<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: LDAP authentication for CLI in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-authentication-for-cli/m-p/477728#M103699</link>
    <description>&lt;P&gt;Any update onnthis issue as i am also facing the same issue&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sat, 02 Apr 2022 18:27:49 GMT</pubDate>
    <dc:creator>mnmeetz.singh</dc:creator>
    <dc:date>2022-04-02T18:27:49Z</dc:date>
    <item>
      <title>LDAP authentication for CLI</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-authentication-for-cli/m-p/35530#M26091</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I got LDAP authentication working so that when logging into the Web GUI the microsoft active directory accounts works with no problems.&amp;nbsp; When a user logs into the CLI and tries using their LDAP account the system log shows invalid username/password.&amp;nbsp; the username syntax is &amp;lt;title&amp;gt;.&amp;lt;firstname&amp;gt;.&amp;lt;lastname&amp;gt;.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Sep 2012 15:58:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-authentication-for-cli/m-p/35530#M26091</guid>
      <dc:creator>snormoyle</dc:creator>
      <dc:date>2012-09-25T15:58:03Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP authentication for CLI</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-authentication-for-cli/m-p/35531#M26092</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please correct me if I am misunderstanding your issue. A user is able to login through the Web GUI not through the CLI with same login credentials?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Sep 2012 16:26:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-authentication-for-cli/m-p/35531#M26092</guid>
      <dc:creator>kadak</dc:creator>
      <dc:date>2012-09-25T16:26:52Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP authentication for CLI</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-authentication-for-cli/m-p/35532#M26093</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;that is correct.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Sep 2012 16:59:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-authentication-for-cli/m-p/35532#M26093</guid>
      <dc:creator>snormoyle</dc:creator>
      <dc:date>2012-09-25T16:59:45Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP authentication for CLI</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-authentication-for-cli/m-p/35533#M26094</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you please try the following -&lt;/P&gt;&lt;P&gt;1)Login into the cli using a local account and run this command "tail follow yes mp-log authd.log"&lt;/P&gt;&lt;P&gt;2)Now open web-ui session and try to login using the LDAP credentials and observe the login process ( especially the user credentials and their format ) in the cli log.&lt;/P&gt;&lt;P&gt;3)Now open another cli session and try to login using LDAP credentials and see how the logs are different when compared to the login using web-ui, You can also find the reason here for the authentication failure in the logs&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Sep 2012 19:14:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-authentication-for-cli/m-p/35533#M26094</guid>
      <dc:creator>sdurga</dc:creator>
      <dc:date>2012-09-25T19:14:10Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP authentication for CLI</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-authentication-for-cli/m-p/35534#M26095</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I did it and you can see where it has issues, just don't understand it yet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;dmin@ssca-pa-01&amp;gt; tail follow yes mp-log authd.log&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;****OUTPUT FROM CLI AUTHENTICATION***********************&lt;/P&gt;&lt;P&gt;Sep 26 06:17:11 pan_authd_service_req(pan_authd.c:2604): Authd:Trying to remote authenticate user: alt.steven.normoyle&lt;/P&gt;&lt;P&gt;Sep 26 06:17:11 pan_authd_service_auth_req(pan_authd.c:1115): AUTH Request &amp;lt;'','','alt.steven.normoyle'&amp;gt;&lt;/P&gt;&lt;P&gt;Sep 26 06:17:11 alt.steven.normoyle admin is being authed&lt;/P&gt;&lt;P&gt;Sep 