GFI Software

Welcome to the GFI Software community forum! For support please open a ticket from https://support.gfi.com.

Home » GFI User Forums » Kerio Control » AD Users Cannot login
AD Users Cannot login [message #113728] Sat, 24 May 2014 14:07 Go to next message
farshid is currently offline  farshid
Messages: 2
Registered: May 2014
Hi.I have installed Kerio Control 8.3 and I'm trying to enable Active Directory user authentication. It seems to AD connection is OK and all user added to Kerio successfully but when users try to login, " Incorrect username or password" appears on screen. When I check the logs section, there is a log message that says password is incorrect. I checked the user's password in AD 2008 and it was correct.
Re: AD Users Cannot login [message #113736 is a reply to message #113728] Sun, 25 May 2014 21:19 Go to previous messageGo to next message
ak.sabokdasti is currently offline  ak.sabokdasti
Messages: 1
Registered: May 2014
i have the same problem. Security log message says:
Invalid password for NT/Kerberos user [any users]
Re: AD Users Cannot login [message #113756 is a reply to message #113736] Tue, 27 May 2014 08:14 Go to previous messageGo to next message
mlee (Kerio)
Messages: 211
Registered: October 2012
Location: Sydney
I assume you have read this knowledge base article:
http://kb.kerio.com/product/kerio-control/microsoft-active-d irectory-apple-open-directory/connecting-kerio-control-to-di rectory-service-1277.html

Have you tried enabling user authentication in debug log to get more info?


PTSD. BP. OCD. ASPD. BPD. Certified.
Re: AD Users Cannot login [message #113765 is a reply to message #113728] Tue, 27 May 2014 16:03 Go to previous messageGo to next message
farshid is currently offline  farshid
Messages: 2
Registered: May 2014
I found the problem. It was because of time difference in servers despite of joining kerio machine to domain. It was supposed to sync its time with dc but it wasn't. Anyway problem get solved and everything works just fine.
Re: AD Users Cannot login [message #120033 is a reply to message #113765] Mon, 16 March 2015 12:07 Go to previous messageGo to next message
aidin
Messages: 3
Registered: March 2015
I am experiencing the same problem and my server time/date do match!
Do you have any other ideas?
Re: AD Users Cannot login [message #120035 is a reply to message #120033] Mon, 16 March 2015 12:25 Go to previous messageGo to next message
vtripp is currently offline  vtripp
Messages: 616
Registered: September 2009
Location: Cambridge
Hi Guys,

We had a couple of customers report AD auth breaking to control. This appears to have been caused by a Microsoft update:

"Microsoft KB3002657 Update for Windows 2003 installed March 11 2015.
This KB3002657 Update breaks NTLMSSP-authentification."

However this update did go to other Windows Server versions so check which Microsoft updates were installed recently.

All the best,
Vicky
Re: AD Users Cannot login [message #120038 is a reply to message #120035] Mon, 16 March 2015 13:17 Go to previous messageGo to next message
aidin
Messages: 3
Registered: March 2015
Thanks for the prompt reply

Mine is a Windows Server 2012 R2 environment which is instantly updated. I have recently installed Kerio Connect for evaluation and had the same issue from begining.
But, it is making me more worried if updating Windows may result in this type of severe issues!!
I am seeing the following error in Kerio Security log:

HTTP/WebMail: Authentication failed for user email<_at_>domain.com. Attempt from IP address xx.xx.xx.xx. External authentication service rejected authentication due to invalid password or authentication restriction.
Re: AD Users Cannot login [message #120039 is a reply to message #120038] Mon, 16 March 2015 13:45 Go to previous messageGo to next message
aidin
Messages: 3
Registered: March 2015
IT WORKED!!
I just added my local domain name to the advanced tab under Kerberos field!
I don't remember this one to be included in Kerio Connect documents!
Re: AD Users Cannot login [message #120049 is a reply to message #120039] Mon, 16 March 2015 15:36 Go to previous message
Kerio/GFI Brian is currently offline  Kerio/GFI Brian
Messages: 852
Registered: March 2004
Location: California
Thanks Aidin for confirming that you found a resolution. Regarding your point on the documentation, I also had a difficult time locating this information. I expect that it should be covered in KB 1130. I'll notify our doc team to make sure that it gets included. You'll notice in this forum post http://forums.kerio.com/m/119063/#msg_119063 that the forum user had the same problem, so it's not uncommon.

Brian Carmichael
Instructional Content Architect
Previous Topic: webpage not open
Next Topic: Lock IP range (all ports, all) , and only after authentication, release all
Goto Forum:
  


Current Time: Sun Apr 02 11:48:22 CEST 2023

Total time taken to generate the page: 0.03580 seconds