You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Mac Sonoma 14.6.1更新后Ruby ovirt-engine-sdk SSO认证失败求助

Mac Sonoma 14.6.1更新后Ruby ovirt-engine-sdk SSO认证失败

将Mac系统更新至Sonoma 14.6.1后,使用Ruby 3.0.0搭配ovirt-engine-sdk 4.6.0连接oVirt引擎时,触发以下SSO认证错误:

create_access_token': Error during SSO authentication: access_denied: Cannot authenticate user 'user@domain.com': Unable to log in. **Verify your login information or contact the system administrator.. (OvirtSDK4::AuthError)
  ruby-3.0.0/gems/ovirt-engine-sdk-4.6.0/lib/ovirtsdk4/connection.rb:476:in `create_access_token': Error during SSO authentication: access_denied: Cannot authenticate user 'user@domain.com': Unable to log in. **Verify your login information or contact the system administrator.. (OvirtSDK4::AuthError)**
    from /Users/077503/.rvm/gems/ruby-3.0.0/gems/ovirt-engine-sdk-4.6.0/lib/ovirtsdk4/connection.rb:646:in `internal_send'
    from /Users/77503/.rvm/gems/ruby-3.0.0/gems/ovirt-engine-sdk-4.6.0/lib/ovirtsdk4/connection.rb:202:in `block in send'
    from /Users/77503/.rvm/gems/ruby-3.0.0/gems/ovirt-engine-sdk-4.6.0/lib/ovirtsdk4/connection.rb:202:in `synchronize'
    from /Users/77503/.rvm/gems/ruby-3.0.0/gems/ovirt-engine-sdk-4.6.0/lib/ovirtsdk4/connection.rb:202:in `send'
    from /Users/77503/.rvm/gems/ruby-3.0.0/gems/ovirt-engine-sdk-4.6.0/lib/ovirtsdk4/service.rb:194:in `internal_get'
    from /Users/77503/.rvm/gems/ruby-3.0.0/gems/ovirt-engine-sdk-4.6.0/lib/ovirtsdk4/services.rb:36365:in `list'

连接代码示例:

connection = OvirtSDK4::Connection.new(
  url:      'https://xxx.example.com/ovirt-engine/api',
  username: 'xxx@domain.com',
  password: 'xxx',
  debug:    true,
  insecure: true)

解决方法

  • 升级SDK版本:执行gem update ovirt-engine-sdk,新版本通常会适配系统更新后的依赖环境
  • 修复Ruby的OpenSSL绑定:Sonoma更新可能改变系统OpenSSL版本,重新编译Ruby指定兼容库:
    rvm reinstall 3.0.0 --with-openssl-dir=$(brew --prefix openssl@3)
    
  • 指定TLS协议版本:在连接参数中添加ssl_cipher_suite,强制使用oVirt支持的TLS版本:
    connection = OvirtSDK4::Connection.new(
      url:            'https://xxx.example.com/ovirt-engine/api',
      username:       'xxx@domain.com',
      password:       'xxx',
      debug:          true,
      insecure:       true,
      ssl_cipher_suite: 'TLSv1.2:TLSv1.3'
    )
    
  • 检查oVirt侧配置:确认oVirt引擎的SSO服务允许密码认证,且用户权限未被变更

内容的提问来源于stack exchange,提问作者Siddu hadapad

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.18 10:05:12