WARNING: No "known good" pasword found in LDAP

I'm trying to get windows client (EAP-PEAP MSCHAPv2) to authenticate through freeRadius. I have eDirectory as user store. I've configured universal password and assigned the policy to respective OUs in eDir. I configured universal password policy to allow to retrieve cleartet password by users and "radmin" account, as per Novell docs. iManager RADIUS plugin is also installed, eDir RADIUS schema is extended, radius profile is applied to some users for testing (although no radius attributes are specified in that Radius profile, as Novell docs don't mention anything about it).
However, is looks like eDirectory is still not returning user's clear-text password in its LDAP reply to freeRadus server, the following warning appears in radius debug log: (WARNING: No "known good" password found in LDAP).
I followed this Novell guide to setup eDir and freeRadius: https://www.netiq.com/documentation/...ata/front.html
Here is my radius ldap config:
ldap TEST {
server = "192.168.1.1"
port = 636
identity = "cn=radmin,ou=USERS,o=TEST"
password = "password"
basedn = "ou=USERS,o=TEST"
filter = "(uid=%{%{Stripped-User-Name}:-%{User-Name}})"
#base_filter = "(objectclass=radiusprofile)"
auto_header = yes
ldap_connections_number = 5
timeout = 4
timelimit = 3
net_timeout = 1
tls {
# start_tls = yes
tls_mode = yes
cacertfile = /etc/raddb/certs/test-tree.b64
dictionary_mapping = ${confdir}/ldap.attrmap
password_attribute = nspmPassword
edir_account_policy_check = no
set_auth_type = no
# access_attr = dialupAccess
keepalive {
idle = 60
probes = 3
interval = 3
#END
Any suggestions on fixing the problem are welcomed. Thanks in advance.

log doesn't seem display any errors, also I notices that the "nspm password" is is mentioned twice. As far as I know the n="nspm password" attribute is the clear text password. Also From the log i can see that all attributes are the request from radius, would be good to see actual eDir ldap reply in the log, including reply attributes. Any suggestions?
4269549312 LDAP: Work info status: Total:2 Peak:0 Busy:0
4211123968 LDAP: New TLS connection 0x8d5c00 from 192.168.1.52:54349, monitor = 0xffffffffe5102700, index = 1
3843041024 LDAP: Monitor 0xffffffffe5102700 initiating TLS handshake on connection 0x8d5c00
4205860608 LDAP: DoTLSHandshake on connection 0x8d5c00
4205860608 LDAP: BIO ctrl called with unknown cmd 7
4205860608 LDAP: Completed TLS handshake on connection 0x8d5c00
3821344512 LDAP: DoBind on connection 0x8d5c00
3821344512 LDAP: Bind name:cn=radmin,ou=USERS,o=TEST, version:3, authentication:simple
3821344512 AUTH: [000080c4] <.radmin.USERS.TEST.TEST-TREE.> LocalLoginRequest. Error success, conn: 8.
3821344512 LDAP: Sending operation result 0:"":"" to connection 0x8d5c00
4222703360 LDAP: DoSearch on connection 0x8d5c00
4222703360 LDAP: Search request:
base: "ou=USERS,o=TEST"
scope:2 dereference:0 sizelimit:0 timelimit:3 attrsonly:1
filter: "(uid=radmin)"
attribute: "nspmPassword"
attribute: "radiusNASIpAddress"
attribute: "radiusExpiration"
attribute: "acctFlags"
attribute: "userPassword"
attribute: "dBCSPwd"
attribute: "sambaNtPassword"
attribute: "sambaLmPassword"
attribute: "ntPassword"
attribute: "lmPassword"
attribute: "radiusCallingStationId"
attribute: "radiusCalledStationId"
attribute: "radiusSimultaneousUse"
attribute: "radiusAuthType"
attribute: "radiusCheckItem"
attribute: "radiusTunnelPrivateGroupId"
attribute: "radiusTunnelMediumType"
attribute: "radiusTunnelType"
attribute: "radiusReplyMessage"
attribute: "radiusLoginLATPort"
attribute: "radiusPortLimit"
attribute: "radiusFramedAppleTalkZone"
attribute: "radiusFramedAppleTalkNetwork"
attribute: "radiusFramedAppleTalkLink"
attribute: "radiusLoginLATGroup"
attribute: "radiusLoginLATNode"
attribute: "radiusLoginLATService"
attribute: "radiusTerminationAction"
attribute: "radiusIdleTimeout"
attribute: "radiusSessionTimeout"
attribute: "radiusClass"
attribute: "radiusFramedIPXNetwork"
attribute: "radiusCallbackId"
attribute: "radiusCallbackNumber"
attribute: "radiusLoginTCPPort"
attribute: "radiusLoginService"
attribute: "radiusLoginIPHost"
attribute: "radiusFramedCompression"
attribute: "radiusFramedMTU"
attribute: "radiusFilterId"
attribute: "radiusFramedRouting"
attribute: "radiusFramedRoute"
attribute: "radiusFramedIPNetmask"
attribute: "radiusFramedIPAddress"
attribute: "radiusFramedProtocol"
attribute: "radiusServiceType"
attribute: "radiusReplyItem"
attribute: "nspmPassword"
4222703360 AUTH: Starting SEV calculation for conn 8, entry .radmin.USERS.TEST.TEST-TREE..
4222703360 AUTH: 1 GlobalGetSEV.
4222703360 AUTH: 4 GlobalGetSEV succeeded.
4222703360 AUTH: SEV calculation complete for conn 8, (0:0 s:ms).
4222703360 LDAP: Sending search result entry "cn=radmin,ou=USERS,o=TEST" to connection 0x8d5c00
4222703360 LDAP: Sending operation result 0:"":"" to connection 0x8d5c00
4219545344 AUTH: UpdateLoginAttributesThread page 1 processed 1 login in 1 milliseconds

