ONTAPツール: 問題のある SAML 要求によりストレージ システムの追加タスクが失敗する
環境
- VMware vSphere 9.x向けONTAPツール
問題
ONTAPで SAML 認証が有効になっています。 例:
cluster::> security saml-sp show
Cluster Uuid 1234565-abcd-1234-4321-123456abc
Identity Provider (IdP) Metadata Location https://sso-1234.sso.domain.com/saml2/sp/abcdefg/metadata
SAML Service Provider Host 192.168.0.101
Server Certificate Issuing CA cluster
Server Certificate Serial Number 12345ABC
SAML Service Provider Enabled true
ストレージ システムを追加すると、SAML リクエスト中に次の「予期しないタグが見つかりました」という例外が表示されます。
[2025-06-12T15:29:05,157Z] [qtp1537371824-12441] [DEBUG] Creating new controller instance, ip: 192.168.0.50
[2025-06-12T15:29:05,157Z] [qtp1537371824-12441] [ INFO] Invoking zapiInvoker.invokeFilerBasedZapi() to get result for : <system-get-version/>
[2025-06-12T15:29:05,345Z] [qtp1537371824-12441] [ INFO] Establishing connection with username and password for cluster: 192.168.0.50
[2025-06-12T15:29:05,390Z] [qtp1537371824-12441] [ INFO] received raw response.
[2025-06-12T15:29:05,392Z] [qtp1537371824-12441] [ INFO] Connected to clustered Data ONTAP at: OntapConnectionImpl{ipAddress=192.168.0.50, userName=otvadmin, port=443, ssl=true}
[2025-06-12T15:29:05,392Z] [qtp1537371824-12441] [ INFO] Version is: 9.13.1
[2025-06-12T15:29:05,392Z] [qtp1537371824-12441] [ INFO] Invoking zapiInvoker.invokeFilerBasedZapi() to get result for : <vserver-get-iter><query><vserver-info><vserver-type>admin,data,cluster</vserver-type></vserver-info></query><desired-attributes><vserver-info><vserver-type/><vserver-name/><uuid/><vserver-aggr-info-list><vserver-aggr-info/></vserver-aggr-info-list><vserver-subtype/></vserver-info></desired-attributes><max-records>1000</max-records></vserver-get-iter>
[2025-06-12T15:29:05,393Z] [qtp1537371824-12441] [DEBUG] Establishing connection with socket factory: for cluster: 192.168.0.50
[2025-06-12T15:29:10,708Z] [qtp1537371824-12441] [DEBUG] retryIfApplicable: message=com.netapp.offtap3.ontap.NaProtocolException: Unexpected tag found: <!DOCTYPE html>
<html>
<head>
<meta charset="utf-8" />
<title
id="redirect-parent"
data-redirect-url="/samlabcd;SAMLRequest1234"
data-redirect-method="get"
>
Redirecting...