IBM Verify

IBM Verify

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  ISVA Account getting diabled (not valid) for unknown reason

    Posted 3 days ago

    Hi

    In our ISVA v10.0.8 we have an account which sometimes gets disabled (not valid). We've not been able to figure out why. I've tried applying audit logging , if it could shine a light on this and made some tests in our ISVA test environment. But I have not been able to provoke an event that invalidates an account nor found any interresting entries in the audit.log. I've tried logging in with a wrong password too many times; it results in a temporary lock of the account, but no logging. I've enabled the User authentication and Account locked components in Audit configuration. What audit logging configuration do I need and how can I provoke an account getting disabled?

    BR Carsten



    ------------------------------
    Carsten Jensen
    ATP
    +4530595704
    ------------------------------


  • 2.  RE: ISVA Account getting diabled (not valid) for unknown reason

    Posted 3 days ago

    It sounds like the problem is on the ldap level - so I would recommend looking in the ldap audit logs for binds with an outdated password.

    HTH



    ------------------------------
    Franz Wolfhagen
    WW IAM Solution Architect - Certified Consulting IT Specialist
    IBM Expert Labs
    ------------------------------



  • 3.  RE: ISVA Account getting diabled (not valid) for unknown reason

    Posted 3 days ago

    Hi Franz. Thanks for your reply.

    A wrong password for bind, would it not impact all (a lot) accounts? In our case a certain account more often ends up locked (disabled).

    (I did check server audit log settings on our primary ISDS and server audit logging is not enabled.)

    I've enabled the User authentication and Account locked components in ISVA Audit configuration in our ISVA test environment. I could try to enable all components. But how can I provoke a user getting disabled? Should I just enable audit logging in our production environment and "wait" for net user getting disabled? Are there any performance consideration?



    ------------------------------
    Carsten Jensen
    ATP
    +4530595704
    ------------------------------