Harvest administrator is able to login to Harvest Workbench and Admin tool using an LDAP account, but other users are not successful. Error message returns "Invalid Credentials". After several attempts, the LDAP account gets locked out, confirming that LDAP rejects the authentication.
CA Harvest Software Change Manager
LDAP / Active Directory
Authentication succeeds for some users but fails for others when LDAP server rules, attribute mismatches, or search filter restrictions prevent specific accounts from being validated. Since the account locks out in LDAP, the Harvest Broker is successfully communicating with the LDAP server, but the server rejects the provided credentials for those specific users.
Follow these steps to identify the discrepancy between working and non-working accounts:
hauthtst utility from the Harvest broker machine to test authentication for a failing user independently of the broker.-ldapbasedn parameter in the HServer.arg file.-ldapattrusrname attribute in HServer.arg (typically sAMAccountName) matches the format users enter during login.