> Source: [sk110882](https://support.checkpoint.com/results/sk/sk110882)

# sk110882 - Users are not matched against their LDAP directory after upgrade of Security Management Server to R80 / R80.10, if some of the LDAP configuration fields contain non-English characters

| Property | Value |
|----------|-------|
| Solution ID | sk110882 |
| Date Created | 2016-04-09 |
| Last Modified | 2017-05-17 |
| Technical Level | Advanced |
| Products | Security Management Server, Multi-Domain Security Management Server |
| Versions | R82.10, R82, R81.20, R82.10, R82.20, R81.20, R82, R82.20 |
| OS | Gaia |

## Symptoms

- * The authentication fails against the user's directory, which is represented by LDAP Account Units with Domain field defined in non-English characters.

* Authentication / Authorization fails against the user's directory, which is represented by LDAP Account Units with Branches defined in non-English characters.

* Authorization (Branch / Group membership) fails for LDAP Groups with fields defined in non-English characters (rule matching on those users will be skipped).

* Query to Active Directory fails and the Kerberos Single Sign On is enabled, and its account name defined in non-English characters.

## Cause

R80 / R80.10 Security Management Server uses the Unicode character set and the UTF-8 encoding to store non-English characters.

SmartDashboard R77.X and lower allows the user to use encodings other than UTF-8 for non-English characters in some properties of LDAP Account Unit and LDAP Group.

If these fields contained non-English characters (e.g., Russian, Japanese, Chinese, Korean, etc.) before the upgrade to R80 / R80.10, then they will become corrupted during policy installation on R80 / R80.10 Security Management Server.

The relevant fields are (example is given for Russian characters):

* LDAP Account Unit properties - "General" tab - "Domain" field:

  ![](https://sc1.checkpoint.com/sc/SolutionsStatics/NEW_SK_NOID1459942197311/Picture2_801604060449.jpg)
* LDAP Account Unit properties - "General" tab - "Active Directory SSO configuration" button - "Account Name" field:

  ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk110882/Untitled1604070345.jpg)
* LDAP Account Unit properties - "Objects Management" tab - "Branches in use" field - "CN":

  ![](https://sc1.checkpoint.com/sc/SolutionsStatics/NEW_SK_NOID1459942197311/Picture3_801604060450.jpg)
* LDAP Group properties:

  ![](https://sc1.checkpoint.com/sc/SolutionsStatics/NEW_SK_NOID1459942197311/Picture51604060457.jpg)

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
