Technical Tip: Unable to fetch user groups information on FSSO Collector agent
| Description | This article describes the situation where the user is unable to fetch user group information on the Fortinet Single Sign-On Collector Agent Service. |
| Scope | Fortinet Single Sign-On Collector Agent. |
| Solution | When there is a service account/administrator password getting expired/reset/renewed on the Active Directory results in the FSSO collector agent failing to get group information.
The collector agent debug shows the following messages, where the LDAP bind fails.
02/11/2022 11:47:58 [ 5152] ldaplib::ldap_bind_s failed, server:fermion-kvm52.rishi.com error code:0x31.
'LDAP error 0x31' = Invalid Credentials/Bind Failure.
This means that the Collector Agent is trying to authenticate to the domain controller, but the bind account is failing.
In most cases, it is caused by incorrect service account credentials. The FSSO LDAP account password may have changed or expired.
Quick Fix: In the FSSO Collector Agent.
 
Note: If the Advanced setting shows blank for LDAP configuration, it means Fortinet Single Sign-On uses Service account credentials. It can be validated under 'service.msc', Open services--Fortinet Single Sign-on Agent service--Properties--Logon, correct with credentials.
|





