IBM Support

Guardium GUI Login Failure with Duo MFA

News


Abstract

IBM Guardium is impacted by an issue with the duo‑universal‑sdk used for Duo MFA authentication. The current SDK version causes GUI login failures when Duo MFA is enabled, preventing users from accessing the Guardium UI. Customers who do not use Duo MFA are not affected. This issue does not affect the Guardium 12.2.2 environment.

Content

Guardium is affected by an issue related to the duo-universal-sdk version. To permanently resolve the issue within the Guardium product, the duo-universal-sdk must be updated to version 1.3.1. Customers who do not use Cisco Duo MFA are not affected. Guardium environment version 12.2.2 is not impacted by this issue. 

Symptoms

  • Users are unable to log in to the Guardium GUI
  • Duo MFA authentication fails during GUI login

 

Workaround 

Customers can temporarily disable Duo MFA for GUI login to regain access, apply the necessary fix, and then re‑enable Duo MFA.
 
Disable Duo MFA for GUI login. Execute the following command through CLI interface: 
grdapi configure_mfa mfaType="DUO" enable=false loginPath=GU 
 
Note: A GUI restart is not required when disabling or enabling Duo MFA.
 

Remediation

  1. Disable Duo MFA for GUI login using the command in the previous Workaround section.
  2. Log in to the Guardium UI.
  3. Install the required ad hoc patch that updates duo-universal-sdk to version 1.3.1.
  4. Re-enable Duo MFA for GUI login. Execute the following command through CLI interface: 
    grdapi configure_mfa mfaType="DUO" enable=true loginPath=GUI 

    Note: A GUI restart is not required when disabling or enabling Duo MFA.

 

Fix availability

IBM is actively delivering fixes for the affected Guardium versions. The update includes duo‑universal‑sdk version 1.3.1. Customers are advised to apply the available workaround if impacted and plan to install the applicable fix once it becomes available for their Guardium version.

Guardium versionFix delivery methodEstimated availability
11.0p582 for version 11.5 environmentsFix CentralAvailable. See release notes for 11.0p582.
12.0p56 for version 12.0 environmentsFix CentralAvailable. See release notes for 12.0p56.
12.0p141 for version 12.1 environmentsFix CentralAvailable. See release notes for 12.0p141.
12.0p208 for version 12.2 environmentsFix CentralAvailable. See release notes for 12.0p208.
12.0p1031Fix CentralAvailable. See release notes for 12.0p1031.

 

[{"Type":"MASTER","Line of Business":{"code":"LOB76","label":"Data Platform"},"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSMPHH","label":"IBM Security Guardium"},"ARM Category":[{"code":"a8m0z000000Gp0JAAS","label":"APPLIANCE"}],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"10.0.0;10.0.1;10.1.0;10.1.2;10.1.3;10.1.4;10.5.0;10.6.0;11.0.0;11.1.0;11.2.0;11.3.0;11.4.0;11.5.0;12.0.0;12.1.0;12.2.0;8.0.1;8.2.0;9.0.0;9.1.0;9.5.0"}]

Document Information

Modified date:
24 April 2026

UID

ibm17269364