Similar Messages

  • Any way to set aside a "known good" iPhone backup?

    I've had lots of trouble with my 3G iPhone crashing irreversibly and needing a restore. Tonight Apple gave me a new phone- maybe that will solve it, but in the meantime, after four full restores, I really want a way to preserve a "known good" backup.
    Every time I've restored, I've had to go back farther in time than I wanted to. iTunes gives me a choice of multiple backup dates, but I've found there's only a couple that are very recent, and they're typically suspect.
    Is there any way to trick iTunes into preserving a particular backup version? As I understand it, renaming the iPhone won't do this. Can I duplicate and set aside some SyncServices folder and then replace it when I want to roll back to the known-good version?
    I've been through a lot of iPhone 2.0 suffering here, and it would be nice to improve my odds for the future....

    I've been able to get out of a bind by doing backups every so often on more than one computer. With the previous version iPhone, I had a few times when one backup was corrupted so I went in and used the backup from another computer that was about a week old. Just lost a few SMS messages and that weeks phone logs but nothing too important.
    Hopefully someone else will have other ideas as well.

  • Suddenly all my iOS devoices refuse to connect to all my known good networks

    Weeks ago I upgraded my iPhone, iPad and iPad Mini to iOS7 (and the subsequent updates). All was well. This morning all three devices refuse to connect to both of my known good WiFi networks (known good because everything else connected to them is fine).
    The symptom: Settings:, Wi-Fi: I select my network and the 'grey ball' starts to spin. But... it never makes a connection. The grey ball spins forever, never making a connection nor reporting an error. Both networks are totally seperate Airport Express devices. In pursuit of this problem I have completely reset and reconfigured one of them, no solution.
    Attempted so far: Network Reset on all three devices. Nothing. Reboots on all three, nothing. A hard reset, nothing. A total delete and restore of the iPad both via iTunes 11.1 and standalone, nothing.
    All three devices can make cellular connections just fine.
    I am really running out of ideas here - any pointers would be most welcome.

    Ok, after a very energetic and impressive response from Apple I found the answer - thank you Apple.
    Reboot the Router! Yes... it did'nt make sense to me. Something to do with DHCP leases, the Aiprports use DHCP assigned IP addresses that are issued by the router. Rebooting the Router forced the leases to renew, and bingo, problem solved. If I have the problem again I may put the Airports on fixed IP addresses to see if the issue goes away.

  • Mac mini 2009 mavericks won't boot. Blank display no logo,etc. Tried all keyboard boot functions, no help. replaced RAM w/known good. No help. Removed HD mounted in external enclosure and ran permissions and repair. No help. Upgraded HD to Yosemite a

    Mac mini 2009 Mavericks won't boot. Chimes and power light comes on. USB ports have power. Blank display no logo,etc. Tried all keyboard boot functions, no help. Replaced RAM w/known good. No help. Removed HD and mounted in external enclosure and ran permissions and repair. No help. Upgraded HD to Yosemite and was able to boot another mini from HD mounted in external enclosure, reinstalled HD still no boot. Any ideas on how to proceed appreciated.

