Skip to main content
jcastellanos
Staff
Staff
November 21, 2024

Troubleshooting Tip: Unable to log in to the GUI using an LDAP user due to password length

  • November 21, 2024
  • 0 replies
  • 213 views

Description

This article describes how to resolve a scenario where some users can log in to the GUI but others cannot.

Scope

FortiWeb v7.x, FortiWeb v8.x.

Solution

In some scenarios, certain administrator LDAP users are able to connect to the GUI while other users in the same LDAP group cannot.

To analyze the behavior, it is recommended to start a packet capture while reproducing the issue.

Go to Network -> Packet Capture -> Create New.

6b743b6d.png


Fill out the fields towards the LDAP server.

e39434c9.png


Once the capture has been created, select the play button to start the capture.

c4cebd4b.png


In the packet capture results, it is possible to see that the LDAP server responds with the message 'invalidCredentials'.

2-dlap response.png

 

Looking at the Bind Request shows that the password length is bigger than 64 characters. FortiWeb may be truncating the password sent to the LDAP server.

1-ldap request.png

 

If the password is large, as a workaround, try to use a password shorter than 64 characters and verify if it is possible to authenticate.

Open a TAC support ticket (Support) for further problem analysis if the authentication is still not working.

    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!