Forum Discussion
1 Reply
Hi Steph,
What software version are you using? And could it be the case that the AD query is failing? And is the APM able to perform the following LDAP query to retrieve the password complexity settings:
Considerations for the 'Complexity check for Password Reset' setting
When the Complexity check for Password Reset setting is enabled, the BIG-IP APM system will use a Lightweight Directory Access Protocol (LDAP) searchRequest packet to attempt to retrieve the user's Distinguished Name (DN) by using the sAMAccountName attribute as a filter (sAMAccountName=<user name>). Therefore, if the user name (CN) entered in the BIG-IP APM system (during the login attempt) does not match the sAMAccountName attribute, the LDAP searchRequest packet will fail when retrieving the user DN.
As a result, the user cannot change their password and the BIG-IP APM system logs messages similar to the following example to the /var/log/apm file:
Session variable 'session.ad.last.errmsg' set to 'Password policy check error: can't get required user attribute'
See KB16806 for more information.
Cheers,
Kees