is here.
 
 

November 2nd, 2005 20:00

I've taken to using the shotgun approach to problem solving.
 
1. I disable Internet Explorer 6 Extensions on Win 2003 Servers (Control Panel->Add/Remove Programs->Windows Componets-> clear IE extensions). Disclaimer -- this make your system less "safe" from attacks. I sit behind a firewall and do not use my Server for casual internet browsing.
 
2. The instructions say to make sure your web server is installed before you install IT Assistant or ServerAdministrator. Given that, I also check using the IIS MMC plugin that the security for my home server is not too restrictive (anonymous access -- yes, window authentication --yes).
 
3. When I log in locally I use an Administrators account.
 
4. When I log in remotely I check my IE settings to make sure that my server is included in the addresses that exempt from firewall proxy access. (Tools->Internet Options->Connections tab -> LAN settings -> Advanced).
 
I tend to still get a lot of pop-up boxes for certificates. I try to view the certificate and install them into the certificate repository. Sometime it works, sometimes it doesn't.
 
Good hunting.
 
 
 
 

626 Posts

November 7th, 2005 21:00

I'm just curious.  Did you solve the problem?

November 8th, 2005 16:00

Nope.  This didn't do it.  I get the same behaviour w/ the 4.5 cd.  This makes no sense.  Does anyone from Dell ever read these postings?

626 Posts

November 8th, 2005 18:00

When you type in the username and password, you are using your Windows username and password right?  And does your password include characters or is it a blank password?  OMSA doesn't allow a login with a blank password.  Not sure if this applies to you or not but it's worth mentioning.

November 8th, 2005 18:00

using the windows username and passwd.  real passwd, not a blank one. 

November 8th, 2005 19:00

already did.  same deal. 

626 Posts

November 8th, 2005 19:00

Are you using Internet Explorer?  If so, go to Internet Options, Advanced Tab.  Look under Security, make sure that "Enable Integrated Windows Authentication" is checked.

On my system, the following boxes are checked under the Security section in the Advanced tab.

  • Check for publisher's certificate revocation
  • Check for signatures on downloaded programs
  • Enable Integrated Windows Authentication
  • Enable Profile Assistant
  • Use SSL 2.0
  • Use SSL 3.0
  • Warn about invalid site certificates
  • Warn if forms submittal is being redirected

Under HTTP 1.1 Settings, the following box is checked

  • Use HTTP 1.1

 

626 Posts

November 8th, 2005 19:00

This baffles me.  Can you try the newest version of OMSA?  OMSA 4.5 is on the dell support site.  If you still have the problem, then it would be good if I can set my system up the exact same way that yours is setup so that I can try to reproduce it.
 
Here's an OMSA 4.5 ISO for burning a CD image:
 
If you want to download the install directly to your hard drive:
 
 
 

November 8th, 2005 20:00

Are you using IE and does your server name have an underscore it?

I know this seems off-hand, but from painful previous experience I have found that IE will not support a session token on a system whose name has an underscore. It has something to do with potential security vulnerabilities. The results tends to look like the system is just asking you to log in again and again.

A work around is if you can get to that systems console, or Remote Desktop/Terminal Services to that machine, you can try to connect as localhost:1311 or localhost:2607,.....no underscore, no problem.

When we found this out we renamed a bunch of servers. That was a pain gettiing corporate to rework the DNS entries,... but I digress.

2nd work-around. Try same with Mozilla/Firefox.

 

2 Posts

November 9th, 2005 19:00

It's not Microsoft that has a problem with a _ character in the machine name. The DNS specification doesn't support the _ from what I understand. So when you have a _ in a machine name, it doesn't register in DNS correctly, therefore when you open an application such as OMSA that tries to find the machine, it can't.

November 9th, 2005 19:00

the server name does have a "_" in it.  that's gotta be the dumbest thing i've ever heard of.  I'll try renaming the box and see how it goes.  if that's the problem... if microsoft is going to have such problems w/ a _ in the name, then they shouldn't allow the _ as a valid character. 

November 9th, 2005 20:00

I'm glad we seem to have found the cause.
 
The denial of sessions to URLs with underscores is by design on the part of Microsoft to block some script injection by evil people calling with strange URL strings. Google - "IE  316112". Google has the MS knowledge base article cached, although it seems unavalible on microsoft when I went to look for it. They patched something in MS01-055, and built that underscore blocker in IE 6.
 
ergo.... work-arounds like using an IP address or using Firefox.
 
 

November 15th, 2005 13:00

i renamed the server and this works fine now.  thx for the help.
No Events found!

Top