Forum Discussion

Jason_Jernigan1's avatar
Jason_Jernigan1
Icon for Nimbostratus rankNimbostratus
Jan 24, 2007

Ldap Authentication and expired Passwords

We are using bigip LDAP authentication. Most things seem to be working as expected. However when we have a user with an expired password the bigip allows the authentication through even though the LDAP server is logging error=49 and the LTM log shows.

 

Jan 24 11:23:59 ROBONAUT tamd: 010b0232:4: pam_authenticate: 6

 

Jan 24 11:23:59 ROBONAUT tamd: 010b0235:4: AUTH: Permission denied

 

 

I have added additional logging to my irule and it appear that Auth_Success event is firing when this happens. Is this a bug we have found? This occurs using the default Irule that comes with the bigip and our own irule. We are running version 9.1.1. I have not opened a case with tech support yet. Any help would be greatly appreciated.

 

Thanks,

 

Jason
  • Colin_Walker_12's avatar
    Colin_Walker_12
    Historic F5 Account
    Could you post up a copy of the rule you're using when receiving this error? It sounds strange that the BIG-IP would log that permission was denied AND trigger the success event...

     

     

    Thanks,

     

    Colin