This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

eDirectory 9.2.7 upgrade fails with " ..failed, invalid request (-641) Bad password"

Hi,

I am trying to upgrade eDirectory to recent 9.2.7, but on running ./nds-install, and entering the admin DN for instance and its password, the process stops with the error message

"Login for cn=admin.ou=sa.o=system.IDM_TREE: failed, invalid request (-641) Bad password"

The password is 6 digits, AND has been used on this system successfully over years, for upgrade to every service pack under IDM-4.7, through  each and all of the service packs in IDM 4.8 till date, hence implying the strength or complexity  of the password ought not to be an issue.

 {     SLES-12 SP3;   eDirectory-9.2.6 P1;   IDM-4.8.5 P1    }

///*******************************  nds-install.log

2022-10-18 16:47:29+03:00 Start of eDirectory 9.2.7.0000 Install
2022-10-18 16:47:29+03:00 Detected OS sles
2022-10-18 16:47:38+03:00 Upgrading NetIQ eDirectory
2022-10-18 16:48:21+03:00 Error: Invalid administrator credentials for instance /etc/opt/novell/eDirectory/conf/nds.conf

///**********************************

using  eDirectory_9..2.7_Linux_x86_64.tar.gz    Or   Identity_Manager_4.8.6_Linux.iso    media result in same error.

Any pointers or ideas on what could be the root cause, or what to tweak would be appreciated.

  • 0  

    I'd assume that something like "ndslogin" DOES indeed work with this account. Are you really on SLES12SP3? As even SP4 has been pulled from the list of supported OS with 9.2.7.

    Are you aware of this one?

    https://portal.microfocus.com/s/article/KM000010751?language=en_US

  • 0 in reply to   

    Thanks  Mathias for the pointers.

    I just tried ndslogin, but it fails, with same error code.

    ndslogin -t IDM_TREE admin.sa.system
    Password:
    Login for admin.sa.system.IDM_TREE: failed, invalid request (-641)

    So what is this puzzle about ?  Password worked for previous upgrades, and usual authentication via iManager, but not in this upgrade instance & ndslogin.

    What do you suggest to overcome this ?

    Yes, I have looked into this (https://portal.microfocus.com/s/article/KM000010751?language=en_US), and still pondering over it.

    Regarding SLES version,   Yes, 

    NAME="SLES"
    VERSION="12-SP3"
    VERSION_ID="12.3"
    PRETTY_NAME="SUSE Linux Enterprise Server 12 SP3"

  • 0   in reply to 

    Well, in case of a bad password you'd rather get a 669 than a 641.

    Can you login to iManager with this user? Can you "ndslogin" with this user on another server? If you try to login with an OES client, do you also see a 641? Which kind of password policy (if any at all) does this object have? Did you ever try to bounce the box (or the nds daemon at least)?

  • 0 in reply to   

    After pondering over the various factors including:

    "OS version= SLES12SP3?  As even SP4 has been pulled from the list of supported OS with 9.2.7.

    Are you aware of this one?

    https://portal.microfocus.com/s/article/KM000010751?language=en_US " ;  ... the current issue, and other shared issues related to 9.2.7 & IDM-4.8.6.

    I have decided on the "safer" option to setup new machine (SLES-15 SP3), do the relevant migration, and proceed from there.

    Thanks   for the suggestions and red-flag.