    - Make an appointment at the Genius Bar of an Apple store. You have a hardware problem.
      Apple Retail Store - Genius Bar

  • Log4j:WARN No appenders could be found

    We are using weblogic 10.0.1 and JDK 1.6.
    We are using Log4j for logging, if I pass -Dlog4j.configuration=log4jconfig.xml in the startup script as a command line parameter weblogic console is displaying following warning messages. However, system properly initializes Log4j properly.
    Looks like beehive loggers are not initialized properly. In our log4jconfig.xml we have added appender for org.apache.
    log4j:WARN No appenders could be found for logger (org.apache.beehive.netui.pageflow.internal.AdapterManager).
    log4j:WARN Please initialize the log4j system properly.
    Please advise

    I've the same problem on weblogic 10.0.
    When the application code calls commons LogFactory for the first time, I see the following error messages.
    log4j:WARN No appenders could be found for logger (com.xxx.TestClass).
    log4j:WARN Please initialize the log4j system properly.
    Can someone explain why the same config file/setup works with Weblogic 8.1 but not with Weblogic 10.
    Thanks
    Kambiz
    Here is my folder structure
    -webroot
    +
    +-WEB-INF
    +classes
    | |--log4j.properties
    +lib
    +commons-logging.jar
    +log4j-1.2.15.jar                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           

  • ICloud flags known good email as junk!

    For the past few months, iCloud mail has frequently flagged known good email as junk. In all cases, the messages that are flagged are from correspondents who have been sending me messages for years without any problem. Now, all of a sudden, iCloud thinks these messages are junk—and continues to flag them as junk no matter how many times I tell iCloud that they are "not junk".
    I also see that Apple offers iCloud tech support only to those whose computers are still in warranty. What's with that?! No email support, no nothing.
    Suggestions appreciated.

    - Add the thumbs down button to your mail toolbar as other commenters have noted (View>Customize Toolbar).
    - Open your junk mail folder and find one of the messages that should not have been marked as junk.
    - Hit the "Thumbs Down" button.
    - A banner will appear at the top of the message preview window that says "You marked this a junk mail."
    - In that banner will be a "Not Junk" button.
    Contrary to Apple's principle, this is not very intuitive, and it places the blame/responsibility for the mis-categorization back on the user ("YOU marked..."). However, this method does work to keep future messages like the ones you've unmarked from landing in your Junk folder.

  • Prime Infrastructure 2.0 "Wrong CLI Credentials" error with known good credentials

    In the device work center sometimes devices show up with "wrong CLI credentials". Even when I change to known good SSH credentials and click the update & sync button the error does not go away.
    Has anyone else had this issue? Does anyone know a workaround?
    It seems absurd that you would not be able to edit the SSH credentials of devices.

    ok, tried all that was said here. Nothing worked ... I do have banners, but no # sign ... removed them anyways ... then thinking about the banners might be causing issues for what PI expects ... (i do have my prompts changed to mask the platform) ... so i defaulted back to regular prompts ... WORKED !!!!
    So here is what works for me ... no banners, no custom prompts AND device added through the 'classic theme'.
    I presume the expectation is that the device begins with minimal config ... the rest is pushed through the config templates deployment. But have the developers thought of existing devices ? is it IOS version related (target device) or simply a bug.
    BTW, PI v2.1
    Edit --- needing to clarify, for some models (namely UC520) ... removed banner, custom prompts and i could add it comfortably through the Lifecycle interface.
    Others (3550), could be inserted easily with banners and custom prompts ... rather inconsistent, though at least , i have working recipes.
    Thanks for the help all :)

  • I have a known good apple id and password but when I try to update apps i am told incorrect password or id

    I have a known good apple id and password, but when I try to update apps I am told incorrect apple id or password through the iTunes store

    Probably because the Apps in question were originally downloaded using a different Apple-id.

  • Getting error as :  log4j : WARN No appenders could be found for logger

    Hi all,
    I am using IBM - Rational Application Developer (RAD) for the development of my project service task.
    I am trying to use log4j to log various events like errors and warnings and so on ....
    But I am getting following errors in console window of RAD :
    {color:#ff0000}
    [8/5/08 10:12:18:001 IST] 00000038 SystemErr R log4j:WARN No appenders could be found for logger (VINValidationService).
    [8/5/08 10:12:18:001 IST] 00000038 SystemErr R log4j:WARN Please initialize the log4j system properly.{color}
    If you have any clue regarding how to get out of this then it would be of great help to me .... please reply soon ....!
    (Please note that I have tried all the ways of setting CLASSPATHS and BUILDPATHS in the RAD) .
    --- Thanking you in advance ...
    Akshay_L.

