VMware Solutions Discussions
VMware Solutions Discussions
Hi, this is a new installation of ONTAP tools for VMware vSphere 10.5.
When we click on the OTV plugin within vCenter, buttons are all greyed out - hovering over displays "Insufficient privilege"
Per the following NetApp KB, we've verified that both forward and reverse DNS is functioning normally: https://kb.netapp.com/data-mgmt/OTV/VSC_Kbs/Insufficient_privilege_in_OTV_10_x_options
We've also already added the OTV service account as a member to the global AD Security group: "vSphere8 vCenter Admins" and assigned that same AD Security Group to the vCenter "Administrator" role and it doesn't work.
We also attempted an OTV installation using the vsphere.local admin account and that too also didn't work.
We've attempted the installation and setup on 2 separate/different lab (test/dev/non-prod) environment vCenter's and seeing the same behavior across them both.
Any ideas?
Also raised the following Discord thread: https://discord.com/channels/855068651522490400/1445184071356518421
I have heard of that happening before, but I'm not sure what the final resolution was. I'll ask around and see if I can find out.
@ChanceBingen - sounds good, ty!
One of the causes seems to be that ONTAP tools will extract all of the possible hostnames from the common name and list of all Subject Alternative Names (SANs) in vCenter's x509Certificate.
Can you check this and see if anything looks weird?
Yes, all the entries are correct. Seeing all vCenters currently listed, including the two we are actively testing against.
Ok, good to know. One last question, does the certificate have an IP SAN? And if so, can you do a "ping -a" on it to see if it reverse resolves?
If that doesn't yield any results, we might need you to open a support case so that we can look at the error message in the logs.
No, the certificate only has DNS names currently listed in the SAN, no IPs. vCenter currently has both forward + reverse DNS entries. Am able to successfully ping both IP + DNS. Also, nslookups from diag shell also succeed for both forward and reverse lookups per the following KB:
https://kb.netapp.com/data-mgmt/OTV/VSC_Kbs/Insufficient_privilege_in_OTV_10_x_options
Out of curiosity, when you added the vCenter in the ONTAP tools manager UI, did you specify it by IP address or FQDN?
The reason I ask is that if you add vCenter by IP address, then it expects an IP SAN in the certificate.
FQDN. BTW - raised a NetApp Support case
Sounds good. We'll need to see what the specific error is in the log bundle, which I don't want to ask you to post here.