Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

User is getting Reset Certificate Password dialog box.

I have a user that changed their AD password, but the SGN client didn't recognize the change.  Now she is presented with the Certificate Password dialog box: SafeGuard Enterprise was unable to complete your logon.  If you have recently changed your Windows password, please enter the "OLD" password now.  When the user enter's their OLD password, they are presented with a "Certificate Import Failed" box.  Unable to import the certificate.  The password may have been entered incorrectly.

The user states that they are entering the OLD password correctly.  I have deleted the computer and user certificate from the SGN console, but it has not solved this issue.  What else can I try?

:2189


This thread was automatically locked due to age.
Parents
  • Zman could you provide us with some more information like OS version, SGN version, are you using the SGN credential provider or a different one. What happens when a user changes his password by prsssing CTRL-ALT-DEL and then clicking change password?

    The reason I am asking this is that normally a SafeGuard Enterprise (SGN) client should recognize that a user is trying to change his password. There are some exceptions though where we cannot recognize this, for example:

    - you are using Windows Vista/ Windows 7 and are not logged on to the system using the SGN Credential Provider;

    - you change your password on a different system which does not have SGN installed;

    - the password is reset within active directory.

    When a user that is connected to his AD using VPN, is therefore changing his password, then this password is copied to the POA automatically and when the user logs on to the system the next time then he can use his new password. The certificate used by SGN is secured with the new password. When the SGN client can connect to the SGN Server at this time then the updated certificate (private key) is send to the SGN server so that the new password can be distributed all other PCs where the user was registered as well. Is no connection possible at this time then SGN will "upload" the data the next time it can reach the server.

    :7579
Reply
  • Zman could you provide us with some more information like OS version, SGN version, are you using the SGN credential provider or a different one. What happens when a user changes his password by prsssing CTRL-ALT-DEL and then clicking change password?

    The reason I am asking this is that normally a SafeGuard Enterprise (SGN) client should recognize that a user is trying to change his password. There are some exceptions though where we cannot recognize this, for example:

    - you are using Windows Vista/ Windows 7 and are not logged on to the system using the SGN Credential Provider;

    - you change your password on a different system which does not have SGN installed;

    - the password is reset within active directory.

    When a user that is connected to his AD using VPN, is therefore changing his password, then this password is copied to the POA automatically and when the user logs on to the system the next time then he can use his new password. The certificate used by SGN is secured with the new password. When the SGN client can connect to the SGN Server at this time then the updated certificate (private key) is send to the SGN server so that the new password can be distributed all other PCs where the user was registered as well. Is no connection possible at this time then SGN will "upload" the data the next time it can reach the server.

    :7579
Children
No Data