Cannot change password user AD of ASA

ASA 8.4 running. I have the password-management enabled on the tunnel group, LDAP over SSL is activated, but when I test in defining an account to require password change after the next connection, the new page password required loads (clientless) and allows to enter password again. After continue to knock, he returned to the login page user name with this message above the username field

"

Cannot complete the password change, because the password does not meet the password policy requirements. Check the minimum password length, password complexity and password history requirements.

".

Yet, I am able to change the password at the same time a post work, so there is no policy of gp who refuses change of password. We have minimum days 0 and no complexity required. I'll meet the minimum length.

a debug output when I hit continue it after entering the new password:

Starting a session [10068]

New [10068] Session, request the 0x74637d10 context, reqType = change password

Started fiber [10068]

[10068] LDAP context with uri = ldaps://192.168.102.15:636

[10068] to connect to the LDAP server: ldaps://192.168.102.15:636, status = success

supportedLDAPVersion [10068]: value = 3

supportedLDAPVersion [10068]: value = 2

[10068] link as asauser

Authentication Simple running [10068] to asauser to 192.168.102.15

Search LDAP [10068]:

Base DN = [DC = subdomain, DC = company, DC = com]

Filter = [[email protected] / * /]

Range = [subtree]

DN of the user [10068] = [CN = useraccount, CN = Users, DC = subdomain, DC = company, DC = com]

[10068] talk to Active Directory 192.168.102.15

[10068] password for reading strategy for [email protected] / * /dn:CN = useraccount, CN = Users, DC = subdomain, DC = company, DC = com

Bad password count [10068] reading 0

[10068] change password for [email protected] / * / password successfully converted to unicode

[10068] output fiber Tx = 759 bytes Rx = 2959 bytes, status =-1

End of session [10068]

If 'asauser' is not yet a member of the "account operators" group, add to this group.

There is an enhancement request to do this work without special privileges, see:

CSCtq54856    ENH: Support for the management of w/o rights connection LDAP Admin DN password

HTH

Herbert

EDIT:

Just to further clarify for those hitting this thread in the search for a solution to the same problem: the 'asauser' in the above example is the user who is configured in the ASA LDAP settings:

AAA-server ldap protocol ldap

AAA-server ldap (inside) host 10.0.0.2

Server-port 636

LDAP-base-dn cn = users, dc = CISCOTEST, dc = COM

LDAP-login-password *.

LDAP-connection-dn asauser

enable LDAP over ssl

microsoft server type

While this user (the one defined with ldap-connection-"dn") must be in the group account opertators, not all vpn users.

Tags: Cisco Security

Similar Questions

  • Users cannot change password for 802.1 x and implementation of ISE

    Hi all

    We have implemented cisco ISE 1.1 for a week and we notice that Microsoft active directory the user cannot change password there when it expired.

    We store all user account in Microsoft active directory for authentication and ISE is mapped with Microsoft active directory. Normally, when your expired password Microsoft active directory ask you to change your password, but in our case cisco switch or 802. 1 x do not allow communication with active directory before giving access to the network. Is this a configuration error or cisco do not support this?

    Best regards.

    Hello

    I have the same problem, did you find a solution?

    Thank you

  • vRO - AD plugin - defined attributes of user - password never expires and user cannot change password

    Hello
    Could someone suggest how can I set the object AD attributes: User to have two active parameters?

    Password never expires

    The user cannot change the password

    I guess I'll use the .setAttribute method, but I can't find anywhere a useful example/document that could help me to do so.

    Thank you

    Kamil

    OK, I found help in the thread:

    Properties of creation of account user AD - cannot change password and password never expires

    The closure of this one.

  • The user cannot change password

    Hi all

    I have my users set up in the .rpd have to change their password every 90 days. My first user just hit this limit. She received an ODBC error that says the password has expired and please change the password. Unfortunately - there is no room available to do so. I think that OBIEE would come with a change of password area - but it isn't. I also searched on OTN and the documentation and cannot find anywhere that solves this problem. I think it's an easy fix - but can't seem to find where if users are allowed to change their password. Any ideas?

    Thank you!

    You must enable the link change password to users.
    read this blog
    http://obiee101.blogspot.com/2008/08/OBIEE-change-password.html

    -Madan

  • Authorized DBA cannot change password

    In Oracle Vault (v11), I got the role of Dv_Acctmgr by the owner of the vault.  I'm a DBA.  I am still unable to change a password for a user to db.  The id of the current owner of the Dv_Acctmgr cannot change it either.  Any suggestions/tips on how to diagnose and fix this?

    Found the solution.  has had to cancel the user ID DV_SECANALYST.

