Does LDAP support the Username Modifier "%USERDOMAIN%\%USERINPUT%" when the User Domain is configured along with Login Attribute "sAMAccountName" in the authentication profile
1934
Created On 01/30/23 02:52 AM - Last Modified 01/31/25 21:25 PM
Question
- Does LDAP support the username modifier "%USERDOMAIN%\%USERINPUT%" when the User Domain is configured along with Login Attribute "sAMAccountName" in the authentication profile?
Environment
- GlobalProtect Portal and Gateway.
- LDAP authentication
Answer
- LDAP doesn't support the Username Modifier "%USERDOMAIN%\%USERINPUT%" when the User Domain is configured along with Login Attribute "sAMAccountName" in the authentication profile.
- Configure Username Modifier "%USERINPUT%" when the User Domain is configured along with Login Attribute "sAMAccountName" in the authentication profile.
Additional Information
- Configure an Authentication Profile and Sequence
- How authentication username modifiers affect the usernames sent to an authenticating server and authorize users
- When authentication failed authd log shows the below error
.........
-0800 debug: pan_authd_ldap_authenticate(pan_authd_shared_ldap.c:1223): DN sent to LDAP server: DC=sarad,DC=com
-0800 Error: _parse_ldap_bind_result(pan_authd_shared_ldap.c:282): bind failed (extracted from parsed bind result) (code: 49) (string: Invalid credentials) (additional info: 80090308: LdapErr: DSID-0C09044E, comment: AcceptSecurityContext error, data 57, v2580)<<<<<<<<
-0800 Error: _parse_ldap_bind_result(pan_authd_shared_ldap.c:286): wrong password was provided <<<<<<<
-0800 Error: pan_authd_ldap_authenticate(pan_authd_shared_ldap.c:1245): User "sarad.com\shlok525" is REJECTED (msgid = 4, LDAPp=0x564b5ec86100)
-0800 debug: pan_authd_ldap_authenticate(pan_authd_shared_ldap.c:1328): binding back to binddn: uiasvc@sarad.com (Try 1)
-0800 debug: pan_authd_ldap_bind(pan_authd_shared_ldap.c:637): binding with binddn uiasvc@sarad.com
-0800 debug: pan_auth_response_process(pan_auth_state_engine.c:4381): auth status: auth failed <<<<<<<<<<
-0800 debug: pan_auth_incr_failed_attempt(pan_authd_db.c:173): increase failed attempt for user: shlok525
-0800 debug: pan_auth_response_process(pan_auth_state_engine.c:4577): Authentication failed: <profile: "LDAP1", vsys: "vsys1", username "sarad.com\shlok525">
-0800 failed authentication for user 'shlok525'. Reason: Invalid username/password. auth profile 'LDAP1', vsys 'vsys1', server profile 'LDAP', server address '172.18.18.4', From: 192.168.0.20.
-0800 debug: _log_auth_respone(pan_auth_server.c:310): Sent PAN_AUTH_FAILURE auth response for user 'shlok525' (exp_in_days=-1 (-1 never; 0 within a day))(authd_id: 7191876974275461175) (return domain 'sarad.com')