Symantec Access Management

 View Only

Tech Tip : CA Single Sign-On : Policy Server authenticate user in Active Directory even if the User must change its password. No redirection happens.

  • 1.  Tech Tip : CA Single Sign-On : Policy Server authenticate user in Active Directory even if the User must change its password. No redirection happens.

    Broadcom Employee
    Posted Jul 06, 2017 09:26 AM

    Issue:

     

    Running Policy Server, when user has Password Expired, then Policy Server authenticate the user.

     

    By trouble shooting this issue, we've observed that the Policy Server gets the right code from Active Directory, but the Policy Server authenticate and authorize the user.

     

    [12/02/2015][08:00:52][4532][s626/r15][Sm_Auth_Message.cpp:4629][CSm_Auth_Message::SendReply][badal][][][test.one][][][][** Status: Not Authenticated. Password must change. 80090308: LdapErr: DSID-0C0903A9, comment: AcceptSecurityContext error, data 532, v1db1][Badal Root][][][BadalTest][badalagent][Password must change. 80090308: LdapErr: DSID-0C0903A9, comment: AcceptSecurityContext error, data 532, v1db1][eTenet Form Auth-Siteminder][test.one][][]

     

    As per the code data 532

    HEX: 0x532 - password expired

     

    Environment:

     

    Policy Server 12.52SP1CR02 User Directory Microsoft Active Directory 2008 R2

     

    Resolution:

     

    Fix in 12.52 SP1 CR05

     

    00250192 DE101595 The Authreason codes from Policy Server are not same as the AD response irrespective of the status of isADEnhanced.

    defects fixed in 1252sp1cr05

    KB :TEC1901049