Skip to main content

Temporarily disable and reenable single sign-on for one Admin Node

Contributors netapp-perveilerk netapp-madkat netapp-lhalbert

You might not be able to sign in to the Grid Manager if the single sign-on (SSO) system goes down. In this case, you can temporarily disable and reenable SSO for one Admin Node. To disable and then reenable SSO, you must access the node's command shell.

Before you begin
  • You have specific access permissions.

  • You have the Passwords.txt file.

  • You know the password for the local root user.

About this task

After you disable SSO for one Admin Node, you can sign in to the Grid Manager as the local root user. To secure your StorageGRID system, you must use the node's command shell to reenable SSO on the Admin Node as soon as you sign out.

Tip Disabling SSO for one Admin Node does not affect the SSO settings for any other Admin Nodes in the grid. The Enable SSO checkbox on the Single Sign-on page in the Grid Manager remains selected, and all existing SSO settings are maintained unless you update them.
Steps
  1. Log in to an Admin Node:

    1. Enter the following command: ssh admin@Admin_Node_IP

    2. Enter the password listed in the Passwords.txt file.

    3. Enter the following command to switch to root: su -

    4. Enter the password listed in the Passwords.txt file.

      When you are logged in as root, the prompt changes from $ to #.

  2. Run the following command:disable-saml

    A message indicates that the command applies to this Admin Node only.

  3. Confirm that you want to disable SSO.

    A message indicates that single sign-on is disabled on the node.

  4. From a web browser, access the Grid Manager on the same Admin Node.

    The Grid Manager sign-in page is now displayed because SSO has been disabled.

  5. Sign in with the username root and the local root user's password.

  6. If you disabled SSO temporarily because you needed to correct the SSO configuration:

    1. Select CONFIGURATION > Access control > Single sign-on.

    2. Change the incorrect or out-of-date SSO settings.

    3. Select Save.

      Selecting Save from the Single Sign-on page automatically reenables SSO for the entire grid.

  7. If you disabled SSO temporarily because you needed to access the Grid Manager for some other reason:

    1. Perform whatever task or tasks you need to perform.

    2. Select Sign out, and close the Grid Manager.

    3. Reenable SSO on the Admin Node. You can perform either of the following steps:

      • Run the following command: enable-saml

        A message indicates that the command applies to this Admin Node only.

        Confirm that you want to enable SSO.

        A message indicates that single sign-on is enabled on the node.

      • Reboot the grid node: reboot

  8. From a web browser, access the Grid Manager from the same Admin Node.

  9. Confirm that the StorageGRID Sign in page appears and that you must enter your SSO credentials to access the Grid Manager.