IBM Support

IV69437: LDAP BASED USER MAY FAIL TO LOGIN WITH SPECIAL CHAR IN PASSWORD APPLIES TO AIX 7100-03

A fix is available

Subscribe

You can track all active APARs for this component.

APAR status

  • Closed as program error.

Error description

  • Many LDAP servers support special characters (like German
    umlauts or French characters with accents) in passwords.
    
    LDAP servers use UTF-8 for strings per design.
    
    If secldapclntd is configured with
    
    authtype:ldap_auth
    
    in /etc/security/ldap/ldap.cfg
    
    secldapclntd delegates password authority to the LDAP
    server.
    
    Most AIX instances do not use a full UTF-8 environment so
    a
    string handled is normally no UTF-8 string.
    
    If secldapclntd is configured with
    
    enableutf8_xlation:yes
    
    "secldapclntd" handles the conversion between local AIX
    encoding and UTF-8 encoding.
    
    This works fine for attributes but fails if the string to
    convert is a password login string.
    
    So a login always fails as soon as the password string
    consists of a character which would need conversion.
    

Local fix

  • Circumvention:
    avoid passwords with non-7bit-ascii characters
    

Problem summary

  • LDAP user fails to login into a system when the password has a
    special character using ldap_auth.
    

Problem conclusion

  • Special characters in user's password is handled before sending
    to the LDAP server for successful user authentication.
    

Temporary fix

Comments

  • 6100-08 - use AIX APAR IV70465
    6100-09 - use AIX APAR IV70392
    7100-02 - use AIX APAR IV70463
    7100-03 - use AIX APAR IV69437
    

APAR Information

  • APAR number

    IV69437

  • Reported component name

    AIX V7.1

  • Reported component ID

    5765H4000

  • Reported release

    710

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Submitted date

    2015-02-12

  • Closed date

    2015-02-27

  • Last modified date

    2015-09-30

Fix information

  • Fixed component name

    AIX V7.1

  • Fixed component ID

    5765H4000

Applicable component levels

  • R710 PSY U867640

       UP15/05/19 I 1000

PTF to Fileset Mapping



Document information

More support for: AIX Enterprise Edition

Software version: 710

Operating system(s): AIX

Reference #: IV69437

Modified date: 30 September 2015