16.10 - Diagnosing Logon Failure Due to Incorrect Realm Information - Teradata Database

Teradata Database Security Administration

prodname
Teradata Database
vrm_release
16.10
created_date
June 2017
category
Administration
Security
featnum
B035-1100-161K

Directory users may receive the generic error message, “SSO logon failed by gateway.” This message is often related to entry of (or defaulting to) an invalid directory server realm name.

To help diagnose the problem, you can run the same tdsbind -u input shown in Example: Tdsbind Output for a Directory User Mapped to a Database User If the command produces the following error message, the LdapServerRealm property in the TDGSS user configuration file contains an invalid realm name.

tds_bind: Directory error - Invalid Credentials
additional info: SASL(-1): generic failure: realm changed: authentication aborted

You can correct this error by editing the value of the LdapServerRealm property. See LdapServerRealm.

Once the value of the LdapServerRealm is correct, use tpareset to restart the server and enable the change. If you cannot restart the server, instruct users to enter the correct realm information as part of the logon string. See Logging on Using LDAP Authentication and Authorization.