sk181039 - ioc_feeds changes the username to all lower cases which causes a 401 unauthorized error
ioc_feeds changes the username to all lower cases which causes a 401 unauthorized error
Product
Anti-Virus
Version
R81 (EOS), R81.10 (EOS), R81.20
Last Modified
2025-10-28
Symptoms
- ioc_feeds fails to add. ioc debug ($FWDIR/bin/ioc_feeder -d -f) shows the username was passed in a lower case but username is case sensitive:
[18751 4113409920]@R81_10[16 May 9:28:40] CIOCHTTPFetcher[125] ::trace: [INFO] == Info: Server auth using Basic with user 'anthony'
[18751 4113409920]@R81_10[16 May 9:28:40] CIOCHTTPFetcher[125] ::trace: [INFO] == Info: Authentication problem. Ignoring this.
[18751 4113409920]@R81_10[16 May 9:28:40] CIOCHTTPFetcher[125] ::trace: [INFO] == Info: The requested URL returned error: 401
[18751 4113409920]@R81_10[16 May 9:28:40] CIOCHTTPFetcher[125] ::trace: [INFO] == Info: Closing connection 0
[18751 4113409920]@R81_10[16 May 9:28:40] CIOCHTTPFetcher[487] ::download: [ERROR] curl_easy_perform() failed: HTTP response code said error
[18751 4113409920]@R81_10[16 May 9:28:40] CIOCHTTPFetcher[85] ::fetch: [ERROR] download failed
[18751 4113409920]@R81_10[16 May 9:28:40] CIOCFeed[222] ::doFeed: [ERROR] Fetch failed for usernameIssue
[18751 4113409920]@R81_10[16 May 9:28:40] CIOCFeederManger[1042] ::run: [ERROR] Feed usernameIssue failed
[18751 4113409920]@R81_10[16 May 9:28:40] CIOCFeederManger[1050] ::run: [ERROR] External Indicators processing failed
[18751 4113409920]@R81_10[16 May 9:28:40] CIOCFeederManger[1177] ::logFinalStatus: [INFO] logging "External IOC - External Indicators processing failed
usernameIssue: Failed to fetch feed. Resource: http://172.25.159.6/ip.txt, Reason: HTTP response code said error" severity 3
Solution
This problem was fixed. The fix is included in:
- Check Point Quantum R82
- Jumbo Hotfix Accumulator for R81.20 starting from Take 43
- Jumbo Hotfix Accumulator for R81.10 starting from Take 131
- Jumbo Hotfix Accumulator for R81 starting from Take 99
- Jumbo Hotfix Accumulator for R80.40 starting from Take 211
If you choose not to upgrade, Check Point can supply a Hotfix. Contact Check Point Support to get a Hotfix for this issue.
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.
For faster resolution and verification, please collect CPinfo files from the Security Management Server and Security Gateways involved in the case.
Hotfix installation instructions:
Refer to sk168597 - How to install a Hotfix.
NOTE
This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.
Article Properties
Access Level: General
Status: Approved by TAC
Date Created: 2023-06-02
Last Modified: 2025-10-28
Was this page helpful? Yes No