"User Certificate Authentication Failed : No matching Principal found!" error using X509 authentication

  • 7001938
  • 19-Nov-2008
  • 26-Apr-2012

Environment

Novell Access Manager 3 Linux Novell Identity Server
Novell Access Manager 3 Support Pack 4 applied

Situation

Basic Access Manager setup installed and working well. Users could authenticate successfully to the Identity Server using their username and passwords, or using their X509 client certificates.

Over the next few days, a small handful of users would intermittently call the help desk claiming that they could not authenticate to the Identity Server using their client certificates. In each case, the error reported was

"User Certificate Authentication Failed : No matching Principal found!"

Resolution

Removed time restrictions that were enabled for certain users.

The issue here is that the error reported has nothing to do with the problem. The issue has been reported to engineering and will be addressed in a future support pack.