Version Affected: All
Overview
Testing the LDAP connection on a realm's Data tab returns "The user name or password is incorrect," even though the credentials being used are valid and correct.
Cause
This is typically caused by copying a realm's web.config file to a new appliance without also bringing over the certificate that realm references. The certificate selected in the System Info tab's License Info section is used to encrypt and decrypt the password sent for the LDAP bind; if that certificate does not exist on the local server, the appliance cannot decrypt the password, so the connection test fails with this error even though the credentials themselves are correct.
Resolution:
To resolve this:
- If this is a test server, or a server that employees will not be using, select any certificate that is issued by SecureAuth in the System Info tab's License Info section.
- If this is a production appliance, or one that employees will be using, export the certificate, including its private key and with Make exportable selected, from the appliance the realms were copied from, then import that certificate into this appliance and select it in the System Info tab's License Info section.
SecureAuth Knowledge Base Articles provide information based on specific use cases and may not apply to all appliances or configurations. Be advised that these instructions could cause harm to the environment if not followed correctly or if they do not apply to the current use case.
Customers are responsible for their own due diligence prior to utilizing this information and agree that SecureAuth is not liable for any issues caused by misconfiguration directly or indirectly related to SecureAuth products.
Comments
Please sign in to leave a comment.