sk147417 - Users are not authenticated when an identity source provides the login name in 'User Principal Name' format "user@domain"

Users are not authenticated when an identity source provides the login name in 'User Principal Name' format "user@domain"

Product: Identity Awareness
Version: R80.10 (EOS), R80.20 (EOS), R80.30 (EOS), R80.40 (EOS), R81 (EOS), R81.10 (EOS), R81.20
Last Modified: 2023-12-06

Symptoms

Cause

A 'User Principal Name' formatted name will not match the content of the login attribute sAMAccountName and vice versa. To keep the default login attribute definition and allow users to authenticate successfully, split the 'User Principal Name' (as in, username@domain) into the user name and domain based on the position of '@'.

Solution

This problem was fixed. The fix is included in:

If you choose not to upgrade, Check Point can supply a Hotfix. Contact Check Point Support to get a Hotfix for this issue. A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.

For faster resolution and verification, please collect CPinfo files from the Security Management Server and Security Gateways involved in the case.

By default, if the PDP receives a 'User Principal Name' representation of the user name and domain (as in, username@domain), it would NOT split the username from the domain and the input remains as received.

The Hotfix above allows you to change the default behavior for the different identity sources and split the user name from the domain based on the '@' position.

As part of the procedure described below, the file: identity_awareness_custom_settings.C is edited.

By editing it, you can add/change various identity awareness configurations. The file should be edited on the Security Management Server and is passed to the Gateway by a policy push. As the procedure requires you to edit the identity_awareness_custom_settings.C file, it is recommended to back up the original file to save any custom configurations.

To change the default behavior for an identity source and split the user name for the domain:

  1. On the Security Management Server, edit the file $FWDIR/conf/identity_awareness_custom_settings.C by following these steps:
    1. Back up the following file: $FWDIR/conf/identity_awareness_custom_settings.C If the environment is a Multi-Domain Management Server, make sure that you are in the proper CMA:

      # mdsenv <desired CMA>
      # mcd
      
    2. Edit the file and add the following section: "user_at_domain_client_types_to_split".

      This section contains all the identity sources for which the customer can configure a split (vpn, ida-agent, radius etc.). By default, the split configuration is disabled for all identity sources, as there is a hash mark at the beginning of all the lines (as in, #identity-collector). To configure a split for an identity source, remove the hash mark at the beginning of the relevant line and save the file.

For example:

To make the input received in UPN format split when received from identity source radius according to the '@' position, the section " user_at_domain_client_types_to_split" should change from the default configuration: [user_at_domain_client_types_to_split] #In this section you can add identity sources for which to split the user name and Domain according to the position of @ #captive-portal #ida-agent #vpn #ad-query #multihost-agent #radius #ida-api #identity-collector [/user_at_domain_client_types_to_split] To the below configuration: [user_at_domain_client_types_to_split] #In this section you can add identity sources for which to split the user name and Domain according to the position of @ #captive-portal #ida-agent #vpn #ad-query #multihost-agent radius #ida-api #identity-collector [/user_at_domain_client_types_to_split]

  1. Install the policy on the necessary Security Gateway/s.

Notes:

NOTE

This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.