How to Fix IPhone Password Incorrect Error that Happens with Google Apps and LDAP

Even when You Know the Password

Charlotte Welch
At my work, we've started this past week using Google Apps for Education. Google Apps has been well-received by the users. We are using an LDAP single-sign in web page for users to login with so they can use their Active Directory username password combination and don't need to remember still another password.

A number of our users have iPhones, and some have had trouble getting their account setup on the phone. Not all iPhones. Sometimes iPhone 3, sometimes iPhone 4. Up-to-date system, or not, seemed to have no bearing.

The error was that the phone gave an incorrect password message even though the user was using the correct password. If they went to the Single Sign-on page on the phone, they could log-in there. Just had the error on the Mail app built into the phone. My iPhone worked fine. It was a mystery. Searching over the internet yielded lots of discussion of the problem, but no solution. There were also reports of getting a Captcha to reset the password after getting locked out.

One evening, I was staying late to work with a student on the problem. I tried to reset her password on the Google admin page to skip the sync time with the AD/LDAP. After a couple of resets this way, I realized there was a message in red letters. The password had to be a minimum of eight characters, it said. mmm Could it be related? My password was only six characters long and I could login without any problem. I reset the password to longer than eight characters. It worked!! We reset the password in Active Directory to keep it in sync.

It made sense, sso was authenticating against our Active Directory while iPhone Mail was using m.gmail.com. But why was I able to get my mail with only six characters? I did some more research and found that Google Apps had started requiring eight characters on March 14, 2011. Earlier Google Apps users would be grandfathered and be able to keep their password. If they changed their password, it would require eight characters. I had my account created during the pilot phase, which began in early March and so was grandfathered in.

So the solution was to have the user reset their password to a longer one, login and out of sso, to cache their new ldap password with Google, and then proceed to set up the iPhone.

Next step is to figure how to change the minimum password length in Active Directory without total chaos.

Published by Charlotte Welch

I am a librarian, IT support person, grandmother and home cook. DH and I share our home with our extended family, for a total of seven around the house. I like to fish, enjoy the outdoors, read, and use a...  View profile

To comment, please sign in to your Yahoo! account, or sign up for a new account.