Hashicorp Vault LDAP authentication issues

Viewed 30

We use LDAP as our access into Hashicorp Vault.

One of our users was deleted and recreated in AD... This use cannot log into the vault any longer, receiving a "Authentication failed: internal error" (rather than a "Authentication failed: ldap operation failed" that we see for a user that is not in AD or with an invalid password)

The only error we see is in the vault_audit.log (with passwords, and assessors munged, ip changed, and replaced with my name as example):

{
"time": "2022-09-12T19:03:55.457492415Z",
"type": "response",
"auth": {
    "client_token": "hmac-sha256:xxxxxxx",
    "accessor": "hmac-sha256:yyyyyyy",
    "display_name": "ldap-ssiegler",
    "token_policies": [
        "default"
    ],
    "metadata": {
        "username": "ssiegler"
    },
    "entity_id": "aca5c682-b0c4-2f51-9681-b4244a23720b",
    "token_type": "service"
},
"request": {
    "id": "275b5b49-80ff-ee5f-a7f8-1e0c5a3dc645",
    "operation": "update",
    "namespace": {
        "id": "root"
    },
    "path": "auth/ldap/login/ssiegler",
    "data": {
        "password": "hmac-sha256:zzzzzzz"
    },
    "remote_address": "192.168.205.23"
},
"response": {},
"error": "internal error"

}

"error": "internal error" being the only information...

I have removed the entities that referenced this user, with no change, and created a new entity that was able to have this ad user as an alias, so AD sees him...

Ideas?

0 Answers
Related