<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Authentication via LDAP server not sending complete DN name in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/authentication-via-ldap-server-not-sending-complete-dn-name/m-p/232639#M66730</link>
    <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have configured LDAP server profile and confirmed the condition of reading group via Group mapping it works.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I try to test the LDAP username through authentication profile it succeed upto LDAP authentication but after it is sending DN name only with domain name and my user get failed to authenticate.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What else I need to check.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;test authentication authentication-profile LDAP user name remesk&amp;#8;&amp;#27;[K&amp;#8;&amp;#27;[K&amp;#8;&amp;#27;[K&amp;#8;&amp;#27;[K&amp;#8;&amp;#27;[K&amp;#8;&amp;#27;[Kremeshk &amp;#27;[K&amp;#27;[A&amp;#27;[Kadmin-remeshk@TH-FW-PA3060&amp;gt; test authentication authentication-profile LDAP user name remeshk password&lt;BR /&gt;Enter password :&lt;BR /&gt;&amp;#27;[?1h&amp;#27;=&amp;#27;[40;1H&amp;#27;[K&lt;BR /&gt;Target vsys is not specified, user "remeshk" is assumed to be configured with a shared auth profile.&lt;/P&gt;&lt;P&gt;Do allow list check before sending out authentication request...&lt;BR /&gt;name "trojanholding.ae\remeshk" is in group "all"&lt;/P&gt;&lt;P&gt;Authentication to LDAP server at 10.3.4.10 for user "remeshk"&lt;BR /&gt;Egress: 172.25.25.4&lt;BR /&gt;Type of authentication: plaintext&lt;BR /&gt;Starting LDAP connection...&lt;BR /&gt;Succeeded to create a session with LDAP server&lt;BR /&gt;DN sent to LDAP server: DC=trojanholding,DC=ae&lt;BR /&gt;Authentication failed against LDAP server at 10.3.4.10:389 for user "remeshk"&lt;/P&gt;&lt;P&gt;Authentication to LDAP server at 10.3.4.11 for user "remeshk"&lt;BR /&gt;Egress: 172.25.25.4&lt;BR /&gt;Type of authentication: plaintext&lt;BR /&gt;Starting LDAP connection...&lt;BR /&gt;Succeeded to create a session with LDAP server&lt;BR /&gt;DN sent to LDAP server: DC=trojanholding,DC=ae&lt;BR /&gt;Authentication failed against LDAP server at 10.3.4.11:389 for user "remeshk"&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Authentication failed for user "remeshk"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 27 Sep 2018 06:17:01 GMT</pubDate>
    <dc:creator>Venkatesan_radhakrishnan</dc:creator>
    <dc:date>2018-09-27T06:17:01Z</dc:date>
    <item>
      <title>Authentication via LDAP server not sending complete DN name</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/authentication-via-ldap-server-not-sending-complete-dn-name/m-p/232639#M66730</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have configured LDAP server profile and confirmed the condition of reading group via Group mapping it works.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I try to test the LDAP username through authentication profile it succeed upto LDAP authentication but after it is sending DN name only with domain name and my user get failed to authenticate.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What else I need to check.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;test authentication authentication-profile LDAP user name remesk&amp;#8;&amp;#27;[K&amp;#8;&amp;#27;[K&amp;#8;&amp;#27;[K&amp;#8;&amp;#27;[K&amp;#8;&amp;#27;[K&amp;#8;&amp;#27;[Kremeshk &amp;#27;[K&amp;#27;[A&amp;#27;[Kadmin-remeshk@TH-FW-PA3060&amp;gt; test authentication authentication-profile LDAP user name remeshk password&lt;BR /&gt;Enter password :&lt;BR /&gt;&amp;#27;[?1h&amp;#27;=&amp;#27;[40;1H&amp;#27;[K&lt;BR /&gt;Target vsys is not specified, user "remeshk" is assumed to be configured with a shared auth profile.&lt;/P&gt;&lt;P&gt;Do allow list check before sending out authentication request...&lt;BR /&gt;name "trojanholding.ae\remeshk" is in group "all"&lt;/P&gt;&lt;P&gt;Authentication to LDAP server at 10.3.4.10 for user "remeshk"&lt;BR /&gt;Egress: 172.25.25.4&lt;BR /&gt;Type of authentication: plaintext&lt;BR /&gt;Starting LDAP connection...&lt;BR /&gt;Succeeded to create a session with LDAP server&lt;BR /&gt;DN sent to LDAP server: DC=trojanholding,DC=ae&lt;BR /&gt;Authentication failed against LDAP server at 10.3.4.10:389 for user "remeshk"&lt;/P&gt;&lt;P&gt;Authentication to LDAP server at 10.3.4.11 for user "remeshk"&lt;BR /&gt;Egress: 172.25.25.4&lt;BR /&gt;Type of authentication: plaintext&lt;BR /&gt;Starting LDAP connection...&lt;BR /&gt;Succeeded to create a session with LDAP server&lt;BR /&gt;DN sent to LDAP server: DC=trojanholding,DC=ae&lt;BR /&gt;Authentication failed against LDAP server at 10.3.4.11:389 for user "remeshk"&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Authentication failed for user "remeshk"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Sep 2018 06:17:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/authentication-via-ldap-server-not-sending-complete-dn-name/m-p/232639#M66730</guid>
