LDAP unable to login to our NetOps Portal console, Receiving 'unable to authenticate user' error
search cancel

LDAP unable to login to our NetOps Portal console, Receiving 'unable to authenticate user' error

book

Article ID: 145862

calendar_today

Updated On:

Products

CA Performance Management - Usage and Administration DX NetOps

Issue/Introduction

When an LDAP user tries to login to the NetOps Portal console, they get an error:

'unable to authenticate user'

This was working fine a few days ago.

Tried to test the LDAP user in SsoConfig, and we fail:

Could not obtain a DirectoryContext.

javax.naming.AuthenticationException: [LDAP: error code 49 - 8009030C: LdapErr: DSID-0C09056D, comment: AcceptSecurityContext error, data 52e, v2580]

Logon failure: unknown user name or bad password.

Bind to the directory failed.

Environment

Release : All PM releases

Component : IM Reporting / Admin / Configuration

Cause

In SsoConfig there are 2 types of settings:

  1. Remote Value

These settings are propagated to all other CA products and data sources that are registered to this instance of NetOps Portal. This includes the Event Manager in NetOps Portal, which embeds the URL of NetOps Portal. NetOps Portal uses Remote Value settings only if a corresponding Local Override value is not present.

  1. Local Override

Overrides a setting on this NetOps Portal instance, which does not propagate to other CA products and data sources (including Event Manager) registered to this instance of NetOps Portal. Local Override takes precedence over both the Remote Value and default settings.

 

For LDAP use ‘Remote Value’ so that the values are passed to the LDAP server.

‘Local Override’ should be all blank.
Here we see that someone had edited the Local Override values:




Resolution

In this case, we see that the user bind setting had been accidentally set to enabled.




Use SsoConfig to reset the Local Override.



and now the settings will use the Remote Value as desired:

 

Additional Information