NGS Sponsors authentication does not work in case user has non-English character in his password

Hi,
we are using the NAC Guest Server v 2.0.1 and have Sponsors authentication done through Radius servers. Radius servers are Microsoft IAS using AD.
Sponsors user authentication works okay in case user's password includes English characters, but does not work in case an user uses national characters like for example Umlauts in German.
On Radius server I can see these error messages:
User XXXX was denied access.
Reason = Authentication was not successful because an unknown user name or incorrect password was used.
As soon as an user changes his password and uses English characters only, it resolves.
I guess this might be that NGS uses different coding while sending a password to Radius server, but not sure.
Appreciate if anyone knows a root cause and what could be a workaround. Unfortunately our AD policy allows users to use national characters and we can hardly change it. So a change on NGS or Radius side would be more viable.
Many thanks for your help.

A case has been opened at Cisco and it is now quite clear that it is a problem with coding.
According to Cisco development team NGS uses UTF-8 coding to send the password, of course encrypted, to the Radius server. This cannot be changed within NGS. We use Radius Microsoft IAS Version 5.2.3790.3959 running on VMWare Windows 2003 SP2. More tests are scheduled to be performed.

Similar Messages

  • MAC Authentication does not work

    My MAC Authentication does not work.
    I have a ACS 3.0 server set. the MAC address is set in the user name field and in the password field.
    I can ping the ACS, I can ping my AP, I can ping my client.
    I don't want WEP and I don't want LEAP just MAC. So I set my authentication to "Open with MAC" My client has WEP set to NO WEP and authentication to OPEN
    I have the latest drivers for both AP and my 350 Client.
    I see that the client is associating and disassociating back and forth non stop. My AP log is full with the following message:
    Station 0009.7c9f.xxxx Authentication failed
    this is my config:
    version 12.2
    no service pad
    service timestamps debug datetime msec
    service timestamps log datetime msec
    service password-encryption
    hostname GOM_1200IOS
    aaa new-model
    aaa group server radius rad_eap
    aaa group server radius rad_mac
    server 10.1.2.197 auth-port 1812 acct-port 1812
    aaa group server radius rad_acct
    aaa group server radius rad_admin
    aaa group server tacacs+ tac_admin
    aaa group server radius rad_pmip
    aaa group server radius dummy
    aaa group server radius wlccp_rad_infra
    aaa group server radius wlccp_rad_eap
    aaa group server radius wlccp_rad_leap
    aaa group server radius wlccp_rad_mac
    aaa group server radius wlccp_rad_any
    aaa group server radius wlccp_rad_acct
    aaa authentication login eap_methods group rad_eap
    aaa authentication login mac_methods local
    aaa authentication login wlccp_infra group wlccp_rad_infra
    aaa authentication login wlccp_eap_client group wlccp_rad_eap
    aaa authentication login wlccp_leap_client group wlccp_rad_leap
    aaa authentication login wlccp_mac_client group wlccp_rad_mac
    aaa authentication login wlccp_any_client group wlccp_rad_any
    aaa authorization exec default local
    aaa authorization ipmobile default group rad_pmip
    aaa accounting network acct_methods start-stop group rad_acct
    aaa accounting network wlccp_acct_client start-stop group wlccp_rad_acct
    aaa session-id common
    enable secret xxxxxx
    username Cisco password xxxx
    ip subnet-zero
    iapp standby timeout 5
    bridge irb
    interface Dot11Radio0
    no ip address
    no ip route-cache
    encryption key 1 size 40bit 7 9DF1C10BF11A transmit-key
    ssid GOM_1230
    authentication open mac-address mac_methods
    speed basic-1.0 basic-2.0 basic-5.5 basic-11.0
    rts threshold 2312
    channel 2462
    station-role root
    no cdp enable
    dot1x reauth-period server
    dot1x client-timeout 600
    bridge-group 1
    bridge-group 1 subscriber-loop-control
    bridge-group 1 block-unknown-source
    no bridge-group 1 source-learning
    no bridge-group 1 unicast-flooding
    bridge-group 1 spanning-disabled
    interface FastEthernet0
    no ip address
    no ip route-cache
    duplex auto
    speed auto
    no cdp enable
    bridge-group 1
    no bridge-group 1 source-learning
    bridge-group 1 spanning-disabled
    interface BVI1
    ip address 172.16.43.45 255.255.240.0
    no ip route-cache
    ip default-gateway 172.16.47.254
    ip http server
    ip http help-path http://www.cisco.com/warp/public/779/smbiz/prodconfig/help/eag/ivory/1100
    ip radius source-interface BVI1
    access-list 700 permit 000a.b74c.e8c9 0000.0000.0000
    access-list 700 permit 0009.7c9f.d6e0 0000.0000.0000
    access-list 700 permit 0006.25b1.2f79 0000.0000.0000
    access-list 700 permit 000a.b78b.2d19 0000.0000.0000
    access-list 700 permit 000b.5f6e.77c8 0000.0000.0000
    access-list 700 deny 0000.0000.0000 ffff.ffff.ffff
    access-list 701 deny 000b.5f6e.77c8 0000.0000.0000
    access-list 701 permit 0000.0000.0000 ffff.ffff.ffff
    no cdp run
    snmp-server community GOM_AP1230 RO
    snmp-server enable traps tty
    radius-server local
    group AP1230
    user brazil nthash 7 1249523544595F517972017912677A3055325A25770B08770D5C5B4E4478087605 group AP1230
    radius-server host 10.1.2.197 auth-port 1812 acct-port 1812 key 7 00233C2B
    radius-server retransmit 3
    radius-server attribute 32 include-in-access-req format %h
    radius-server authorization permit missing Service-Type
    radius-server vsa send accounting
    bridge 1 route ip
    line con 0
    line vty 5 15
    end
    What is wrong?
    Thanks very much for your help.

