Author Topic: Random AAA Redirect Failure After Password change  (Read 893 times)

Offline HA

  • Contributor
  • *
  • Posts: 4
  • Karma: 0
Random AAA Redirect Failure After Password change
« on: January 03, 2012, 01:44:23 PM »
Hello,

I have a random problem with Netscaler AAA LDAPS password changing feature.
Basically, the first time the user connects to the Netscaler, he is asked to change his password (LDAPS->;Active Directory).
The password change is ALWAYS a success (check of the cat aaad.debug file confirm it).
The problem (random) is that some user receives an HTTP 500 Internal error (POST to /cgi/dlge).
The needs to restart the browser in order to login successfully to the application...

This is very annoying because the end user doesn't known if the password has been changed or not...

NS VPX 9.2 52.8 cl

Regards,

HA

Offline HA

  • Contributor
  • *
  • Posts: 4
  • Karma: 0
Re: Random AAA Redirect Failure After Password change
« Reply #1 on: January 04, 2012, 04:12:40 AM »
Hello,

Some more new about this issue.
NS has been upgraded to NS 9.3 54.4 but the problem remains the same.
It seems the random behaviour is related "some session timer".
When the user received the AAA TM login page, the user has less than 2 minutes to complete the login process (username+AD Password+OTP and if the AD password has expired, enter a new one).
If it takes more than 2 minutes, the Netscaler returns HTTP 500 Error...

Anyway to change this timer ??

Regards,

Hedi

Offline HA

  • Contributor
  • *
  • Posts: 4
  • Karma: 0
Re: Random AAA Redirect Failure After Password change
« Reply #2 on: January 18, 2012, 12:11:07 PM »
Hi all,

Citrix supports confirm this default behaviour (for security reason, thay said) on AAA TM and AGEE.

Regards,

Hedi