26 06:17:11 pan_authd_handle_admin_auths(pan_authd.c:1968): Using auth prof mgt-auth for admin alt.steven.normoyle&lt;/P&gt;&lt;P&gt;Sep 26 06:17:11 pan_authd_handle_admin_auths(pan_authd.c:2022): shared/mgt-auth is auth prof is of type (auth profile)&lt;/P&gt;&lt;P&gt;Sep 26 06:17:11 Error: pan_authd_get_sysd_multivsys(pan_authd.c:3527): failed to fetch: NO_MATCHES&lt;/P&gt;&lt;P&gt;Sep 26 06:17:11 pan_authd_common_authenticate(pan_authd.c:1511): Authenticating user using service /etc/pam.d/pan_ldap_shared_mgt-auth_0,username alt.steven.normoyle&lt;/P&gt;&lt;P&gt;Sep 26 06:17:11 pan_authd_authenticate_service(pan_authd.c:663): authentication failed (6)&lt;/P&gt;&lt;P&gt;Sep 26 06:17:11 pan_authd_common_authenticate(pan_authd.c:1531): Authenticating user using service /etc/pam.d/pan_ldap_shared_mgt-auth_0,username alt.steven.normoyle failed - trying other hosts&lt;/P&gt;&lt;P&gt;Sep 26 06:17:11 pan_authd_common_authenticate(pan_authd.c:1511): Authenticating user using service /etc/pam.d/pan_ldap_shared_mgt-auth_1,username alt.steven.normoyle&lt;/P&gt;&lt;P&gt;Sep 26 06:17:11 pan_authd_authenticate_service(pan_authd.c:663): authentication failed (6)&lt;/P&gt;&lt;P&gt;Sep 26 06:17:11 pan_authd_common_authenticate(pan_authd.c:1531): Authenticating user using service /etc/pam.d/pan_ldap_shared_mgt-auth_1,username alt.steven.normoyle failed - trying other hosts&lt;/P&gt;&lt;P&gt;Sep 26 06:17:11 pan_authd_common_authenticate(pan_authd.c:1506): Skipping LDAP server due to missing Auth-Profile: pan_ldap_shared_mgt-auth_2&lt;/P&gt;&lt;P&gt;Sep 26 06:17:11 pan_authd_common_authenticate(pan_authd.c:1506): Skipping LDAP server due to missing Auth-Profile: pan_ldap_shared_mgt-auth_3&lt;/P&gt;&lt;P&gt;Sep 26 06:17:11 authentication failed for user &amp;lt;shared,mgt-auth,alt.steven.normoyle&amp;gt;&lt;/P&gt;&lt;P&gt;Sep 26 06:17:11 pan_authd_process_authresult(pan_authd.c:1258): pan_authd_process_authresult: alt.steven.normoyle authresult not auth'ed&lt;/P&gt;&lt;P&gt;Sep 26 06:17:11 pan_authd_process_authresult(pan_authd.c:1282): Alarm generation set to: False.&lt;/P&gt;&lt;P&gt;Sep 26 06:17:11 User 'alt.steven.normoyle' failed authentication.&amp;nbsp; Reason: Invalid username/password From: ssca-lt-04.nmed.ds.med.navy.mil.&lt;/P&gt;&lt;P&gt;Sep 26 06:17:11 pan_get_system_cmd_output(pan_cfg_utils.c:3056): executing: /usr/local/bin/sdb -n -r cfg.operational-mode&lt;/P&gt;&lt;P&gt;Sep 26 06:17:12 pan_authd_generate_system_log(pan_authd.c:844): CC Enabled=False&lt;/P&gt;&lt;P&gt;Sep 26 06:17:12 pan_get_system_cmd_output(pan_cfg_utils.c:3056): executing: /usr/local/bin/sdb -n -r cfg.operational-mode&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;*************OUTPUT FROM WEB GUI AUTHENTICATION**************************************&lt;/P&gt;&lt;P&gt;Sep 26 06:17:55 pan_authd_service_req(pan_authd.c:2604): Authd:Trying to remote authenticate user: alt.steven.normoyle&lt;/P&gt;&lt;P&gt;Sep 26 06:17:55 pan_authd_service_auth_req(pan_authd.c:1115): AUTH Request &amp;lt;'','','alt.steven.normoyle'&amp;gt;&lt;/P&gt;&lt;P&gt;Sep 26 06:17:55 alt.steven.normoyle admin is being authed&lt;/P&gt;&lt;P&gt;Sep 26 06:17:55 pan_authd_handle_admin_auths(pan_authd.c:1968): Using auth prof mgt-auth for admin alt.steven.normoyle&lt;/P&gt;&lt;P&gt;Sep 26 06:17:55 pan_authd_handle_admin_auths(pan_authd.c:2022): shared/mgt-auth is auth prof is of type (auth profile)&lt;/P&gt;&lt;P&gt;Sep 26 06:17:55 Error: pan_authd_get_sysd_multivsys(pan_authd.c:3527): failed to fetch: NO_MATCHES&lt;/P&gt;&lt;P&gt;Sep 26 06:17:55 pan_authd_common_authenticate(pan_authd.c:1511): Authenticating user using service /etc/pam.d/pan_ldap_shared_mgt-auth_0,username alt.steven.normoyle&lt;/P&gt;&lt;P&gt;Sep 26 06:17:55 pan_authd_authenticate_service(pan_authd.c:663): authentication succeeded (0)&lt;/P&gt;&lt;P&gt;Sep 26 06:17:55 pan_authd_authenticate_service(pan_authd.c:669): account is valid&lt;/P&gt;&lt;P&gt;Sep 26 06:17:55 pan_get_passwd_expiry(pan_authd_passwd.c:778): Using /etc/openldap/pan_ldap_shared_mgt-auth_0 to get password info&lt;/P&gt;&lt;P&gt;Sep 26 06:17:55 pan_get_ldap_ip(pan_authd_passwd.c:120): Reading file /etc/openldap/pan_ldap_shared_mgt-auth_0&lt;/P&gt;&lt;P&gt;Sep 26 06:17:55 pan_authd_bind(pan_authd_passwd.c:244): binding with binddn