    I figured out what was wrong so thank you for stopping by.
    I will publish the config for other people to see.
    Regards,

  • I have a license of the PSE 11, recently expired, to find out what was going on I have PSE 11 uninstalled. Reinstall does not work because the license has expired. Can I purchase the upgrade version of PSE 12 now or should I buy a full program?

    I have a license of the PARTY 11, recently expired, to find out what was going on I have PSE 11 uninstalled. Reinstall does not work because the license has expired. Can I purchase the upgrade version of PSE 12 now or should I buy a full program?

    Ok thank you, I better can wait then.
    Greetings, Evert Annen
    Op 8 sep. 2014 19:45 schreef "Peru Bob" <[email protected]>:
        I have a license of the PSE 11, recently expired, to find out what
    was going on I have PSE 11 uninstalled. Reinstall does not work because the
    license has expired. Can I purchase the upgrade version of PSE 12 now or
    should I buy a full program?  created by Peru Bob
    <https://forums.adobe.com/people/Peru+Bob> in Photoshop Elements - View
    the full discussion <https://forums.adobe.com/message/6711348#6711348>

  • CE7305 - Transparent mode authentication does not work.

    Hi,
    I’m doing a trial content engine 7305 for my customer. Everything worked well so far with the box except with the authentication feature.
    Authentication work well on proxy mode but when I turned it on with transparent mode it does not work. My customer is using LDAP for user authentication.
    I suspect there is something that I did not turn on in the configuration.
    Attached herewith is the show tech of the Cisco 7305 content engine.
    Please advise!
    Thanks in advance,
    Raymond Hew

    Hi Zach,
    My customer is using Novell LDAP.
    Right at the moment the CE is already working with the auth. after rebooted the CE 7305. Just can't explain why but it works after rebooting.
    Thanks for your fast respond.
    Best regards,
    Raymond Hew

  • TS1702 How do I report a "bad" app product to Apple? The App developer has failed to address the problem and keeps on selling a product which does not work. Surely Apple has some liability in this case or at the very least some responsibility.

    How do I report an App that is not working and the seller has not fixed the problem yet is continuing to sell it? People are being ripped off and Apple does not seem to care.

    sophiesheu wrote:
    I recently purchased a scam app (GPS map Virgin Islands) by the Kaart Data LLC.  I first emailed the developers and got a quick response: "we are sorry that you don't like the app, but we don't do refund".  I went to the "Report a Problem" link from Apple like King_Penguinsuggested, and got a response from Apple saying they will refund the whole amount and start an investigation on that app.  So it definitely worthes a try.
    Glad you got some resolution on that. I'm not familier with the app you had issues with, but the one the OP was questioning is very highly regarded and widely sold. Odds are the issue was with his iPad and he never responed to inquiries about troubleshooting (I suspect he had not tried much of anything).

  • Flash player does not work under one user account.

