cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
523
Views
1
Helpful
7
Replies

Login Failures after Upgrade to 2.11.0.4

millerlw
Level 1
Level 1

Good morning,

I upgraded our collector to 2.11.0.4 this morning and now we are not able to login with our credentials.  I am still able to login to the CLI with the collectorlogin, admin and root, but login to the GUI is not possible.  Three of us have tried to login, it fails, and ISE tells us: 24408 User authentication against Active Directory failed since user has entered the wrong password.  The system restarted itself twice for the upgrade, and I restarted it again after it failed to allow us to login, but nothing has worked.

Thank you,

Leonard

7 Replies 7

millerlw
Level 1
Level 1

Anybody?  Bueller?

share with me your cco id, company name on SNTC portal 

 

tjw-msts
Level 1
Level 1

following the upgrade to 2.11.0.4 GUI logins using RADIUS are failing.  GUI login using the 'admin' account or a local user account work as expected.  Running the 'Test Remote Server' from the 'Manage Remote Authentication Servers' area is successful but GUI login using the same credentials as in the test fails.

millerlw
Level 1
Level 1

The solution for now is to continue using local logins, unless you have a Smart Assist contract and can open a TAC case.  Adias said he would pass the issue on to people that could further look into it and I have no reason to doubt him, so hopefully they have a solution soon.

Leonard

Hello. Same problem here:

I tried rebooting, quitting the config and adding again. Also I will tried changing the SHARED KEY, Authentucation Method and changing TACACS to RADIUS. Also I deleted the user and added again

In the configuration test box the result is OK (Authentication Successful) but in the login page the error is Invalid credentials.

The problem is only with the remote user. Local user is working propertly.

Thanks in advance!

In Cisco ISE I have the same error:

Event5400 Authentication failed
Failure Reason24408 User authentication against Active Directory failed since user has entered the wrong password
ResolutionCheck the user password credentials. If the RADIUS request is using PAP for authentication, also check the Shared Secret configured for the Network Device
Root causeUser authentication against Active Directory failed since user has entered the wrong password

 

2025-03-21 15:10:35,065 [https-jsse-nio-8001-exec-8] INFO com.cisco.cspc.server.integration.ServerConnector - Remote Authentication Failed for the user: XXXXXX
com.pari.api.InvalidUserIdOrPasswordException: Remote Authentication Failed for the user: XXXXXX
at com.pari.nm.modules.session.UserSessionManager.createSession(UserSessionManager.java:442) ~[cspcserverforweb-2.11.jar:?]
at com.pari.nm.modules.session.UserSessionManager.createSession(UserSessionManager.java:537) ~[cspcserverforweb-2.11.jar:?]
at com.cisco.web.mw.WebUISpecificOperationsImpl.login(WebUISpecificOperationsImpl.java:58) ~[cspcserverforweb-2.11.jar:?]
at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method) ~[?:1.8.0_441]
at sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:62) ~[?:1.8.0_441]
at sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43) ~[?:1.8.0_441]
at java.lang.reflect.Method.invoke(Method.java:498) ~[?:1.8.0_441]
at com.pari.nm.modules.proxy.ProxyServer.handleGInvoke(ProxyServer.java:228) ~[cspcserverforweb-2.11.jar:?]
at com.pari.nm.modules.proxy.ProxyServer.handleProxyMessage(ProxyServer.java:146) ~[cspcserverforweb-2.11.jar:?]
at com.pari.nm.modules.proxy.ServerStreamHandler.handleProxyRequest(ServerStreamHandler.java:99) ~[cspcserverforweb-2.11.jar:?]
at com.pari.nm.modules.proxy.ServerStreamHandler.handleAllProxyRequests(ServerStreamHandler.java:126) ~[cspcserverforweb-2.11.jar:?]
at com.pari.nm.modules.proxy.DynamicProxyServer$1.run(DynamicProxyServer.java:81) ~[cspcserverforweb-2.11.jar:?]
2025-03-21 15:10:35,067 [https-jsse-nio-8001-exec-8] INFO com.cisco.cspc.server.services.OpenLoginServiceImpl - Remote Authentication Failed for the user: lega749
com.pari.api.InvalidUserIdOrPasswordException: Remote Authentication Failed for the user: lega749
at com.pari.nm.modules.session.UserSessionManager.createSession(UserSessionManager.java:442) ~[cspcserverforweb-2.11.jar:?]
at com.pari.nm.modules.session.UserSessionManager.createSession(UserSessionManager.java:537) ~[cspcserverforweb-2.11.jar:?]
at com.cisco.web.mw.WebUISpecificOperationsImpl.login(WebUISpecificOperationsImpl.java:58) ~[cspcserverforweb-2.11.jar:?]
at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method) ~[?:1.8.0_441]
at sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:62) ~[?:1.8.0_441]
at sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43) ~[?:1.8.0_441]
at java.lang.reflect.Method.invoke(Method.java:498) ~[?:1.8.0_441]
at com.pari.nm.modules.proxy.ProxyServer.handleGInvoke(ProxyServer.java:228) ~[cspcserverforweb-2.11.jar:?]
at com.pari.nm.modules.proxy.ProxyServer.handleProxyMessage(ProxyServer.java:146) ~[cspcserverforweb-2.11.jar:?]
at com.pari.nm.modules.proxy.ServerStreamHandler.handleProxyRequest(ServerStreamHandler.java:99) ~[cspcserverforweb-2.11.jar:?]
at com.pari.nm.modules.proxy.ServerStreamHandler.handleAllProxyRequests(ServerStreamHandler.java:126) ~[cspcserverforweb-2.11.jar:?]
at com.pari.nm.modules.proxy.DynamicProxyServer$1.run(DynamicProxyServer.java:81) ~[cspcserverforweb-2.11.jar:?]

 

I quitted HTML tags from the config:

RadiusServer
  ServerXXX.XXX.XXX.XXX
  Port 1812
  Timeout 2000
  SharedKey XXXXXXXXXXX
  AAAAuthenticationMethod PAP
RadiusServer

david
Level 1
Level 1

We are experiencing the same issue.  Test within CSPC logged in with local account is successful.  Login to CSPC with Remote account fails.  We are using RADIUS against Cisco ISE.

millerlw
Level 1
Level 1

You'll just have to live with it for now, and I suspect with the migration to the CX Cloud, it's not likely they are going to put any effort into fixing it, which makes sense.  We are almost finished our migration to the CX Cloud and it was actually fairly easy, the only thing left is to install our local CX Agent to replace the CSPC, everything else has been slurped in.