HP-UX AAA Server A.08.01 administrator's guide (T1428-90072, May 2010)

Table Of Contents
To determine if an unrecorded DHCP failure caused the problem, complete the following
steps:
1. Access the datastore used for user profile storage as described in “Identifying
Unrecorded External Datastore Failures” (page 493).
2. If the DHCP address pool is configured, ensure that there are sufficient addresses
in the pool.
3. Ensure that the DHCP server is sending valid packets to the HP-UX AAA Server.
Troubleshooting Access-Rejects from the HP-UX AAA Server
The HP-UX AAA Server sends an Access-Reject message to the RADIUS client if
authentication fails. Authentication failures occur because of incorrect configuration
on the HP-UX AAA Server or the RADIUS client, or due to incorrect credentials passed
to the HP-UX AAA Server.
Use the following sections to troubleshoot problems related to authentication failures.
“Common Authentication Failure Problems” (page 494): This section lists the
common problems related to authentication failures and the necessary corrective
actions.
“EAP Problems” (page 502): This section lists EAP implementation-specific problems
related to authentication failures.
Common Authentication Failure Problems
Compare the error messages recorded in the logfile to those in Table 30-5 and perform
the corresponding corrective actions.
Table 30-5 Common Authentication Failure Problems
TroubleshootingProblem
Authentication failed. Unsuccessful password comparison for
user '<user name>' in realm '<realm name>'. Verify password
Log MessageUnable to
authenticate
in request and user profile. Verify shared secret match between
client '<client>' and client configuration in '/etc/opt/aaa/clients'
or Access Devices screen in Server Manager
This error occurs because of any of the following reasons:Cause
The shared secret configured for the RADIUS client and the
HP-UX AAA Server do not match.
The password provided by the user does not match the
password configured in the user profile datastore.
Solution 1. Ensure that the shared secret configured on the RADIUS client
matches the one specified in the Access Devices screen of the
Server Manager.
2. Ensure that the password supplied by the user is correct.
494 Troubleshooting Procedures