  • AIP-SSM20: cannot change password - please help

    Reset the password using the hw-module command.  But now I can't change the default password of cisco.  she rejects any combination of password that I tried, uppercase, lowercase, numbers and the characters not alphanumeric.  It's probably requrement of password policy that I put forward.  How can I work around this problem and restore default setting?

    Thank you.

    Login: cisco

    Password:

    You are required to change your password immediately (years)

    Change password for cisco

    (current) password:

    New password:

    INCORRECT PASSWORD: is too simple

    New password:

    INCORRECT PASSWORD: is too simple

    New password:

    Model serial number of map mod

    --- -------------------------------------------- ------------------ -----------

    1. ASA 5500 Series Security Services Module-20 ASA-SSM-20 JAF1204AQHT

    MAC mod Fw Sw Version Version Version Hw address range

    --- --------------------------------- ------------ ------------ ---------------

    1 001e.7a36.7aba to 001e.7a36.7aba 1.0 1.0 (11) E4 2 7.0 (5A)

    The Application name of the SSM status Version of the Application of SSM mod

    --- ------------------------------ ---------------- --------------------------

    1 FPS up to 7,0 E4 (5A)

    Data on the State of mod aircraft compatibility status

    --- ------------------ --------------------- -------------

    1 up Up

    Hello

    You can try a more complex password.

    was soon 1

  • Cannot change the user name of the forum

    If you go to the user control panel, under the profile box, there is a place where we can make our forum user name - which would be nice because this stuff USER-xyz is ridiculous.

    Unfortunately, it does not work because you must put a valid e-mail address in order to change your user name... but you can't because it lacks the text box that you are supposed to type in the e-mail address field.

    Can a mod contact someone who can take a look at this?

    I too have this problem. I really wish that Sony would like to address this forum some to make it easier to use.

  • W500 4061, cannot change password, noise AC adapter

    Hello, everyone.

    I am can not change the password for ME WOOD. The "admin" password is accepted, but reports 'ERROR' as intrel change password rejected. Can someone give me some light on it

    I have an Intel management Aegina BIOS extension version v4.04.0006 and Intel ME fireware version 4.0.3.1124.

    BTW, can someone tell me how do not change at the start of the DVD, the brand of DVD some noise when start and according to me, that's not healthy for her.

    The power adapter were also low noise frenqency, something in common?

    I had the same expirence with Intel ME password. You must choose a password that is sophisticated like me! Admin! 00 with uppercase and lowercase and special characters

  • Cannot change log users on or off error: Services the customer has disabled the display of welcome and g fast easy

    Original title: XP users

    After you have reinstalled XP, I tried to change the users connect or not, but when I do I get the msg: Services the customer has disabled the Welcome screen and fast switching.  To restore these features, you must uninstall the Client Services for NetWare.  I can't find service to customer or NewWare so I can uninstall.  How do you find the Client Services for NetWare?

    Hello

    I suggest you to follow the steps below and check if it helps.

    Error Message When you try to turn on welcome screen or fast user switch: http://support.microsoft.com/kb/315347

    Hope this information is useful.

  • Change password user account

    Original title: change password

    I need to change my password. And I don't know how?  grateful for the help with my problem

    Hello

    This will help you:

    "Change your Windows password"

    http://Windows.Microsoft.com/en-us/Windows-Vista/change-your-Windows-password

    "How to change your password in Windows Vista"

    http://pcsupport.about.com/od/tipstricks/HT/chgpassvista.htm

    See you soon.

  • Still can not log in to windows XP, cannot change the user name, or start in what either.

    locked out of windows xp.  happens only with the window prompted for a user name and password.  the user name is the name of the previous owner and does not know the password.  It is as far as the computer goes.  It's not my computer (thank God), but I need to know what to do to help the girl he has.  The computer was rebuilt and bought by it.  It's a computer dell laptop.

    What I can do.  I can't connect what either.  I can't edit or create a new user name and password for it either.  I can't get in any other mode.  You have any suggestions?

    Hello

    Microsoft cannot help you to reset, change or delete passwords. For more information, see the article mentioned below.

    Microsoft's strategy concerning lost or forgotten passwords

    http://support.Microsoft.com/default.aspx/KB/189126

  • Windows 7 Home Premium - cannot change the user name in the authentication dialog box

    I was hoping someone might be able to answer a question on how to get a computer running Windows 7 Home Premium to display both the username and password fields when attempting to authenticate on another Windows computer.

    Here's the situation: allow us that the leaders and other members of the staff allowed our Organization to establish a VPN connection to our corporate network (via Fortinet Forticlient, for what it's worth.)  Once the VPN connection is established, on the remote computer, the user must be able to access the UNC path to our file (\\servername\share) server.