    Flash player does not work under one of my user accounts.
    My system: I work with a mac mini with Mac OS X 10.6.8.
    What I have done:
    I installed the flash player maybe one year ago under my "first" user account. At that time this user account had had administrator authorization. In the meantime I had to change this "first" user account in an account without administrator authorization and created an administrator user with which I installed different programms. Lately, the message came up that it would be necessary to update the flash player. I did it; under the "first" user account, but of course with the administrator's password for installing. The installation had been "successful" - so I was told. But it did not run. I tried it again and again. Each time with "deinstallation" first. No way; it did not work.
    After asking Adobe for the reason of the problem, they suggested to install the programm directly under the administrator user. I did that (of course after deinstalling under the "first" user account) with the result, that flash player runs under my administrator and my "second" user account, but not under the first user account. There I am always told to update my flash player.
    With this result, I talked to Adobe. So they told me to contact the producer of the operating software, since this would be a mistake of the operating software.
    And here I am - full of hope to get help from you.
    Thanks for reading. And thanks in advance for helping me.
    Nanny FS

    Any update to provide at all here guys?  Again, in my situation, it's very much rights-related as a standard user doesn't even report that the flash player exists when testing it on the Adobe Flash Version Detection website (despite it showing up in Control Panel and under Add/Remove Programs).  I've already tried giving the C:\Windows\System32\Macromed and files/subfolders appropriate permissions for the standard user and still nothing.  If I either give the user in question full local admin rights or logon as the domain admin, then the Adobe Flash Version Detection website says Flash is installed and Flash works fine.
    Thoughts???

  • MB Air two finger scroll does not work for a user but does for another

    Hi
    MB Air. 10.9.3.
    Defective Trackpad was just replaced. Two finger scroll does not work for the main user. I made a test log in and two finger scroll works. I booted off an external drive and two finger scroll works.
    I pulled all of the user preferences out, logged out and in and still does not work. Zapped PRAM. Checked all trackpad settings. No luck.
    Tried this in Terminal:
    defaults write -g com.apple.trackpad.scrollBehavior 2
    Any ideas?

    This sounds strange but check the settings in Settings>Accessability for the track pad. I belive your problem lies there not in Track Pad set up in Settings.

  • Flash Player does not work with Standard User, but will work when browser is "Run as Administrator"

    I don't understand why this is happening, but Flash Player will not work when a Standard User is using the browser. It will only work when the browser is run as an administrator. Any way to fix this? I've tried to uninstall, and reinstall the player, and it still wouldn't work.
    The user is on Windows 7, 64-bit. Using IE 10.
    Flash not working for Standard User - YouTube

    Any update to provide at all here guys?  Again, in my situation, it's very much rights-related as a standard user doesn't even report that the flash player exists when testing it on the Adobe Flash Version Detection website (despite it showing up in Control Panel and under Add/Remove Programs).  I've already tried giving the C:\Windows\System32\Macromed and files/subfolders appropriate permissions for the standard user and still nothing.  If I either give the user in question full local admin rights or logon as the domain admin, then the Adobe Flash Version Detection website says Flash is installed and Flash works fine.
    Thoughts???

  • Web Service Call with Basic Authentication does not work

    If I try to use Basic Authentication in my Web Service Client with the automatically created methods
    setUsername(inUserName)
    setPassword(inPassword)
    setAddress(inAddress)
    the application does not make a call. Did I forget something?
    Is it possible to use "Test Method" with Basic Authentication?
    Thank you.

    Thank you for your answer.
    But: I already read this article. And it doesn't help me.
    I use the following code:
                getMyServiceClient1().setUsername(inUserName);
                getMyServiceClient1().setPassword(inPassword);With this code I always get a java.lang.NullPointerException.
    The methods setUsername and setPassword are definded as follows:
    public void setUsername(String inUserName) {
            myStub._setProperty(Stub.USERNAME_PROPERTY, inUserName);
      public void setPassword(String inPassword) {
            myStub._setProperty(Stub.PASSWORD_PROPERTY, inPassword);
      }But if I look at the methods which are generated automatically by Sun Java Studio Creator I cannot find _setProperty.
    I also found this thread in your forum:
    http://swforum.sun.com/jive/thread.jspa?forumID=123&threadID=54773

  • Exe created with Report Generation toolkit does not work for all users

    I created a exicutable with the report generation toolkit and it only works with some of my users. I use microsoft 2007 and anyone that has microsoft 2007 my exe works well. Most of my users that have microsoft 2010 are able to use my program as well. However, there is one user with 2010 and Windows 2007 that cant get my program to work.
    Any suggestions for troubleshooting this?
    Thanks

    The most likely issue is due to the fact that Microsoft changes the ActiveX object model of Office for each version of Office. The Report Generation Toolkit does a pretty good job of handling this, but it is not 100% effective. Search, for example on the "Set Cell Border" function and you will see what I mean. In these cases it's up to you to handle this issue. How you handle it really depends on your situation. For us to provide a more concrete answer you will need to provide further details, such as what toolkit function is "not working" (whatever that means), and who you "users" are. Is this an internal distribution? Are you selling this program? Is this code written for a project with a specific customer?

