Hi Dylan,

recheck your root_password_sha2 setting. The password SHA-256 hash seems to 
be invalid. It has to be exactly 64 characters long (the hexadecimal 
representation of a 256-bit value).

Cheers,
Jochen

On Thursday, 3 November 2016 16:32:18 UTC+1, Dylan Humphreys wrote:
>
> Hi Everyone,
> graylog 2.1.1-2 on debian 8, elasticsearch 2.4.1 and mongo 2.6.12 manual 
> install.
> I have set
>
> password_secret = qBbUBsZDwL9...
>
> and 
>
> root_password_sha2 = 240be518fa...
>
> Using the commands mentioned in server.conf, however whenever I try and 
> login using the web interface I get this in the logs:
>
>
> 2016-11-03T15:22:29.813Z WARN  [ModularRealmAuthenticator] Realm 
> [org.graylog2.security.realm.RootAccountRealm@38be73c4] threw an exception 
> during a multi-realm authentication attempt: 
> java.lang.IllegalArgumentException: Odd number of characters. 
>        at org.apache.shiro.codec.Hex.decode(Hex.java:128) ~[graylog.jar:?] 
>        at org.apache.shiro.codec.Hex.decode(Hex.java:107) ~[graylog.jar:?] 
>        at org.apache.shiro.codec.Hex.decode(Hex.java:95) ~[graylog.jar:?] 
>        at 
> org.apache.shiro.authc.credential.HashedCredentialsMatcher.getCredentials(HashedCredentialsMatcher.java:353)
>  
> ~[graylog.jar:?] 
>        at 
> org.apache.shiro.authc.credential.HashedCredentialsMatcher.doCredentialsMatch(HashedCredentialsMatcher.java:380)
>  
> ~[graylog.jar:?] 
>        at 
> org.apache.shiro.realm.AuthenticatingRealm.assertCredentialsMatch(AuthenticatingRealm.java:597)
>  
> ~[graylog.jar:?] 
>        at 
> org.apache.shiro.realm.AuthenticatingRealm.getAuthenticationInfo(AuthenticatingRealm.java:578)
>  
> ~[graylog.jar:?]
> .
> .
> .
> .
> 2016-11-03T15:22:29.818Z INFO  [SessionsResource] Invalid username or 
> password for user "admin"
>
>
> It's not referring to the password because it has an even number of 
> characters in it. Any pointers appreciated.
>
>
> Dylan
>
>

-- 
You received this message because you are subscribed to the Google Groups 
"Graylog Users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to graylog2+unsubscr...@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/graylog2/0365efde-be2c-432d-90fc-ce68e328b78d%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.

Reply via email to