Citrix FAS - Incorrect username and password

Citrix FAS - Incorrect username and password

book

Article ID: CTX560789

calendar_today

Updated On:

Description

Incorrect username and password (FAS) After launching desktop when users tries to log on.

No error on the certificates, no error in "Application" and "System" in the FAS server.


VDA event logs (Windows logs > Security) and looking for audit failure at the same time as the login failure :

0xC000006Auser name is correct but the password is wrong
0XC000006DThis is either due to a bad username or authentication information


image.png

An error like the above, suggests that the certificate validation failed at a domain (Kerberos) level.
 

Domain controller contained the following error for your userID. EventID: 4771 :

image.png
 

 

Environment

Citrix is not responsible for and does not endorse or accept any responsibility for the contents or your use of these third party Web sites. Citrix is providing these links to you only as a convenience, and the inclusion of any link does not imply endorsement by Citrix of the linked Web site. It is your responsibility to take precautions to ensure that whatever Web site you use is free of viruses or other harmful items.

Resolution

Issues with validating user certificate at a Domain level would need to be troubleshooted from a Microsoft perspective, as the user’s certificate validation is failing at the domain level.

The recommendation: Would be to reach out to Microsoft support or the vendor of the certificate-based authentication, as there seems to be something invalid about this user certificate.


Workaround :
as per https://support.citrix.com/article/CTX217150 put the reg key on the VDA :

HKEY_Local_Machine\System\CurrentControlSet\Control\LSA\Kerberos\Parameters
Value Name: UseCachedCRLOnlyAndIgnoreRevocationUnknownErrors
Value Type: DWORD
Value Data: 1
Description: After you set this DWORD value to 1.

The Kerberos clients (Smartcard logon clients) will ignore "revocation unknown" errors that are caused by an expired CRL if the above registry key is configured.
Note: This key should be deleted once the actual issue is resolved
 

Problem Cause

Certificate validation failed at a domain (Kerberos) level.
Certificate information is only provided if a certificate was used for pre-authentication.
Pre-authentication types, ticket options and failure codes are defined in RFC 4120.
If the ticket was malformed or damaged during transit and could not be decrypted,
then many fields in this event might not be present.

Issue/Introduction

Incorrect username and password (FAS)

Additional Information

https://mivilisnet.wordpress.com/2016/03/07/how-to-troubleshoot-the-kerberos-error-4771-and-locked-user-accounts/

https://support.citrix.com/article/CTX217150