Forum Discussion
Citrix iApp and Active Directory
According to AD policy, the user is required to change their password every so many days. When logging in to Citrix via the APM logon page, the user receives the message:
"The domain password has expired. Please change the password". The user enters their new password meeting the AD complexity requirements, clicks logon and is presented with:
"The domain password change operation failed. Please try again".
Looking into the sessions logs on the APM, the log message says: "AD module: change password for "username" failed: (1588592656).
Any ideas?
Also, on the iApp for the Citrix APM section when it asks:
"What is the name or IP address of an Active Directory server in your domain this BIG-IP system can contact?"
It seems to only give the option for 1 IP address for a DC. Can I add more? Is it possible to do it in the system somewhere rather than in the iApp?
Thanks.
2 Replies
- Greg_Crosby_319Historic F5 Account
Might be you are using an older version of the Citrix iApp, the latest Citrix iApp (citrix_vdi.v.2.1.0) has the option to enter multiple ad servers.
Password changes require a user account with administrative privileges to be present in the APM AAA profile. Verify "Yes...." was selected for question "Does your Active Directory domain require credentials?" if using the iApp to configure your AAA AD profile. If you manually built the AAA profile, verify an admin account and proper password has been entered.
To help troubleshoot, you can enable "Complexity check for Password Reset" and "Show Extended Error" within your access policy ad auth policy item. Doing so will display a more decipherable error message during logon and could help pin point where the failure resides.
- tolinrome_13817
Nimbostratus
Hi Greg, Thanks for your response, I appreciate it. Also, thanks for the update for the new iApp, I think the one I'm using is from 2012.
I am using the iApp and I dont see the question in the Iapp you posted, ""Does your Active Directory domain require credentials?". But I do have a user account listed and I'm not sure what they mean by it must have "administrative permissions", perhaps domain admin group?
I did enable "Complexity check for Password Reset" and "Show Extended Error" and thats how I was able to see the session ID and see that error I posted ""AD module: change password for "username" failed: (1588592656)."
Note however, that users can login no problem, its just when AD forces them to change their passwords they cant.
Maybe I'll update the iApp and see what happens.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com