Description | This article describes the cause for the authentication failure error 'Remote LDAP user authentication from (null) with no token failed: invalid password', which appears even when the correct password is used. A solution is provided. |
Scope | FortiAuthenticator. |
Solution |
Authentication fails when the Remote LDAP user attempts to log in, and the following error appears in the FortiAuthenticator logs: 'Remote LDAP user authentication from (null) with no token failed: invalid password.' The user has been successfully imported from GWS LDAP into FortiAuthenticator, and the password used is confirmed to be correct. Radius debug can be taken as below:
https://<FAC IP>/debug/radius/
2025-04-15T17:13:01.137924+05:30 AL-FortiAuthenticator radiusd[12971]: (10138) facauth: LDAP user found: test The issue needs to be investigated on the LDAP server, as the 'Insufficient Access' error indicates that the server is rejecting the operation due to a lack of necessary permissions. This typically happens when the operation is attempted using a DN (Distinguished Name) that doesn't have adequate privileges. To resolve this, the required permissions must be granted on the LDAP server.
2025-04-16T15:08:39.538481+05:30 AL-FortiAuthenticator radiusd[12971]: (62021) facauth: LDAP user found: test
Related article: Troubleshooting Tip: How to debug FortiAuthenticator Services |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.