- BlackBerry Enterprise Server 5.0
- BlackBerry Administration Service
- DT 301644
- DT 837819
This article contains an overview of several causes that prevent BlackBerry smartphone users or administrators from being able to log in to the BlackBerry Administration Service web console. The following generic error appears for all of the issues described:
The username, password, or domain is not correct. Please correct the entry.
Issue 1
If experiencing this issue, the following log line appears in the BAS-AS log file:
{http-<BASName>%2F10.200.26.82-443-1} [com.rim.bes.basplugin.activedirectory.ActiveDirectoryManagerBean] [INFO] [ADAU-1000] {u=SystemUser, t=32681} loginAsLdapUser failed to authenticate LDAP user=besadmin, realm=<Domain>, kdc=<Domain Controller providing KDC services) javax.security.auth.login.LoginException: Clock skew too great (37)
Note : The realm=<Domain> and kdc=<Domain Controller providing KDC services> values will be unique to each environment.
Issue 2
If experiencing this issue, the following log line appears in the BAS-AS log file:
[WARN] [BBAS-2015] {u=1, uc=-1, o=0, t=150975} _getExternalAuthenticatorId could not find external authenticator identifier - com.rim.bes.bas.usermanager.CouldNotFindExternalAuthenticatorIdException: Message: 'LOGIN ERROR: findExternalAuthenticatorIdLocal failed to login as LDAP user com.rim.bes.bas.pluginmanager.InvalidAuthenticationException: Message: 'LOGIN ERROR: loginAsLdapUser exception during authentication com.rim.bes.bas.util.BASCouldNotCompleteRequestRollbackException: getAuthenticationCredentialsLocal stored password could not be decrypted', nested exception: 'getAuthenticationCredentialsLocal stored password could not be decrypted'', nested exception: 'Message: 'LOGIN ERROR: loginAsLdapUser exception during authentication com.rim.bes.bas.util.BASCouldNotCompleteRequestRollbackException: getAuthenticationCredentialsLocal stored password could not be decrypted', nested exception: 'getAuthenticationCredentialsLocal stored password could not be decrypted''
Issue 3
If experiencing this issue, the following log line appears in the BAS-AS log file:
[com.rim.bes.basplugin.activedirectory.ActiveDirectoryManagerBean] [INFO] [ADAU-1000] {u=SystemUser, t=4690} loginAsLdapUser failed to authenticate LDAP user=besadmin, realm=<Domain>, kdc=<Domain Controller providing KDC services> javax.security.auth.login.LoginException: KDC has no support for encryption type (14)
Note: The realm=<Domain> and kdc=<Domain Controller providing KDC services> values will be unique to each environment.
Issue 4
If experiencing this issue, after configuring a BlackBerry Administration Service pool to communicate via TCP, and the following log line appears in the BAS-AS log:
[com.rim.bes.bas.singletondeploymentbarrier.SingletonDeploymentBarrierManagerUtilities] [DEBUG] [BBAS-200] {unknown} barrierCheckTimerEvent CLUSTER: we are not the singleton
Issue 1
For details on how to resolve this issue, see KB18177.
Issue 2
For details on how to resolve this issue, see KB18161.
Issue 3
For details on how to resolve this issue, see KB18186.
Issue 4
For details on how to resolve this issue, see KB25584
Disclaimer
By downloading, accessing or otherwise using the Knowledge Base documents you agree:
(a) that the terms of use for the documents found at www.blackberry.com/legal/knowledgebase apply to your use or reference to these documents; and
(b) not to copy, distribute, disclose or reproduce, in full or in part any of the documents without the express written consent of RIM.
Visit the BlackBerry Technical Solution Center at www.blackberry.com/btsc.

