Connectrix: LDAP Server is Reachable, but Fails to Validate or Authorize the User Account
Summary: The error dump reports the event code SEC-1347: "LDAP server is reachable but failed to validate or authorize the user account" followed by an authentication failure.
Symptoms
Error dump reports event code:
2022/03/24-12:12:39, [SEC-1347], 47583, SLOT 2 | FID 128, INFO, Dell-LabSwitch1, LDAP server 10.xxx.xxx.05 reachable, but failed to validate or authorize the user account 'admin'. 2022/03/24-12:12:39, [SEC-1193], 47584, SLOT 2 | FID 128, INFO, Dell-LabSwitch1, Security violation: Login failure attempt via HTTPS. IP Addr: 10.xxx.xxx.12.
Cause
SEC-1193 Indicates a specified login security violation was reported. The wrong password was used while trying to log in through the specified connection method; the login failed.
When a management software or third-party tool tries to log in to the switch, it goes to the AD first, and then either there is not an "admin" account in the AD server or the user ID or password used by management software or the third-party tool is incorrect.
Resolution
Ensure that the specified user is added to the AD server configuration and that the user and password entered for the specified LDAP server is correct.
Resolving the authentication failure issue stops the streaming of SEC-1347 events under errdump.
This issue may also occur for RADIUS and TACACS+ if those are configured as a part of the AAA configuration.