  • Xsl:id() function does not work though my document has dtd associated

    My Document has dtd associated, but still the id() function does not seem to work.
    Can anybody suggest me what might be wrong.
    I am creating Document as below:
    DOMImplementation domImpl = dbf.newDocumentBuilder().getDOMImplementation();
    DocumentType docType = domImpl.createDocumentType("project","\"-//Test//Project 1.0//EN\"","c:/test/dtd/test.dtd");
    Document newDoc = domImpl.createDocument(null,"project",docType);
    regards,
    Ranjan

    Hi All
    I created a form based on a UDO and it did not work because I found that the problem is in the code.
    Try:
    1) Build a form for your UDO using B1DE UDO Form Generator;
    2) Load the form generated by your code.
    In the case if not, occurs do the following: comment the code at the events and check again functionality.
    I has posted similar question on this [Thread: UDO Form: Search functionality|UDO Form: Search functionality;
    Now my form works.
    Best Regards
    Sierdna S.
    Edited by: Sierdna S on Oct 20, 2008 1:35 PM

  • FF will not start up. FF does not work on other user accounts on this machine either, but works ok on another pc on our home network. Thanks for any help you can offer.

    Computer is an HP Envy 17 laptop. Firefox does not appear on Task Manager list of processes or applications. System restore did not fix problem. Google Chrome works ok. Internet Explorer works ok until I try to download Firefox. Then it too crashes. This pc has been running Firefox fine since I purchased it 10 months ago. I upgraded FF3 to 4 then to 5 with no problems. Suddenly yesterday it stopped working. There is no error message and evidently FF does not launch because there is no listing of Firefox in Task Manager processes or applications. I tried uninstalling Firefox, then tried to download it usingInternet Explorer, but when I click on the download button at the Mozilla site, Internet Explorer crashes. I did a system restore to 8/16/11 when Firefox was still working. This restored the program but it still does not run. Google Chrome seems to run fine. My internet access is via wifi through an Actiontec router and Verizon Fios. I am running Symantec Endpoint virus protection and do not have any Norton or Skype programs listed in Control Panel. My pc is set for automatic updates from Microsoft and from HP. They both say my software is up to date. Is there a fix for this problem or is it a sinister plot by Microsoft to force us to use Internet Explorer?

    Glad to hear it

  • My usb port does not work on all user accounts

    My usb port does not power my iPhone or Apple keyboard on my main account, but if I switch users it begins to work
    Spring 2011 macbook air with the latest OSX as of Jan 2012.
    Thoughts
    THANKS
    Stan

    Try Resetting the System Management Controller (SMC)

  • Wwa_app_module.file_download does not work for public user

    I have a dynamic page that shows images stored in the database using the wwa_app_module.file_download procedure.
    This works fine if I login as the portal user, but if the page is viewed by a public user the image is not shown. I have granted the package to public but this does not help.
    Any ideas?

    Don't use wwa_app_module.file_download procedure in reports yet.
    The best way is to create your own download procedure by copying,pasting and slighty modifying one of the download_x (where x is a number) procedures in a form's package.
    A form's package will have the download_x procedures if the form has intermedia/blob columns.

  • HTTPS Web Service datastore : does not work in case of proxy

    Data Services 12.2 on Windows XP SP2
    I've set up a datastore, type "web service", url is https://.... (an external web service, outside of our company)
    I'm able to import the functions of this web service into the datastore.
    In a DF, in a query transform, I call one these functions.
    The job fails with this error message :
    There is no response for the web service <searchCertificate>. Ensure that the network, web server, and service are running properly. Also ensure that the service client call time out is set properly.
    I'm sure the web service is active. I have to pass a proxy.
    When I do not have to pass a proxy (when I execute this job on my laptop not connected to the office network) the job runs fine !
    How can you configure the axis2.xml so that https can run with a proxy ? (no problem to do this for http web services, but I do not see a solution for https web services !)
    Thanks !!

    Hi Sukarna,
    the connection is not the problem.
    Actually I've tested the scenario of abap proxy --> PI -->abap proxy for the same interface, it works fine. Only when I try ws instead of proxy, I got this error. Since proxy scenario works fine, the connection should not be issue.
    any more clues?
    Thanks

Maybe you are looking for