SecurID Access: Repeated LDAP Bind Errors logged
Originally Published: 2016-09-21
Last Modified: 2023-11-30
Article Number
Applies To
RSA Product/Service Type: Identity Router
Issue
2016-08-22/14:44:37.666/UTC [Thread-505] WARN com.symplified.adapter.userstores.ldap.LdapUserStoreConnectionImpl[94] - Failed to create initial dir context for LDAP connection. LDAP server is 'ldap://<ip-address>' principal is '<principal-name>'. Try one more time ... 2016-08-22/14:44:37.669/UTC [Thread-505] ERROR com.symplified.adapter.userstores.ldap.LdapUserStoreConnectionImpl[122] - Failed to create initial dir context for LDAP connection. LDAP server is 'ldap://<ip-address>' principal is '<principal-name>'. CAUSE: [LDAP: error code 49 - 8009030C: LdapErr: DSID-0C0904DC, comment: AcceptSecurityContext error, data 52e, v1db1]
Cause
One of the configuration requirements for successful SASL digest-MD5 authentication is that reversible encryption must be configured for the AD Administrator's password. Further, if you do configure the AD administrator to successfully authenticate using the SASL digest-MD5 mechanism, then all SecurID Access web portal authentications will strictly be using SASL Digest. This means all end users that intend to authenticate to the Via Access Web Portal will need to have their password stored using reversible encryption.
If reversible encryption is not configured in AD, the SASL digest-MD5 mechanism will continue to fail, and you will see related error messages logged every time the IDR attempts to authenticate, before a successful authentication using Simple BIND.
On the current release of SecurID Access, even if AD is configured appropriately for the SASL digest-MD5 mechanism. SASL digest-MD5 authentication will still fail due to a format error in the principle name that the IDR sends to AD. This issue is currently preventing successful AD authentication with SASL digest-MD5,
Resolution
Workaround
Related Articles
RSA Announces the July 2021 Release of RSA SecurID Access 64Number of Views Windows desktop machine does not display last logged in user ID with RSA Authentication Agent 7.x for Microsoft Windows 73Number of Views False Positive - RSA Authentication Manager 8.1 SP1 P10 vulnerable to CVE 2016-0728, CVE-2015-8787 and CVE-2015-8709 (Open… 32Number of Views Successful SSH login attempts are not logged in /var/log/messages in Authentication Manager prior to 8.4 39Number of Views Create list of users who have not logged into RSA Authentication Manager 8.x for a specific period of days 123Number of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device Reporting on RSA Authentication Manager 8.x users with On-Demand Token, a fixed passcode or a hardware/software token assi… How to Download OTP Token Seed Files from myRSA Anomalix idGenius - SAML Relying Party Configuration - RSA Ready Implementation Guide RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide
Don't see what you're looking for?