Authentication Agent for Windows v. 7.4.x Challenge lookup fails with "Cannot open challenge cache data key for user <UserID>" and "The server is not operational"
Originally Published: 2021-03-15
Last Modified: 2022-06-20
Article Number
Applies To
RSA Product/Service Type: Authentication Agent for Windows
RSA Version/Condition: 7.4
Platform: Windows
Platform (Other): challenge group for users across 2 Domains
O/S Version: Server 2012 R2
Issue
"ADsOpenObject failed",
"Failed to open IADsGroup"
"Returning: The server is not operational"
“[ADSIHelper::getAdsiBindingFlags] Policy: No binding {noformat}"
"Cannot open challenge cache data key for user"
===SIDAuthenticator(LogonUI).log===
2020-01-30 16:11:51.790 9380.9052 [I] [ADSIHelper::getAdsiBindingFlags] Policy: SSL binding
2020-01-30 16:11:51.790 9380.9052 [V] [ADSIHelper::getAdsiBindingFlags] Return
2020-01-30 16:11:51.806 9380.9052 [E] [ADSIHelper::openLdapADsObject<IADsGroup>] ADsOpenObject failed.
2020-01-30 16:11:51.806 9380.9052 [I] [ADSIHelper::openLdapADsObject<IADsGroup>] Returning: The server is not operational.
Object path: LDAP://CN=<Windows_Name>,OU=<ou>,OU=People,DC=<domain>,DC=<org>
User: LDAP://CN=<UserID>,OU=<ou>,OU=People,DC=<domain>,DC=<org>
Cause
Therefore:
If the Fail open option set, users can logon without a Passcode, with just a Password.
If the Fail close option set, users can only logon with a Password.
Resolution
For SSL binding with AAWin 7.4.x
Two of the key takeaways:
1. The need to import the SSL cert into the Server’s Service Account NTDS\Personal store
2. Use of the ldp.exe tool as a test utility to confirm the setup.
Another possibility from RSA Engineering:
If the “SSL Binding” is set to "Kerberos" option for the AD binding, the AD traffic is encrypted with a key that is derived from Kerberos credentials rather than with the key in the SSL cert, which protects the AD payload against network sniffing without PKI or Certificates.
Workaround
Notes
https://social.technet.microsoft.com/wiki/contents/articles/2979.event-id-1220-ldap-over-ssl-ldaps.aspx
Related Articles
A more concise guide to updating Authentication Manager 8.x passwords 351Number of Views PAM Agent Solaris 10 sshd allows SecurID challenged user with blank Unix password access without challenge 67Number of Views ORA-39070: "Unable to open the log file" error or ORA-06512: at "SYS.DBMS_SYS_ERROR" and "SYS.DBMS_DATAPUMP" errors when b… 280Number of Views Unable to open a workflow after upgrade to RSA Identity Governance & Lifecycle 7.1.0 P01 with error "The features paramete… 110Number of Views Determine the challenge mode of RSA Authentication Agent 7.x for Windows from Windows registry 152Number of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device Reporting on RSA Authentication Manager 8.x users with On-Demand Token, a fixed passcode or a hardware/software token assi… How to Download OTP Token Seed Files from myRSA Anomalix idGenius - SAML Relying Party Configuration - RSA Ready Implementation Guide RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide
Don't see what you're looking for?