Security

last person joined: 23 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Clearpass timeout when AD is prompting for a password change?

This thread has been viewed 3 times
  • 1.  Clearpass timeout when AD is prompting for a password change?

    Posted Jul 29, 2014 05:23 PM

    Anyone come across this? We have users at remote sites logging into IAP225. The new users that have not logged into the domain before have a temp password. In AD we have it set to prompt for change of password as soon as they login with the temp.

    This part happens to the user and while they take 2 minutes to figure out what password they want to use, they enter it, and then they get a no logon servers available. 

     

    In clearpass it shows this under alerts for their login attempt. This is the first time i have seen this as well:

     

    MSCHAP: AD status: Password-Change: No Password-Change-Error: Password restriction .

    MSCHAP: AD status: Password-Change: No Password-Change-Error: Password restriction .

    MSCHAP: AD status: Password-Change: No Password-Change-Error: Password restriction .MSCHAPL Password change failed

    EAP-MSCHAPv2: User authentication failure

     

     

     

    Is there some timeout window with clearpass and if so where would this setting be located?

     



  • 2.  RE: Clearpass timeout when AD is prompting for a password change?

    Posted Jul 29, 2014 05:59 PM

    in my CPPM 6.2, the default domain server time out is 10 seconds:

    Capture.PNG



  • 3.  RE: Clearpass timeout when AD is prompting for a password change?

    EMPLOYEE
    Posted Jul 29, 2014 06:14 PM
    You'll see the same behavior if the user doesn't accept the certificate immediately. I don't think there is a solution for that. The EAP process is time sensitive.

    Are you doing machine authentication while the device is at the login screen? This is the best way to handle new users logging in.