    You could read these to get some hints [http://www.google.co.uk/search?q=%22Please+initialize+the+log4j+system+properly.%22]
    The first reply to the first hit on google says "log4j.properties needs to be on the classpath where log4j can find it.".
    You can set the system property if you wish but the classpath approach is the easiest in my opinion.

  • Log4j:WARN No appenders could be found for logger (Log4jExample).

    Hi,
    I am getting this error when I try to use log4j to generate logs.The program works fine if I keep log4j.properties file and my logging program in the same directory.
    If it is different directory,how to make it work ? like below.
    Any help in this regard is appreciated.
    Thanks
    Chat
    C:\mjava\test > dir
    Log4jExample.java
    C:\mjava\test >java Log4jExample.java
    log4j:WARN No appenders could be found for logger (Log4jExample).
    log4j:WARN Please initialize the log4j system properly.
    import org.apache.log4j.*;
    public class Log4jExample
        private static final Logger log =
            Logger.getLogger(Log4jExample.class);
        public static void main(String[] args)
            try
                log.debug("This is a debug message.");
                int i = Integer.parseInt("Hello world");
            catch (java.lang.Exception ex)
                log.error("Caught an exception", ex);
    C:\mjava>dir
    log4j.properties

    I'd recommend you use the classpath. But don't put log4j.properties in the parent directory of where your java class is, or the classpath will end up being incorrect. Try putting it in a separate directory tree, or as a child directory of where your class lives.
    Then add the classpath option to the runtime.
    java -classpath .;otherDirectory Log4jExample
    (where "otherDirectory" is the directory that contains log4j.properties)

  • Log4j: WARN No appenders could be found for logger

    Hi,
    I defined a log4j.properties file in my class directory:
    log4j.defaultInitOverride=false
    log4j.rootLogger=DEBUG, R, S
    log4j.appender.R=org.apache.log4j.RollingFileAppender
    log4j.appender.R.File=R.log
    log4j.appender.R.MaxFileSize=100KB
    log4j.appender.R.MaxBackupIndex=0
    log4j.appender.R.layout=org.apache.log4j.PatternLayout
    log4j.appender.R.layout.ConversionPattern=%p %t %c - %m%n
    log4j.appender.S=org.apache.log4j.RollingFileAppender
    log4j.appender.S.File=S.log
    log4j.appender.S.MaxFileSize=100KB
    log4j.appender.S.MaxBackupIndex=0
    log4j.appender.S.layout=org.apache.log4j.PatternLayout
    log4j.appender.S.layout.ConversionPattern=%p %t %c - %m%n
    Then I used the Logger in loginAction.java:
    private Logger logger = Logger.getLogger("R");
    logger.setAdditivity(false);
    logger.info("LoginAction");
    and in OracleDAOFactory.java:
    private Logger logger = Logger.getLogger("S");
    logger.setAdditivity(false);
    logger.info("Connected to DB from customer DAO");
    what I want to achieve is to record the information for loginAction in R.log and record the information for OracleDAOFactory in S.log. But do NOT add loginAction's information into OracleDAOFactory, and vice versa.
    The above codes work properly if I remove the line "logger.setAdditivity(false);". However the result is both log files have the contents. But if I add the line "logger.setAdditivity(false);", I get the following error message:
    log4j:WARN No appenders could be found for logger (S).
    log4j:WARN Please initialize the log4j system properly.
    What is wrong with my above coding?
    Thanks for your help!

    I don't know if this applies to your situation, but I just resolved this problem in my own environment. It turns out, I was attempting to log something in an area of my code before the logger had been configured by calling the configure method of the PropertyConfigurator class and passing in the file name of the properties file as the argument. It's important to set up log4j before attempting to log to the output file, and I called a debug method before it was set up.

  • Ways an attacker might start malware with a known good service

    How would an attacker be able to get malware started at the same time a legitimate, known good service is started? I am consulting on trying to fix a server that has a service starting and using the tool StealthWatch, we can see that the service is
    shown as running TCP scans of blocks of network addresses. I have compared the MD5 hash of the service to a known good copy of the same service on another server and they are the same, so I pretty confident that the service itself is not changed. I see no
    dependencies for the service and other testing I have done is testing using sigcheck.exe to validate that the service is signed and also checked the signature all of the files in the same directory where the service is located.
    What techniques have you seen that can be used to run malware along with a legitimate service?
    SnoBoy

    Hi,
    Here is some general information regarding malware for you:
    Defining Malware: FAQ
    https://technet.microsoft.com/en-us/library/dd632948.aspx
    Malware
    http://en.wikipedia.org/wiki/Malware
    Best Regards,
    Amy
    Please remember to mark the replies as answers if they help and un-mark them if they provide no help. If you have feedback for TechNet Subscriber Support, contact
    [email protected]

