A fix is available
APAR status
Closed as program error.
Error description
Many LDAP servers support special characters (like German umlauts or French characters with accents) in passwords. LDAP servers use UTF-8 for strings per design. If secldapclntd is configured with authtype:ldap_auth in /etc/security/ldap/ldap.cfg secldapclntd delegates password authority to the LDAP server. Most AIX instances do not use a full UTF-8 environment so a string handled is normally no UTF-8 string. If secldapclntd is configured with enableutf8_xlation:yes "secldapclntd" handles the conversion between local AIX encoding and UTF-8 encoding. This works fine for attributes but fails if the string to convert is a password login string. So a login always fails as soon as the password string consists of a character which would need conversion.
Local fix
Circumvention: avoid passwords with non-7bit-ascii characters
Problem summary
LDAP user fails to login into a system when the password has a special character using ldap_auth.
Problem conclusion
Special characters in user's password is handled before sending to the LDAP server for successful user authentication.
Temporary fix
Comments
6100-08 - use AIX APAR IV70465 6100-09 - use AIX APAR IV70392 7100-02 - use AIX APAR IV70463 7100-03 - use AIX APAR IV69437
APAR Information
APAR number
IV70465
Reported component name
AIX 610 STD EDI
Reported component ID
5765G6200
Reported release
610
Status
CLOSED PER
PE
NoPE
HIPER
NoHIPER
Submitted date
2015-03-03
Closed date
2015-03-03
Last modified date
2015-09-30
APAR is sysrouted FROM one or more of the following:
APAR is sysrouted TO one or more of the following:
Fix information
Fixed component name
AIX 610 STD EDI
Fixed component ID
5765G6200
Applicable component levels
R610 PSY U868373
UP15/09/18 I 1000
PTF to Fileset Mapping
U868373 bos.rte.security 6.1.8.20
[{"Business Unit":{"code":"BU058","label":"IBM Infrastructure w\/TPS"},"Product":{"code":"SG11Q","label":"AIX 6.1 HIPERS, APARs and Fixes"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"610","Edition":"","Line of Business":{"code":"LOB08","label":"Cognitive Systems"}},{"Business Unit":{"code":"BU054","label":"Systems w\/TPS"},"Product":{"code":"SSMV87","label":"AIX 6.1 Enterprise Edition"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"610","Edition":"","Line of Business":{"code":"LOB08","label":"Cognitive Systems"}},{"Business Unit":{"code":"BU058","label":"IBM Infrastructure w\/TPS"},"Product":{"code":"SSMVAX","label":"AIX Express Edition"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"610","Edition":"","Line of Business":{"code":"LOB08","label":"Cognitive Systems"}},{"Business Unit":{"code":"BU054","label":"Systems w\/TPS"},"Product":{"code":"SSAUMY","label":"IBM AIX Enterprise Edition"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"610","Edition":"","Line of Business":{"code":"LOB08","label":"Cognitive Systems"}},{"Business Unit":{"code":"BU058","label":"IBM Infrastructure w\/TPS"},"Product":{"code":"SG11Q","label":"AIX 6.1 HIPERS, APARs and Fixes"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"610","Edition":"","Line of Business":{"code":"LOB08","label":"Cognitive Systems"}},{"Business Unit":{"code":"BU058","label":"IBM Infrastructure w\/TPS"},"Product":{"code":"SG11R","label":"APARs - AIX 7.1 environment"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"610","Edition":"","Line of Business":{"code":"LOB08","label":"Cognitive Systems"}}]
Document Information
Modified date:
17 December 2021