Does LDAP support the Username Modifier "%USERDOMAIN%\%USERINPUT%" when the User Domain is configured along with Login Attribute "sAMAccountName" in the authentication profile

Does LDAP support the Username Modifier "%USERDOMAIN%\%USERINPUT%" when the User Domain is configured along with Login Attribute "sAMAccountName" in the authentication profile

1934
Created On 01/30/23 02:52 AM - Last Modified 01/31/25 21:25 PM


Question


  • Does LDAP support the username modifier "%USERDOMAIN%\%USERINPUT%" when the User Domain is configured along with Login Attribute "sAMAccountName" in the authentication profile?
screenshot for username modifier configuration


Environment


  • GlobalProtect Portal and Gateway.
  • LDAP authentication


Answer


  1. LDAP doesn't support the Username Modifier "%USERDOMAIN%\%USERINPUT%" when the User Domain is configured along with Login Attribute "sAMAccountName" in the authentication profile.
  2. Configure Username Modifier "%USERINPUT%" when the User Domain is configured along with Login Attribute "sAMAccountName" in the authentication profile.

 



Additional Information


.........
-0800 debug: pan_authd_ldap_authenticate(pan_authd_shared_ldap.c:1223): DN sent to LDAP server: DC=sarad,DC=com
-0800 Error:  _parse_ldap_bind_result(pan_authd_shared_ldap.c:282): bind failed (extracted from parsed bind result) (code: 49) (string: Invalid credentials) (additional info: 80090308: LdapErr: DSID-0C09044E, comment: AcceptSecurityContext error, data 57, v2580)<<<<<<<<
-0800 Error:  _parse_ldap_bind_result(pan_authd_shared_ldap.c:286): wrong password was provided <<<<<<<
-0800 Error:  pan_authd_ldap_authenticate(pan_authd_shared_ldap.c:1245): User "sarad.com\shlok525" is REJECTED (msgid = 4, LDAPp=0x564b5ec86100)
-0800 debug: pan_authd_ldap_authenticate(pan_authd_shared_ldap.c:1328): binding back to binddn: uiasvc@sarad.com (Try 1)
-0800 debug: pan_authd_ldap_bind(pan_authd_shared_ldap.c:637): binding with binddn uiasvc@sarad.com
-0800 debug: pan_auth_response_process(pan_auth_state_engine.c:4381): auth status: auth failed <<<<<<<<<<
-0800 debug: pan_auth_incr_failed_attempt(pan_authd_db.c:173): increase failed attempt for user: shlok525
-0800 debug: pan_auth_response_process(pan_auth_state_engine.c:4577): Authentication failed: <profile: "LDAP1", vsys: "vsys1", username "sarad.com\shlok525">
-0800 failed authentication for user 'shlok525'.  Reason: Invalid username/password. auth profile 'LDAP1', vsys 'vsys1', server profile 'LDAP', server address '172.18.18.4', From: 192.168.0.20.
-0800 debug: _log_auth_respone(pan_auth_server.c:310): Sent PAN_AUTH_FAILURE auth response for user 'shlok525' (exp_in_days=-1 (-1 never; 0 within a day))(authd_id: 7191876974275461175) (return domain 'sarad.com')

 



Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000sahdCAA&lang=en_US&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail