06-22-2016 05:48 AM - edited 02-21-2020 08:52 PM
Hi,
I have just enabled "password management" for one of my tunnel groups. I'm using LDAP for authetication. When I login, using AnyConnect, with a user that must change password and uses the right tunnel group (the one I have enabled password management for) I get to type in a new password and verify it but then I get a message back in the AnyConnect client that says "Unwilling to perform password change".
Is there anyway to figure out what exactely is going wrong?
Maybe it's more a question for Microsoft than Cisco?
Solved! Go to Solution.
09-07-2016 01:12 PM
Hi Kiristofer,
Just had the same issue.
After enabling the following -
the issue was resolved.
Good Luck,
Jeff Ferguson
09-07-2016 01:12 PM
Hi Kiristofer,
Just had the same issue.
After enabling the following -
the issue was resolved.
Good Luck,
Jeff Ferguson
11-28-2016 04:05 AM
Hi Jeff,
Ok, but you had to configure your LDAP servers for SSL also?
Ours servers are not so that would have to be solved first I guess.
If I can get the server team to do that I will most definetly try "LDAP over SSL"!
Thanks,
Kristofer
11-28-2016 12:38 PM
Thanks Jeff--I was getting this error with password management enabled and just had to do the second step to get it working.
12-01-2016 05:11 AM
Hi Joshua,
Great! Have you configured your LDAP servers to actually use SSL? Or does it not matter if the servers actually uses it or not?
12-01-2016 05:23 AM
They must have already been configured that way, because when I changed the option in ASDM (Configuration>Remote Access VPN>AAA/Local Users>AAA Server Groups) and used the Test authentication against the LDAP servers, it comes back successful right away. I would say to make the change, which is setting it to use port 636 instead of 389, and then test authentication right away with your domain credentials. If it doesn't work, set it back and then have your server team take a look.
12-01-2016 06:04 AM
Tried and guess what... it did work! I guess the server team have been working after all. :)
Thanks!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide