sk181429 - When a user changes AD group, their access role is not updated
When a user changes AD group, their access role is not updated
Product: Identity Awareness
Version: R80.40 (EOS), R81 (EOS), R81.10 (EOS), R81.20
OS: Gaia
Platform: All
Last Modified: 2024-04-29
Symptoms
- When switching an AD user to a different AD group, they may still retain access to resources from their previous group, effectively being in both groups simultaneously. But this does not show in the PDP monitor.
- The AD user is still seen in the old AD group.
- The Access role is not updated.
- Error from
vpnddebugs:
[vpnd 22266 4074710976]@l909eoaa0102a[28 Feb 15:52:21][CPLDAPSDK] ldap_async_do_search: Error: ldap_search_ext
[vpnd 22266 4074710976]@l909eoaa0102a[28 Feb 15:52:21][CPLDAPSDK] OPSEC_ldap_search: do search failure
Cause
When changing the AD user group, the PDP does not update the access roles.
Solution
This problem was fixed. The fix is included starting from:
- Jumbo Hotfix Accumulator for R81.20 starting from Take 43
- Jumbo Hotfix Accumulator for R81.10 starting from Take 106
- Jumbo Hotfix Accumulator for R81 starting from Take 89
- Jumbo Hotfix Accumulator for R80.40 starting from Take 198
After installing fix PRHF-28702 the following steps are needed -
To enable, Check Point Security Gateway, run:
# ckp_regedit -a SOFTWARE/CheckPoint/VPN1 use_only_identity_provider_groups -n 1install policy
To disable, Check Point Security Gateway, run:
# ckp_regedit -d SOFTWARE/CheckPoint/VPN1 use_only_identity_provider_groupsinstall policy
To view, run:
# ckp_regedit -p SOFTWARE/CheckPoint/VPN1
Check Point recommends to always upgrade to the Recommended version (Security Gateway / VSX / Security Management Server / Multi-Domain Security Management Server / SmartConsole).
If you choose not to upgrade, contact Check Point Support to get a Hotfix for your version.
A Support Engineer will make sure the Hotfix is compatible with your environment before providing it.
NOTE
This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.