Consider the following scenario:
In this scenario, the password change is unsuccessful, and the user receives the following generic error message:
Additionally, tracing in TMG 2010 may indicate that ADsOpenObject failed with 0x80005000 (E_ADS_BAD_PATHNAME) or 0x80072032 (ERROR_DS_INVALID_DN_SYNTAX) because the special character in the LDAP request escaped.
- An administrator has forms-based authentication (FBA) set up in Microsoft Forefront Threat Management Gateway (TMG) 2010.
- The distinguished name (DN) attribute for a user contains a forward slash (/) and an Active Directory Lightweight Directory Access Protocol (LDAP)-defined special character.
- The user tries to change his or her password.
In this scenario, the password change is unsuccessful, and the user receives the following generic error message:
Either the user name or old password is not valid, or the new password does not meet the minimum complexity requirements. Please try again.