Troubleshooting: Appliance Randomly Stops Authenticating and Says "Bad User"

Follow
    Applies to:
  • SecureAuth Identity Platform
Deployment model:
  • Cloud
  • Hybrid
  • On Premises
  • Version Affected: All
     
     

    Overview

    The SecureAuth appliance may randomly return a "Bad user" error when a user tries to authenticate against any realm. Active Directory data store connections using a fully qualified domain name (FQDN) in the connection string fail, while connections using an IP address in the connection string succeed.

     

    Cause

    If the environment has multiple domain controllers, and one or more of them does not have proper DNS records assigned, Kerberos tickets may not validate when the service account is issued a Kerberos ticket by the domain controller that is missing a DNS record. This can be confirmed by running a Wireshark trace from the appliance and finding KRB_ERROR_5 entries when the appliance connects to the affected domain controller using the service account in question.

     

    Resolution:

    1. Verify that all domain controllers in the domain are known, and that each one has the accompanying DNS records published on the DNS server (SRV, A, and similar record types).
    2. Reboot the SecureAuth appliance so the service account requests and receives a new Kerberos ticket.
    3. Test the data store connections using FQDN connection strings, and confirm they connect successfully.




    SecureAuth Knowledge Base Articles provide information based on specific use cases and may not apply to all appliances or configurations. Be advised that these instructions could cause harm to the environment if not followed correctly or if they do not apply to the current use case.

    Customers are responsible for their own due diligence prior to utilizing this information and agree that SecureAuth is not liable for any issues caused by misconfiguration directly or indirectly related to SecureAuth products.

    0 out of 0 found this helpful

    Comments

    0 comments

    Please sign in to leave a comment.