Unable to login with some LDAP Users

Solved
OA
Ozan Acikalin Silver Contributor
JAMBO GmbH

Hello,

i am running MobiControl version 15.1.2.1035 on premise

We are using the instance for about 2 months now. We added our ldap for the enrollment and
to login on the web console.

Out of nowhere some ldap users are not able to login anymore. I checked some users and some
can login and some get the error message

"Invalid credentials, please try again!"

I tried to delete the ldap user and add him again. But made no difference. Then i tried to restart
all services but didn't helped too.

Then i tried to create a new ldap user and add him to mobicontrol. Even the new ldap user was
not able to login.

Then i checked the logs. The logs kinda irritated me because it was saying  different error messages
before and after i restarted the services.

At first it was saying that the user is using the wrong credentials and that he should use the correct ldap
credentials to login using domain\username. And later it was saying that there is no access right defined
for that user. That does not make sense because he is part of the admin group in MC with full rights.

There were no changes in the ldap database for those users. No one touched the configurations on the
server, ldap server or withing mobicontrol.

So has someone an idea how i could fix this?

EDIT: requests from the api no longer work either

Edited 5 years ago
SOTI MobiControl
ANSWERS
YR
Yoan R Bronze Contributor
4 years ago

Thank you. After a complete check and analysis of the logs, it turns out that MobiControl does not know how to correctly follow the AD referrals. However the error message in the logs was really not clear : Exception: LDAP server is not available.

So the solution for us was to simply uncheck the "Follow Referrals" box (which was checked until now)

(Works with the port 636 and 3269)

Solution
MB
OA
Ozan Acikalin Silver Contributor
5 years ago

Hi Marcus,

yes i enabled it from the beginning. I also unenabled and re-enabled the setting just in case.

I mean it was working for 2 months. And now without any changes this is happening.

MB

Ho Ozan,

can it happen that the Password from the User has changed or the User bis Blocked ?

I had this issue too , and the Password from the User who is connecting to the Active Driectory has changed.

OA
Ozan Acikalin Silver Contributor
5 years ago

Hi Marcus,

the password of the user didn't changed. I can login with the user via ldap on other platforms
without any problems. The user is not blocked as far as i checked. I thought the user got blocked
by the MC web console because of failed login attempts but this option does work only for local
users on the web console.

Maybe there is a option where ldap users can be blocked i dont know about?

YR
Yoan R Bronze Contributor
4 years ago

Hi, same issue here. Any solution or idea ?

Many thanks

RC
Raymond Chan Diamond Contributor
4 years ago

If the AD/LDAP integration in Soti MobiControl was not done properly, it is possible that one can never get any AD/LDAP log-in  done successfully.  There are over ten parameters to be set up, and possibly much more related to attribute/value pairs if the DS server is not Microsoft AD.

YR
Yoan R Bronze Contributor
4 years ago

Thank you for your anser.

Currently, the Directory Service Configuration seems to be correctly configured (no error message when validating the addition of  the new LDAP connection). LDAP integration is enabled in the Console Security options.

We can also add our AD groups in the users management. MobiControl can correctly find them.

But it is still impossible to login to the console with AD credential.

And like Ozan, it was correctly working few days ago and no changes have been made.

RC
Raymond Chan Diamond Contributor
4 years ago

If the log-in worked fine few days ago, then your DS integration should be OK.

What is the version of your MobiControl server?

Did you look into various server logs for any suspicious items within these few days?   Open an official support case with Soti support team and send them the log files.

SS
Support Staff Account Platinum Contributor
4 years ago (edited 4 years ago)

Hello Ozan, 

Were you able to apply any of the suggestions provided in this discussion to resolve your issue?  Perhaps if any of these have solved your post you can select it as "is solution".  if not please update the post so we can provide you with next steps.

Regards,

OA
Ozan Acikalin Silver Contributor
4 years ago

Hello,

i actually dont know. Non of the solutions worked. Even the solution from @Yoan.

I just gave the broken users a new login so they were able to work again on the web console.

But since then and after few upgrades to newer versions of MC the problem never appeared again.

Will set @Yoan post as "is solution" :)

Hello Ozan, 

Thank you for the reply.  

Alternatively, you can create a case VIA Support@soti.net and have one of our Technicians look into the issue more in-depth VIA the logs.

Regardless, thank you for marking the post as "is solution" as it seems that the resolution that was provided by Yoan is a viable solution.  Unfortunately, it didn't work for you.

If you create a case feel free to let me know the case number VIA the private message and I will ensure follow-up is conducted.

Regards,