VMware Solutions Discussions

ONTAP tools for VMware vSphere 10.5 setup - vCenter insufficient privileges

prcpa8w3p
1,299 Views

Hi, this is a new installation of ONTAP tools for VMware vSphere 10.5.

 

When we click on the OTV plugin within vCenter, buttons are all greyed out - hovering over displays "Insufficient privilege"

 

Per the following NetApp KB, we've verified that both forward and reverse DNS is functioning normally: https://kb.netapp.com/data-mgmt/OTV/VSC_Kbs/Insufficient_privilege_in_OTV_10_x_options

 

We've also already added the OTV service account as a member to the global AD Security group: "vSphere8 vCenter Admins" and assigned that same AD Security Group to the vCenter "Administrator" role and it doesn't work.

 

We also attempted an OTV installation using the vsphere.local admin account and that too also didn't work.

 

We've attempted the installation and setup on 2 separate/different lab (test/dev/non-prod) environment vCenter's and seeing the same behavior across them both.

 

Any ideas?

10 REPLIES 10

prcpa8w3p
1,272 Views

Also raised the following Discord thread: https://discord.com/channels/855068651522490400/1445184071356518421

ChanceBingen
1,214 Views

I have heard of that happening before, but I'm not sure what the final resolution was. I'll ask around and see if I can find out.

prcpa8w3p
1,208 Views

@ChanceBingen - sounds good, ty!

ChanceBingen
1,192 Views

One of the causes seems to be that ONTAP tools will extract all of the possible hostnames from the common name and list of all Subject Alternative Names (SANs) in vCenter's x509Certificate.

 

Can you check this and see if anything looks weird?

  • From the ONTAP tools diag shell, fetch the vCenter certificate:
    $ echo | openssl s_client -connect vcenter:443 -showcerts | openssl x509 -text
  • Check the vCenter certificates' Subject Alternative Name extension.  Are all of the entries correct?

prcpa8w3p
1,146 Views

Yes, all the entries are correct. Seeing all vCenters currently listed, including the two we are actively testing against.

ChanceBingen
1,103 Views

Ok, good to know. One last question, does the certificate have an IP SAN? And if so, can you do a "ping -a" on it to see if it reverse resolves?

 

If that doesn't yield any results, we might need you to open a support case so that we can look at the error message in the logs.

prcpa8w3p
1,102 Views

No, the certificate only has DNS names currently listed in the SAN, no IPs. vCenter currently has both forward + reverse DNS entries. Am able to successfully ping both IP + DNS. Also, nslookups from diag shell also succeed for both forward and reverse lookups per the following KB:

https://kb.netapp.com/data-mgmt/OTV/VSC_Kbs/Insufficient_privilege_in_OTV_10_x_options

ChanceBingen
1,099 Views

Out of curiosity, when you added the vCenter in the ONTAP tools manager UI, did you specify it by IP address or FQDN?

The reason I ask is that if you add vCenter by IP address, then it expects an IP SAN in the certificate.

prcpa8w3p
1,098 Views

FQDN. BTW - raised a NetApp Support case

ChanceBingen
1,096 Views

Sounds good. We'll need to see what the specific error is in the log bundle, which I don't want to ask you to post here.

Public