16.10 - Diagnosing Logon Failure Due to Incorrect Realm Information - Teradata Database

Teradata Database Security Administration

Product
Teradata Database
Release Number
16.10
Release Date
June 2017
Content Type
Administration
Security
Publication ID
B035-1100-161K
Language
English (United States)

Directory users may receive the generic error message, “SSO logon failed by gateway.” This message is often related to entry of (or defaulting to) an invalid directory server realm name.

To help diagnose the problem, you can run the same tdsbind -u input shown in Example: Tdsbind Output for a Directory User Mapped to a Database User If the command produces the following error message, the LdapServerRealm property in the TDGSS user configuration file contains an invalid realm name.

tds_bind: Directory error - Invalid Credentials
additional info: SASL(-1): generic failure: realm changed: authentication aborted

You can correct this error by editing the value of the LdapServerRealm property. See LdapServerRealm.

Once the value of the LdapServerRealm is correct, use tpareset to restart the server and enable the change. If you cannot restart the server, instruct users to enter the correct realm information as part of the logon string. See Logging on Using LDAP Authentication and Authorization.