> Source: [sk40735](https://support.checkpoint.com/results/sk/sk40735)

# sk40735 - SecureClient user unable to change password when it expires while authenticating through LDAP server

| Property | Value |
|----------|-------|
| Solution ID | sk40735 |
| Date Created | 2009-04-14 |
| Last Modified | 2021-12-12 |
| Technical Level | General |
| Products | Endpoint Security |
| Versions | Cloud, E89.X, E88.X |

## Symptoms

- * SecureClient user unable to change password when it expires while authenticating through LDAP server.
* Error in the Log Viewer:  
  "`reason: Client Encryption: Failed to modify password, LDAP Error.`"
* Error on SecureClient:  
  "`Negotiation with gateway <gateway_name> at site <site_name> has failed.`  

  `Failed to modify password, LDAP error.`"

## Cause

Windows AD is denying changing passwords over unencrypted channel.

## Solution

1. Enable SSL Encryption in the LDAP Account unit. Select 'Manage -\> Servers and OPSEC Applications -\> LDAP Account Unit'.  

2. Under the Servers tab, after completing General tab, select Encryption tab.  

3. Select "Use Encryption (SSL)".  

4. Port will be 636.  

5. Fetch the server's fingerprint.  

6. Click "OK".  

7. Click "OK".

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
