Loading...
Loading...
After multiple SecurID authentication failures, the apmd process runs out of file descriptors. The logs indicate that "epoll_create() failed [Too many open files]," leading to failures in subsequent authentication attempts or Active Directory (AD) queries, which generate "Too many open files" errors. Additionally, sockets connecting to the aced daemon accumulate in a CLOSE_WAIT state
APMD cannot process new access policy requests when file descriptors are exhausted. All APM functionality—including Active Directory queries, authentication, and session management—is affected for all users. A restart of APMD is necessary to recover
- SecurID authentication is configured with logon retry enabled (maxLogonAttempt > 1) - Multiple authentication failures occur (e.g., wrong credentials, brute-force attempts) - The user does not complete the retry flow (session is abandoned after initial failure)
Restart the apmd service to recover file descriptors. Reducing the maxLogonAttempt value to 0 limits exposure but does not eliminate the issue. Implementing rate-limiting for login attempts at the network layer can help slow FD exhaustion.
The SecurID authentication module now immediately closes the socket connection to the aced daemon once the authentication process reaches a terminal state, either accepted or denied, instead of keeping it open for potential retries. Additionally, the session cleanup process has been corrected to properly locate and free the SecurID context object when sessions are aborted
F5 Integration
Learn more about where this data comes from
BugZero Plan
Streamline upgrades with automated vendor bug scrubs
BugZero Prevent
Wish you caught this bug sooner? Get proactive today.