sk147417 - Users are not authenticated when an identity source provides the login name in 'User Principal Name' format "user@domain"
Users are not authenticated when an identity source provides the login name in 'User Principal Name' format "user@domain"
Product: Identity Awareness
Version: R80.10 (EOS), R80.20 (EOS), R80.30 (EOS), R80.40 (EOS), R81 (EOS), R81.10 (EOS), R81.20
Last Modified: 2023-12-06
Symptoms
- When an identity source provides the login name in the 'User Principal Name' format (as in, "user@domain"), and this identity source has a default login attribute defined (typically
sAMAccountName), users encounter authentication issues and they are unable to authenticate successfully.
Cause
A 'User Principal Name' formatted name will not match the content of the login attribute sAMAccountName and vice versa. To keep the default login attribute definition and allow users to authenticate successfully, split the 'User Principal Name' (as in, username@domain) into the user name and domain based on the position of '@'.
Solution
This problem was fixed. The fix is included in:
- Jumbo Hotfix Accumulator for R81 starting from Take 89
- Jumbo Hotfix Accumulator for R80.30 starting from Take 76
- Jumbo Hotfix Accumulator for R80.20 starting from Take 103
- Jumbo Hotfix Accumulator for R80.10 starting from Take 225
If you choose not to upgrade, Check Point can supply a Hotfix. Contact Check Point Support to get a Hotfix for this issue. A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.
For faster resolution and verification, please collect CPinfo files from the Security Management Server and Security Gateways involved in the case.
By default, if the PDP receives a 'User Principal Name' representation of the user name and domain (as in, username@domain), it would NOT split the username from the domain and the input remains as received.
The Hotfix above allows you to change the default behavior for the different identity sources and split the user name from the domain based on the '@' position.
As part of the procedure described below, the file: identity_awareness_custom_settings.C is edited.
By editing it, you can add/change various identity awareness configurations. The file should be edited on the Security Management Server and is passed to the Gateway by a policy push. As the procedure requires you to edit the identity_awareness_custom_settings.C file, it is recommended to back up the original file to save any custom configurations.
To change the default behavior for an identity source and split the user name for the domain:
- On the Security Management Server, edit the file
$FWDIR/conf/identity_awareness_custom_settings.Cby following these steps:Back up the following file: $FWDIR/conf/identity_awareness_custom_settings.C If the environment is a Multi-Domain Management Server, make sure that you are in the proper CMA:
# mdsenv <desired CMA> # mcdEdit the file and add the following section: "
user_at_domain_client_types_to_split".This section contains all the identity sources for which the customer can configure a split (vpn, ida-agent, radius etc.). By default, the split configuration is disabled for all identity sources, as there is a hash mark at the beginning of all the lines (as in, #identity-collector). To configure a split for an identity source, remove the hash mark at the beginning of the relevant line and save the file.
For example:
To make the input received in UPN format split when received from identity source radius according to the '@' position, the section "
user_at_domain_client_types_to_split" should change from the default configuration:
[user_at_domain_client_types_to_split] #In this section you can add identity sources for which to split the user name and Domain according to the position of @ #captive-portal #ida-agent #vpn #ad-query #multihost-agent #radius #ida-api #identity-collector [/user_at_domain_client_types_to_split]
To the below configuration:
[user_at_domain_client_types_to_split] #In this section you can add identity sources for which to split the user name and Domain according to the position of @ #captive-portal #ida-agent #vpn #ad-query #multihost-agent radius #ida-api #identity-collector [/user_at_domain_client_types_to_split]
- Install the policy on the necessary Security Gateway/s.
Notes:
- Make sure that the change is received by the Gateway by verifying that the change also appears on the Gateway in the
$FWDIR/database/identity_awareness_custom_settings.Cfile after policy installation. - The file's path on the Security Management is:
$FWDIR/conf/identity_awareness_custom_settings.C - The file's path on the Security Gateway is:
$FWDIR/database/identity_awareness_custom_settings.C
NOTE
This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.