09-25-2012 04:24 AM
Having upgraded our Panorama from 4.1.7 to 4.1.8 - we can no longer use the LDAP user authentication.
The user constantly gets "invalid username or password" (same message on the Panorama) - yet this worked without any problems with 4.1.7
On Panorama - one can see that in the LDAP profile - the Base option is never getting populated (dropdown option is only "none" rather than domain name).
Is this a new "feature" ?
Br
JørgeDA
11-06-2012 02:03 PM
What is the command line to restart User-ID ?
11-06-2012 02:07 PM
check pid first
admin@oliver(active)> show system resources | match userid
2312 20 0 170m 57m 37m S 0 2.3 3:38.91 useridd
admin@oliver(active)> debug software restart user-id
check pid once more after restart to confirm pid change.
11-07-2012 01:44 PM
We have investigated the changes in version 4.1.8. and can share our findings:
a) Administrator login now REQUIRES the domain field to be EMPTY
b) User identification generally REQUIRES the domain field to be SET
Until version 4.1.6. wit domain field set everything worked as expected, with 4.1.8. you need to create LDAP/Kerberos settings twice, one entry WITH and one W/O domain name. In addition Authentication sequence must be configured twice as well. Then for Admin accounts you select the Auth Profile with empty domains and for User identification (and possibly other purposes) you select the groups with domain fields set. Not nice but it works.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!