IBM Support

LDAP Authentication Failure After GPU P230 Installation

News


Abstract

After installing GPU P230 on a Guardium v12.2.x appliance, LDAP authentication might fail.
Customers who manually imported their LDAP certificate chain into the LDAP truststore are not affected by this issue. Customers who do not use SSL in their LDA configuration are not impacted. Locally authenticated accounts are not impacted as well.
Affected users will be unable to log in and might receive the following UI error message:
"Invalid user name or password"
The underlying error recorded in Guardium logs is:
"SSLHandshakeException: PKIX path building failed — unable to find valid certification path to requested target"

Content

This issue affects all Guardium appliance types running Guardium 12.2.x with GPU P230 installed, including:

  • Standalone Collectors and Aggregators
  • Central Managers and Managed Units

Customers who have manually imported their LDAP certificate chain into the LDAP truststore are not affected by this issue. Customers who do not use SSL in their LDA configuration are not impacted

Locally authenticated accounts are not impacted as well.

Until P231 is applied, you can perform one of the following workarounds.

Workaround 1:

Upload custom LDAP certificate 

Workaround 2:

The following procedure restores LDAP authentication immediately. Because root access is required, this activity should be performed with assistance from Guardium Support through an active support case.

Step 1: Remove the Solr certificate entry from the LDAP truststore

keytool -delete -alias solr-root -keystore $GUARD_TOMCAT_DIR/.ldaptruststore

Step 2: In CM environment, execute Portal User Sync

Step 3: Restart the GUI service on all affected Guardium appliances

After the GUI service restarts, LDAP authentication should function normally.

 

Permanent fix: The fix prevents GPU installation from corrupting or overwriting the LDAP truststore and preserves existing LDAP certificate trust relationships.

  • GPU P231 (Guardium 12.0p231) contains the permanent fix for this issue if Guardium system is NOT configured with EFI bootloader. 
 
  • GPU P232 (Guardium 12.0p232) contains the permanent fix for this issue if Guardium system is configured with EFI bootloader. Fix Central link: SqlGuard_12.0p232_FixPack
     
How to determine whether your system uses EFI
  1. Log in to the Guardium appliance GUI.
  2. In the search field, open the System Monitor report.
  3. Under Hard Disk Usage, review the Mounted On column.
  4. Look for the mount point /boot/efi:
    • If /boot/efi is present, the appliance is using EFI.
    • If /boot/efi is not present, the appliance is not using EFI and is not affected by this issue.

[{"Type":"MASTER","Line of Business":{"code":"LOB76","label":"Data Platform"},"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSMPHH","label":"IBM Security Guardium"},"ARM Category":[{"code":"a8m0z000000Gp0MAAS","label":"AUTHENTICATION"}],"Platform":[{"code":"PF004","label":"Appliance"}],"Version":"12.2.0"}]

Document Information

Modified date:
21 August 2026

UID

ibm17282377