Forum Discussion
AndOs
Cirrostratus
Apr 16, 2013Can't change AD password through APM
Hi!
I'm having some problems with password change for expired AD passwords through APM.
Running on APM+LTM 11.2.1 build 797.
Using "AD Auth" in the access policies to authentica...
AndOs
Cirrostratus
Apr 17, 20131. In your AD AAA, remove the pool and monitor and leave only the domain name and admin user/pass. DNS should be configured so that BIG-IP can resolve this domain name.
Use "Server Connection: Direct" instead of Pool?
I switched the AAA to Direct and entered one of our DCs instead of using a pool and password change started to work!
Packet capture now shows that it's talking UDP to DCs just like the test env.
It's still strange though that test uses a pool and everything works there.
2. Compare the /etc/krb5.conf file between test and prod. Do you see any significant differences?
There's no difference that I can see, except that we have one other domain in test env.
I see in /etc/krb5.com that it defines a few log files, but I can't find them under /var/log.
It it possible to turn on those logs?
[logging]
default = FILE:/var/log/krb5libs.log
kdc = FILE:/var/log/krb5kdc.log
admin_server = FILE:/var/log/kadmind.log
/Andreas
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects