SSL-VPN: LDAP Users Can't Change Password

Description

LDAP users connecting through SonicWall’s SSL-VPN NetExtender cannot reset or change their passwords. This issue often occurs due to misconfigure LDAP settings or insufficient permissions for the LDAP bind user.

Cause

Root Causes

  1. LDAP Bind User Privileges: The LDAP bind user is not bound with administrative privileges, as shown in TSR logs with the entry:

    Bound as administrative user: No

    This indicates the bind account does not have the required permissions to manage password changes.

  2. Delegated Permissions: Proper delegation has not been set up for the LDAP bind user to reset passwords in Active Directory (AD). Additionally, inheritance may not be enabled for user objects.

  3. TLS Protocol: Password changes over LDAP require the connection to be secured using TLS. If TLS is not enabled, the operation fails.

1. Verify LDAP Bind User Privileges

  • Open the TSR logs in SonicWall.

  • Search for the entry: Bound as administrative user: No.

  • If the value is “No,” the bind user lacks administrative privileges.

2. Configure Administrative Privileges

Option 1: Add Bind User to Domain Admins

  1. Open Active Directory Users and Computers (ADUC).

  2. Add the LDAP bind user to the Domain Admins group.

Option 2: Manually Configure Administrative Privileges

  1. In ADUC, locate the LDAP bind user account.

  2. Open the Attribute Editor.

  3. Set the adminCount attribute value to 1.

  4. Image

3. Delegate Control for Password Reset

  1. Open ADUC on the Windows Server.

  2. Right-click on the domain name and select Delegate Control.

  3. In the Wizard:

    • Add the LDAP bind user.

    • Select Reset user passwords and force password change at next logon.

  4. Complete the wizard.

Image

Image

 

Image

 

image

 

Enable Inheritance for User Objects:

  1. Check the Advanced Security Settings for user accounts.

  2. Enable Inheritance to propagate delegated permissions to all user objects.

    • Without inheritance, the LDAP bind user cannot reset passwords for existing accounts.

image

 

Image

 

Note: Delete the LDAP integration , reconfigured and bind with same user account.

Related Articles

  • SonicOS 8.1.0 FAQ
    Read More
  • SonicWall GEN8 TZs and GEN8 NSas Settings Migration
    Read More
  • Getting started with SonicWall firewalls
    Read More
not finding your answers?