CN=SSCA.PA.SVC,OU=Service&lt;/P&gt;&lt;P&gt;Sep 26 06:17:55 Error: pan_authd_bind(pan_authd_passwd.c:271): bind failed (extracted from parsed bind result) (Invalid credentials) (80090308: LdapErr: DSID-0C0903A9, comment: AcceptSecurityContext error, data 52e, v1db1)&lt;/P&gt;&lt;P&gt;Sep 26 06:17:55 pan_authd_ldap_search_result(pan_authd_passwd.c:357): searching base 'DC=nmed,DC=ds,DC=med,DC=navy,DC=mil' for (sAMAccountName=alt.steven.normoyle) (userAccountControl)&lt;/P&gt;&lt;P&gt;Sep 26 06:17:55 Error: pan_authd_ldap_search_result(pan_authd_passwd.c:419): search failed 1 (Operations error) (000004DC: LdapErr: DSID-0C0906E8, comment: In order to perform this operation a successful bind must be completed on the connection., data 0, v1db1)&lt;/P&gt;&lt;P&gt;Sep 26 06:17:55 pan_get_ad_passwd_expiry(pan_authd_passwd.c:679): failed to search userAccountControl&lt;/P&gt;&lt;P&gt;Sep 26 06:17:55 Error: pan_get_passwd_expiry(pan_authd_passwd.c:793): Failed to get expiry info for alt.steven.normoyle&lt;/P&gt;&lt;P&gt;Sep 26 06:17:55 authentication succeeded for user &amp;lt;shared,mgt-auth,alt.steven.normoyle&amp;gt;&lt;/P&gt;&lt;P&gt;useradd: unable to lock password file&lt;/P&gt;&lt;P&gt;usermod: user alt.steven.normoyle does not exist&lt;/P&gt;&lt;P&gt;usermod: user alt.steven.normoyle does not exist&lt;/P&gt;&lt;P&gt;Sep 26 06:17:56 pan_authd_process_authresult(pan_authd.c:1258): pan_authd_process_authresult: alt.steven.normoyle authresult auth'ed&lt;/P&gt;&lt;P&gt;Sep 26 06:17:56 Request received to unlock shared/mgt-auth/alt.steven.normoyle&lt;/P&gt;&lt;P&gt;Sep 26 06:17:56 User 'alt.steven.normoyle' authenticated.&amp;nbsp;&amp;nbsp; From: 192.207.231.8.&lt;/P&gt;&lt;P&gt;Sep 26 06:17:56 pan_get_system_cmd_output(pan_cfg_utils.c:3056): executing: /usr/local/bin/sdb -n -r cfg.operational-mode&lt;/P&gt;&lt;P&gt;Sep 26 06:17:56 pan_authd_generate_system_log(pan_authd.c:844): CC Enabled=False&lt;/P&gt;&lt;P&gt;Sep 26 06:17:56 pan_get_system_cmd_output(pan_cfg_utils.c:3056): executing: /usr/local/bin/sdb -n -r cfg.operational-mode&lt;/P&gt;&lt;P&gt;Sep 26 06:17:56 pan_authd_service_req(pan_authd.c:2610): Authd:get group request&lt;/P&gt;&lt;P&gt;Sep 26 06:17:56 pan_authd_handle_group_req(pan_authd.c:2561): Got user role/adomain / for user alt.steven.normoyle&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 26 Sep 2012 10:43:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-authentication-for-cli/m-p/35534#M26095</guid>
      <dc:creator>snormoyle</dc:creator>
      <dc:date>2012-09-26T10:43:50Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP authentication for CLI</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-authentication-for-cli/m-p/35535#M26096</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That is weird, In both cases PA sent the same format to the LDAP server. Which software version is this ? Did you do any software upgrades and that caused this issue ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 26 Sep 2012 20:25:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-authentication-for-cli/m-p/35535#M26096</guid>
      <dc:creator>sdurga</dc:creator>
      <dc:date>2012-09-26T20:25:59Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP authentication for CLI</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-authentication-for-cli/m-p/35536#M26097</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If this issue is happening after upgrade to 4.1.8, please open a ticket with support as this looks buggy.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Sep 2012 16:27:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-authentication-for-cli/m-p/35536#M26097</guid>
      <dc:creator>sdurga</dc:creator>
      <dc:date>2012-09-27T16:27:04Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP authentication for CLI</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-authentication-for-cli/m-p/477728#M103699</link>
      <description>&lt;P&gt;Any update onnthis issue as i am also facing the same issue&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 02 Apr 2022 18:27:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-authentication-for-cli/m-p/477728#M103699</guid>
      <dc:creator>mnmeetz.singh</dc:creator>
      <dc:date>2022-04-02T18:27:49Z</dc:date>
    </item>
  </channel>
</rss>

