Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Unable to delete weirdly named users in FW XG

Hey,

Yesterday I asked here why I couldn't delete a user : (+) Can't delete user in FW XG - Discussions - Sophos Firewall - Sophos Community

I'm here again for the same problem (deleting a user) but it's not the same scenario:

for exemple : Jonh Doe (j.doe@domain.com) was added I don't know how to the list of sophos users but it's account is like this :

Name : domain oe john (<- there is no typo)
Type : User
With no email address

When trying to delete theses users from Authentification > Users > Checkbox > Delete : A green message says "User has been deleted successfully" but it's still here, giving theses csc.log : 

Readobject Executing PREPSTMT Query=select cachepeer as extPeer,cachepeerport as extpeerport,username as userName,passwd as password,case when(cachepeer is not null and cachepeer != '' and cachepeer != '-11' and cachepeerport is not null and cachepeerport != '') then 'checkbox' else '' end as parentproxystatus from tblcacheconfiguration where ipfamily='1'MESSAGE Jan 18 08:46:33Z [ssod:1039]: {"ssod":{"method":"service","name":"ssod:status","version":"1.6","type":"text","length":0}}


MESSAGE Jan 18 08:46:34Z [worker:7265]: {"request":{"method":"opcode","name":"HBAddEacEpRel","version":"1.0","type":"json","length":11558,"data":{ "relations": [ { "ep_identity": { "name": "V1MtNDM1Mw==", "uuid": "user id" }, "app_paths": [ { "app_path": "long key=", "occurrence_count": 1, "last_seen": 1674031594 } ] }, { "ep_identity": { "name": "VUZQLTYwQkY=", "uuid": "6f39fbd6-b424-4494-9c29-35246ce67b2c" }, "app_paths": [ { "app_path": "long key=", "occurrence_count": 1, "last_seen": 1674031594 }, { "app_path": "long key==", "occurrence_count": 1, "last_seen": 1674031594 } ] }, { "ep_identity": { "name": "V1MtNENGRA==", "uuid": "20bedb4b-53b1-493c-bb7e-77f54be2247b" }, "app_paths": [ { "app_path": "long key==", "occurrence_count": 2, "last_seen": 1674031594 } ] }, { "ep_identity": { "name": "V1MtRTkxRg==", "uuid": "ff843756-54a4-41ec-9175-0e83bb178298" }, "app_paths": [ { "app_path": "long key=", "occurrence_count": 1, "last_seen": 1674031594 }, { "app_path": "long key==", "occurrence_count": 1, "last_seen": 1674031594 } ] }, { "ep_identity": { "name": "V1MtQTk3RQ==", "uuid": "e85c3cf1-7c0e-4338-bd55-55d44ac1dc7d" }, "app_paths": [ { "app_path": "long key==", "occurrence_count": 3, "last_seen": 1674031593 } ] }, { "ep_identity": { "name": "V1MtNUZDMg==", "uuid": "2fb5df9c-c5e0-4489-b2a1-d6d3e08c5097" }, "app_paths": [ { "app_path": "long key==", "occurrence_count": 3, "last_seen": 1674031593 } ] }, { "ep_identity": { "name": "V1MtNjhBNg==", "uuid": "752b6e1d-533d-479b-9617-7ace11fab ...


MESSAGE Jan 18 08:46:35Z [worker:7273]: {"request":{"method":"opcode","name":"apiInterface","version":"1.0","type":"json","length":315,"data":{"mode":33,"currentlyloggedinuserid":68,"___serverport":4444,"___component":"GUI","APIVersion":"1900.1","userIds":["domain\doe john"],"___serverprotocol":"HTTP","___username":"myadminaccount@domain.com","transactionid":"584326","___meta":{"sessionType":1},"___serverip":"10.0.0.21","currentlyloggedinuserip":"10.52.32.156"}}}


MESSAGE Jan 18 08:46:35Z [worker:7258]: {"request":{"method":"opcode","name":"delete_user","version":"1.6","type":"json","length":489,"data":{ "mode": 33, "currentlyloggedinuserip": "10.52.32.156", "webfilterid": "Tout autoriser", "Entity": "user", "___serverport": 4444, "transactionid": "584326", "currentlyloggedinuserid": 68, "___serverip": "10.0.0.21", "APIVersion": "1900.1", "appfilterid": "Tout autoriser", "userIds": [ "domain\\\\doe john" ], "___serverprotocol": "HTTP", "___meta": { "sessionType": 1 }, "___component": "GUI", "___cmenabled": 0, "Event": "DELETE", "___cmrequest": 0, "___username": "myadminaccount@domain.com" }}}


ERROR Jan 18 08:46:35Z [delete_user:7258]: delete_userid: input has no array elements
ERROR Jan 18 08:46:35Z [delete_user:7258]: delete_ugrel_cache: input has no array elements
WARNING Jan 18 08:46:35Z [delete_user:7258]: Action with NOFAIL Failed.

I replaced my actual domain name with "domain" the user with "john doe" and my admin username with "myadminaccount@domain.com"

I also tried disabling everything in the user account (L2TP, PPTP...) but when pressing "save" it says "Missing email address".

Putting one says "There must be at least one user with "Administrator" profile".

Then it ask for a password for the account and gives "Changing password for backend authenticated users is not allowed".

Any idea ? I got two users like that.

Have a nice day.



This thread was automatically locked due to age.
Parents
  •   
    I managed to use the API and its working :

    <Response APIVersion="1900.1" IPS_CAT_VER="1">
    <Login>
    <status>Authentication Successful</status>
    </Login>
    <User transactionid="">
    <Status code="200">Configuration applied successfully.</Status>
    </User>
    </Response>
    But the user is still here after sending the request : 
    x.x.x.x:4444/.../APIControllerAPI admin</Username><Password>PASSWORD</Password></Login><Remove><User><Username>user username</Username><Name>user name</Name></User></Remove></Request>
    (the user has the same name and username, they both have space character in it, I tried with and without " ")
    From csc.log, still the same.
  • Is this user locally created or AD managed ?

    Thanks & Regards,
    _______________________________________________________________

    Vivek Jagad | Team Lead, Global Support & Services 


    Sophos Community | Product Documentation | Sophos Techvids | SMS
    If a post solves your question please use the 'Verify Answer' button.

  • Since I can "change" (but not save !) their group in Authentication > Users > click on user, I'll assume they're local users

    And again, can't change anything to them since it does what I explained in my first post

Reply Children