cancel
Showing results for 
Search instead for 
Did you mean: 

Challenge not being displayed

megs_
New Contributor

Challenge not being displayed

Hello,

I'm currently using custom sign in pages with my Sa2000 device. They were rebuilt after an upgrade. I am using an Entrust Identity guard (referenced as IG) system for first factor authentication, as well as token authentication. The IG system acts as a radius proxy, and the juniper device authenticates with it like it was a radius server. My problem is that I should be seeing challenges when signing in....and I'm not. Users are getting pretty darn confused because they won't know *what* they're supposed to be entering.

For example...it should tell the user when their password needs to be reset, when their PW reset is unsuccessful, as well as something along the lines of "Please enter the PIN from your token with serial nummber 900498304958". Entrust swares up and down that this issue is isolated to my IVE, and my config is 100% correct and they've used this setup many many times without any issues. They also claim to have tested it with my exact setup in their labs and have not been able to reproduce the issue. I have no support contract with Juniper and mangement isn't interested in purchasing one so I'm pretty screwed right now. Even if these is a fault with the IVE, I'm going to have a pretty hard time convincing Juniper to RMA it.

Has anyone experienced this issue? Any ideas as to what I could look at? The juniper logs tell me nothing. Right now I'm waiting on tcp dump files from Entrust's working system so I can compare packet by packet to see what's up... I probably won't be able to pick the problem out, but I figure it's worth a shot! Any more suggestions would be more than appreciated.
2 REPLIES 2
-red-_
Frequent Contributor

Re: Challenge not being displayed

What version of code are you running? Is this something which has worked prior to the upgrade, and then stopped? If you haven't already done so, I'd suggest sending a copy of your sign-in page to Entrust and have them examine it (hopefully they wont be too quick to point a finger at Juniper.) If I'm not mistaken, the more recent versions of code do allow you to set up a support meeting, so you may be able to set up a quick secure meeting, and show Entrust the exact problem you're seeing. Good luck.
megs_
New Contributor

Re: Challenge not being displayed

Hi Red.

I'm running 6.0r3.1....which is the latest as far as I'm aware. I've sent all of my config to Entrust including the signing pages and they work on their system with an identical setup (or so I'm told). Entrust logs on my system show the challenge (please enter your pin from token xxxx, please update your password, etc.), but it's not displayed on the sign in pages.