IBM Support

LDAP users unable to login to Guardium but built-in users are able to login

Troubleshooting


Problem

LDAP users are unable to login to the IBM® Security Guardium® GUI

Symptom

None of the LDAP users are able to login to the gui of the appliance.
The built-in users "admin", "accessmgr" are successfully able to authenticate and login to gui.

Cause

LDAP account locked out.

Environment

  1. Managed Environment : All the appliances involved in the given Central Manager (CM) hierarchy, including the CM will encounter the login issue for LDAP users
  2. Standalone Appliance : Only the standalone appliance will have the login issue for the LDAP users

Diagnosing The Problem

Diagnosis of the problem can be done using debugging the login attempt.
  1. Use one of the application debug methods that are available (must_gather OR manual method).
  2. Attempt the ldap user login on the gui
  3. check the debug-logs.
  4. Verify and check for the presence of below message trace in the debug logs.

==============day mon date hh:mm:ss ZONE YYYY===================

Thread: http-bio-8443-exec-575 - javax.naming.AuthenticationException: [LDAP: error code 49 - 80090308: LdapErr: DSID-0C09042F, comment: AcceptSecurityContext error, data 532, v2580^@]
at com.sun.jndi.ldap.LdapCtx.mapErrorCode(LdapCtx.java:3166)
at com.sun.jndi.ldap.LdapCtx.processReturnCode(LdapCtx.java:3112)
at com.sun.jndi.ldap.LdapCtx.processReturnCode(LdapCtx.java:2898)

Resolving The Problem

The error code presented in the trace message corresponds to the LDAP account being locked out.
Once the LDAP account is unlocked, with the correct password, the login should work.

Document Location

Worldwide

[{"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSMPHH","label":"IBM Security Guardium"},"ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"All Version(s)","Line of Business":{"code":"LOB24","label":"Security Software"}}]

Document Information

Modified date:
27 May 2020

UID

ibm16215317