Password change via GlobalProtect occasionally fails
9134
Created On 03/27/24 00:02 AM - Last Modified 08/27/24 22:31 PM
Symptom
- GlobalProtect configured with Radius Authentication and "Allow users to change password after expiry" is enabled (Device > Server Profiles > RADIUS > [profile-name])
- When the password is expired, GlobalProtect App display the password expiry message to change the password.
- When the password change is attempted it fails with the message “Authentication Failed. Enter login credentials”.
- Note: The correct password is entered when attempting the change.
Environment
- GlobalProtect (GP) App
- supported GP App versions
- Radius authentication configured on Portal
- LDAP authentication configured on Gateway
Cause
- This issue is caused by the timeout of the GlobalProtect Agent(GPA).
- PanGPA.log reports timeout messages.
WINHTTP_CALLBACK_STATUS_REQUEST_ERROR, error=0x2ee2, result=1, dwCertificateError=0 get WINHTTP_CALLBACK_STATUS_REQUEST_ERROR while waitting for header, error=12002, 00600070, ERROR_WINHTTP_TIMEOUT!
Resolution
- Change the TCP handshake timeout from default (10 sec) to 60 sec.
- This can be changed using GUI: Device > Setup > Session > Session Timeouts
- Click "OK" and Commit the changes.