<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Problem authenticating SSL VPN with eDirectory Users in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/problem-authenticating-ssl-vpn-with-edirectory-users/m-p/18524#M13528</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What is the authentication error you get?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Run the command: 'tail follow yes mp-log authd.log' and authenticate to the VPN. This output will give you the reason as to why the authentication fails.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 30 Apr 2012 23:29:00 GMT</pubDate>
    <dc:creator>zarina</dc:creator>
    <dc:date>2012-04-30T23:29:00Z</dc:date>
    <item>
      <title>Problem authenticating SSL VPN with eDirectory Users</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-authenticating-ssl-vpn-with-edirectory-users/m-p/18523#M13527</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have set up a SSL VPN on a PA-500 with Pan OS 4.0.7.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem is that I cannot log in with certain eDirectory users. I have checked those users are in the same group as the ones that work; that group is the one allowed to log in.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would appreciate any help on this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Emilio M.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Apr 2012 10:36:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-authenticating-ssl-vpn-with-edirectory-users/m-p/18523#M13527</guid>
      <dc:creator>emaneiro</dc:creator>
      <dc:date>2012-04-30T10:36:35Z</dc:date>
    </item>
    <item>
      <title>Re: Problem authenticating SSL VPN with eDirectory Users</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-authenticating-ssl-vpn-with-edirectory-users/m-p/18524#M13528</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What is the authentication error you get?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Run the command: 'tail follow yes mp-log authd.log' and authenticate to the VPN. This output will give you the reason as to why the authentication fails.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Apr 2012 23:29:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-authenticating-ssl-vpn-with-edirectory-users/m-p/18524#M13528</guid>
      <dc:creator>zarina</dc:creator>
      <dc:date>2012-04-30T23:29:00Z</dc:date>
    </item>
    <item>
      <title>Re: Problem authenticating SSL VPN with eDirectory Users</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-authenticating-ssl-vpn-with-edirectory-users/m-p/18525#M13529</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The output is&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;May 01 14:51:26 pan_authd_service_req(pan_authd.c:2454): Authd:Trying to remote authenticate user: PruebaVPN&lt;BR /&gt;May 01 14:51:26 pan_authd_service_auth_req(pan_authd.c:1098): AUTH Request &amp;lt;'vsys1','VPNSSL-Auth-Sequence','PruebaVPN'&amp;gt;&lt;BR /&gt;May 01 14:51:26 pan_authd_handle_nonadmin_auths(pan_authd.c:2146): VPNSSL-Auth-Sequence is an auth sequence&lt;BR /&gt;May 01 14:51:26 pan_authd_handle_nonadmin_auths(pan_authd.c:2206): Trying auth profile #1 COA-Local in auth seq&lt;BR /&gt;May 01 14:51:26 panauth:user &amp;lt;PruebaVPN,COA-Local,vsys1&amp;gt; is not allowed&lt;BR /&gt;May 01 14:51:26 pan_authd_handle_nonadmin_auths(pan_authd.c:2206): Trying auth profile #2 COA-eDir-VPN-SSL in auth seq&lt;BR /&gt;May 01 14:51:26 pan_authd_common_authenticate(pan_authd.c:1472): Authenticating user using service /etc/pam.d/pan_ldap_vsys1_:c:o:a-e:dir-:v:p:n-:s:s:l,username PruebaVPN&lt;BR /&gt;May 01 14:51:29 pan_authd_authenticate_service(pan_authd.c:648): authentication failed (6)&lt;BR /&gt;May 01 14:51:29 authentication failed for user &amp;lt;vsys1,COA-eDir-VPN-SSL,PruebaVPN&amp;gt;&lt;BR /&gt;May 01 14:51:29 pan_authd_process_authresult(pan_authd.c:1241): pan_authd_process_authresult: PruebaVPN authresult not auth'ed&lt;BR /&gt;May 01 14:51:29 Error: pan_authd_user_auth_failure_alarm_gen(pan_authd_localdb_utils.c:504): failed to prepare sql statement: select * from authseqdb where seqname=? and vsysname=?'&lt;BR /&gt;May 01 14:51:29 pan_authd_process_authresult(pan_authd.c:1264): Alarm generation set to: False.&lt;BR /&gt;May 01 14:51:29 User 'PruebaVPN' failed authentication.&amp;nbsp; Reason: Invalid username/password From: 88.18.211.151.&lt;BR /&gt;May 01 14:51:29 pan_get_system_cmd_output(pan_cfg_utils.c:3033): executing: /usr/local/bin/sdb -n -r cfg.operational-mode&lt;BR /&gt;May 01 14:51:29 pan_authd_generate_system_log(pan_authd.c:827): CC Enabled=False&lt;BR /&gt;May 01 14:51:29 pan_get_system_cmd_output(pan_cfg_utils.c:3033): executing: /usr/local/bin/sdb -n -r cfg.operational-mode&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But I know the password for that user is correct and other users authenticate correctly&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 01 May 2012 12:57:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-authenticating-ssl-vpn-with-edirectory-users/m-p/18525#M13529</guid>
      <dc:creator>emaneiro</dc:creator>
      <dc:date>2012-05-01T12:57:33Z</dc:date>
    </item>
    <item>
      <title>Re: Problem authenticating SSL VPN with eDirectory Users</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-authenticating-ssl-vpn-with-edirectory-users/m-p/18526#M13530</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It was an issue with user's password in Novell eDirectory. I finally debugged this with 'ndstrace' and 'ndslogin' in the eDirectory server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Emilio M&lt;/P&gt;&lt;P&gt;Ingelan&lt;/P&gt;&lt;P&gt;Sevilla, Spain&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 01 May 2012 14:19:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-authenticating-ssl-vpn-with-edirectory-users/m-p/18526#M13530</guid>
      <dc:creator>emaneiro</dc:creator>
      <dc:date>2012-05-01T14:19:03Z</dc:date>
    </item>
    <item>
      <title>Re: Problem authenticating SSL VPN with eDirectory Users</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-authenticating-ssl-vpn-with-edirectory-users/m-p/18527#M13531</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Your log does indicate its an invalid username/pwd:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;May 01 14:51:29 User 'PruebaVPN' failed authentication.&amp;nbsp; Reason: Invalid username/password From: 88.18.211.151.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 01 May 2012 22:19:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-authenticating-ssl-vpn-with-edirectory-users/m-p/18527#M13531</guid>
      <dc:creator>zarina</dc:creator>
      <dc:date>2012-05-01T22:19:38Z</dc:date>
    </item>
    <item>
      <title>Re: Problem authenticating SSL VPN with eDirectory Users</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-authenticating-ssl-vpn-with-edirectory-users/m-p/18528#M13532</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;After debugging the same problem with another user the problem dissapeared when I changed the user name (CN in this case). I changed one uppercase letter to lowercase... ¡and it worked!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I even changed the user name back to the original value and kept working.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't know the reason but changing the user name solves this problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Emilio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 May 2012 14:51:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-authenticating-ssl-vpn-with-edirectory-users/m-p/18528#M13532</guid>
      <dc:creator>emaneiro</dc:creator>
      <dc:date>2012-05-02T14:51:31Z</dc:date>
    </item>
  </channel>
</rss>