      <dc:creator>Venkatesan_radhakrishnan</dc:creator>
      <dc:date>2018-09-27T06:17:01Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication via LDAP server not sending complete DN name</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/authentication-via-ldap-server-not-sending-complete-dn-name/m-p/232664#M66737</link>
      <description>&lt;P&gt;when you test LDAP via the test command it does not use all configured parts of the authentication profile. it does not use any domain modifier that you have set.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Sep 2018 12:19:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/authentication-via-ldap-server-not-sending-complete-dn-name/m-p/232664#M66737</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-09-27T12:19:34Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication via LDAP server not sending complete DN name</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/authentication-via-ldap-server-not-sending-complete-dn-name/m-p/232666#M66739</link>
      <description>&lt;P&gt;No it is not like that way, Here I found actually the username is missing the root structure of the domain in AD.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Sep 2018 12:21:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/authentication-via-ldap-server-not-sending-complete-dn-name/m-p/232666#M66739</guid>
      <dc:creator>Venkatesan_radhakrishnan</dc:creator>
      <dc:date>2018-09-27T12:21:54Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication via LDAP server not sending complete DN name</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/authentication-via-ldap-server-not-sending-complete-dn-name/m-p/232668#M66741</link>
      <description>&lt;P&gt;sorry i am confused, can you show me a test that does work...&lt;/P&gt;</description>
      <pubDate>Thu, 27 Sep 2018 12:25:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/authentication-via-ldap-server-not-sending-complete-dn-name/m-p/232668#M66741</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-09-27T12:25:24Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication via LDAP server not sending complete DN name</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/authentication-via-ldap-server-not-sending-complete-dn-name/m-p/232670#M66742</link>
      <description>&lt;P&gt;admin@PA-VM&amp;gt; test authentication authentication-profile Auth-GP username venkatesan password&lt;BR /&gt;Enter password :&lt;/P&gt;&lt;P&gt;Target vsys is not specified, user "venkatesan" is assumed to be configured with a shared auth profile.&lt;/P&gt;&lt;P&gt;Do allow list check before sending out authentication request...&lt;BR /&gt;name "venkatesan" is in group "all"&lt;/P&gt;&lt;P&gt;Authentication to LDAP server at 172.16.3.142 for user "venkatesan"&lt;BR /&gt;Egress: 192.168.30.1&lt;BR /&gt;Type of authentication: plaintext&lt;BR /&gt;Starting LDAP connection...&lt;BR /&gt;Succeeded to create a session with LDAP server&lt;BR /&gt;DN sent to LDAP server: CN=venkatesan r.,CN=Users,DC=abdalla,DC=local&lt;BR /&gt;User expires in days: never&lt;/P&gt;&lt;P&gt;Authentication succeeded for user "venkatesan"&lt;/P&gt;</description>
      <pubDate>Thu, 27 Sep 2018 12:28:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/authentication-via-ldap-server-not-sending-complete-dn-name/m-p/232670#M66742</guid>
      <dc:creator>Venkatesan_radhakrishnan</dc:creator>
      <dc:date>2018-09-27T12:28:01Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication via LDAP server not sending complete DN name</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/authentication-via-ldap-server-not-sending-complete-dn-name/m-p/232680#M66743</link>
      <description>&lt;P&gt;ok so now show test that doesn't work.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Sep 2018 12:38:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/authentication-via-ldap-server-not-sending-complete-dn-name/m-p/232680#M66743</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-09-27T12:38:46Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication via LDAP server not sending complete DN name</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/authentication-via-ldap-server-not-sending-complete-dn-name/m-p/232681#M66744</link>
      <description>&lt;P&gt;it works&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Sep 2018 12:40:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/authentication-via-ldap-server-not-sending-complete-dn-name/m-p/232681#M66744</guid>
      <dc:creator>Venkatesan_radhakrishnan</dc:creator>
      <dc:date>2018-09-27T12:40:04Z</dc:date>
    </item>
  </channel>
</rss>