  • IMAP login failures with known good settings

    I cannot set an IMAP account for a particular mail server. The settings are known good (work in other clients) The server is absolutly an IMAP server. the login fails no matter what i try. If I recreate the account but make it pop 3 it works fine, but IMAP will not.
    The settings used are at this link, under IMAP:
    https://www.rit.edu/its/services/email/setup/setup_exchange_quick_reference.html
    Any thoughts would be appreciated.
    Thanks,
    Alan

    So your not a student or alumni?
    It is that Kerberos for SMTP that gets me. That requires a token server to be .
    Try the It people with how to you connect your computer to the issuing trust tokens
    So I think the answer is ask the IT people how you connect your computer to the Kerberos/GSSAPI realm so the SMTP can authenticate. I have a feeling there is a [https://www.rit.edu/its/services/vpn VPN ]in your future, but we will see.

  • I have a MacBook Pro running 10.7.2.  I am trying to import photos from my older Canon EOS-1D for the first time since my OS upgrade.  iPhoto does not see the camera nor does Image Capture.  IC says there is not a camera connected.  Cable is known good.

    I have a MacBook Pro running 10.7.2.  I am trying to import photos from my older Canon EOS-1D for the first time since my OS upgrade.  iPhoto does not see the camera nor does Image Capture.  IC says there is not a camera connected.  Cable is known good.  Has something changed?  Thanks!

    If neither iPhoto not IC can seethe card it might suggest an issue with the card or the ports on the camera/mac.
    Try reformat the card, change the ports and/or use a USB Card Reader.

  • Sending Human Task notification mail to a assignee not found in LDAP

    Hi All,
    I have 2 requirements:
    1. Suppose i have a HumanTask which sends a notification mail to the assignee when the task is assigned to him/her.
        In our process we are first checking if the assignee's email address is present in LDAP using the BPEL variable that holds the assigneeID.
        If it is not present in LDAP, then we are getting the email address from database before the invocation of the HumanTask.
        Now, as the emailaddress is not found in LDAP, so when the HumanTask is invoked the notification mail will not be sent to the assignee.
        So, we have used a separate email activity after the invocation of HumanTask to send the notification mail to the assignee using his emailaddress that we fetched from the database.
        I don't want to use this separate email activity and wanted to know if there is any other alternative to send the notification mail during invocation of the HumanTask using the emailaddress that
        we fetched from the database?
       Basically i want to know if there is any other way to send the notification mail when a task is assigned and the assignee's email address is not found in LDAP?
    2. Is it possible to send a Human Task's outcomes as links in an email activity body?
       Actually, i am sending a mail to a user using the email activity. Before that a HumanTask is present in my BPEL process.
       I want to send the HumanTask's outcomes as links in the email that i am sending to the user using the email activity just as they get displayed in the notification mail when HumanTask's "Make
       notification actionable" feature is selected.
    Please help me with the above requirements.
    Regards,
    Suman

    AnilB,
    Assigning a task to a user that is not in the directory will likely result in the BPM flow going into suspended state. To avoid this, assign the task to a pre-created group, you should not get an error even if the group is empty. You can then add and remove the users to that group to control access to the task.
    Phil

Maybe you are looking for

  • Reg open production orders

    Dear all, Suppose if we are transfering data from one company code,controlling area,and plant to other, how to deal with open production orders specially for orders for which goods issue has taken place and in which somel operations are confirmed.How

  • JWS 1.4.2_06 NoClassDefFoundError

    Help! I am trying to deploy a new application written in java version 1.4.2_01-b06. The network people pushed out JWS version 1.4.2_06 to almost 2000 workstations. The new app will not work with that JWS and returns the error message listed below (No

  • Infoview Timeout Error

    Hi We are using Business Objects XI 3.0 with Integration Kit for SAP Solutions on Windows 2003 Server with Weblogic 10.0 server.We have integrated the SAP Portal with our BO environment.We created URL iview to point to the Infoview and after running

  • How many Read Only Cache Groups?

    How many Read Only Cache Groups we can createin in one DSN? I mean if e.g. 100 are possible? Thanks BR Andrzej Edited by: user8181100 on 2009-04-07 05:53

  • Flash movie downloader?

    Does anyone know a "DECENT" easy to use add on that will allow me to download movies from sites like youtube etc... so that I can add them to itunes/ipod/iphone/psp..... Either for safari or firefox. I have tried one called "download helper" with fir