    Because the remote user has not yet authenticated on the domain Active Directory of business, a dialog box should appear to the user input a user name and password.  Enter the user name (domain\username) and password and share should open, and the user must then be able to access the files in the share.

    I (and several other members of the staff) have been using this method successfully to access files via the VPN connection, and it works very well.  However, it does not work whenever the President of the company will connect to the VPN from his computer at home.

    Whenever the President connects the VPN and attempts to access the UNC path, he reports that the dialog box which appears on his computer at home has only one field for a password; the user name field appears to be on his local user account, and it doesn't have the ability to change.  (I have him asked if there is an option 'use authentication information', and he declares that there is not just a dialog box with a single field, the field of password.)

    The President is running Windows 7 Home Premium on his computer at home, so I thought that the problem could be because he was running this edition of Windows.  However, I have installed VPN client and test the connection on the server share file using the computer of my wife, who is also running Windows 7 Home Premium, and I received the two fields as expected authentication dialog box and has been able to authenticate to the domain successfully and open files from the share with no problems.

    Does anyone have recommendations on what I can try to allow the President to authenticate successfully to our server share?  I am confused, and it is eager to be able to get remote access to files on his home computer.

    Hello

    Please contact Microsoft Community.

    I suggest you to ask your question in the Technet Forums, where we are the support technicians who are well equipped with the knowledge on these issues. Please visit the following link to go to them and post your query there:

    https://social.technet.Microsoft.com/forums/Windows/en-us/home?category=w7itpro

    Have a great day.

  • Windows 7 Administrator account cannot change password ("the password entered is incorrect")

    I have a user account on my computer. This is an administrator account. I can connect with my administrator password and I am in this account as I write this. When I try to change the password in the control panel-> user accounts-> change your Windows password I get my password for the existing administrator and then the new twice, but I get the error message "the password entered is incorrect. Please re-enter your current password. »

    • I entered the current password is the correct (otherwise I wouldn't be connected to the account).
    • I made repeated tests, so I can exclude typos
    • the caps lock is disabled

    How can I work around this problem to change my password? "Current password" means something other than the password I used to access my account?

    Is it possible to display the version of distorted of the password so that I can use it when you change the account password?

    There is no way to display an existing password.

    To dig a little deeper, I suggest you do this:

    1. Create an alternative admin account. You should have it anyway, even that you have a spare House key, because you'd be in diabolical trouble, if something went wrong with your one and only the admin account.
    2. Test the alternative account.
    3. Play with the password for your existing account. If you get locked, use the alternative account to reset the password.

    Check out this link for a tip force a provision of specific keyboard during logon.

  • Change password user Admin in Publisher

    Hi, I want to know how to change the password for the admin user in publisher.
    Thank you...

    Please check Doc ID 566277.1 on support.oracle.com, it has detailed instructions to reset the password of admin BI publisher.

    Thank you

    Wilson

  • change password user dyd thr

    How can I change the password for the sys user?... I want to change the password so that no one else besides me can use the sysdba account

    change or add a parameter in the file sqlnet.ora None

    SQLNET.authentication_services = (NONE)

    then check;

    SQL > SELECT * FROM V$ PWFILE_USERS;

Maybe you are looking for

  • How migrations (El Capitan) not come to the photo library?

    Hello I want to use the Migration Wizard to move my user account for my MacMini BUT put the photo library on a separate hard disk from the system drive. My MacMini has two internal drives, the library is huge. The MacBook (early 2008 - running Snow L

  • Satellite freezes 4600 Pro for a while

    I have a satellite pro 4600 and during operation normal and with out any warning the computer hangs the mouse does not move, numlock won't turn.And then with any alert the computer will work fine again. I noticed that the CPU fan is not working at al

  • HP Compaq s 2230: HP 2230 s BIOS password

    Hello I have a s 2230 HP Compaq My problem is that it has a BIOS password. because I replaced the hard drive I have now a notebook with nothing except a bios password so. LARGE. Please can someone help me n/p = FU312EA #UUZ

  • How to fix a test failure short DST?

    I have an e1405 dell with windows xp home edition and the last time I tried to turn it on crossed the screen of windows xp and then came to a black screen that says "no bootable disk" and gave me the opportunity to try to restart or run the Setup uti

  • HP Beats P017AU K5C38PA #AR6 15: location ram 2 undetected Ram 2x8GiB only 1x8GiB detected

    HP Beats 15 P017AU K5C38PA #AR6, I bought this 'large Tablet' of the retailer. I upgraded the 1 x 2 x 8 GiB 8GiB RAM memory. BIOS detect 16 Gio of RAM in Total, but usable only 7.3 GiB. My Aries suspect is not well versed, I disasmbly once again the