- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Unable to add External Identity Source in Operations Console
I imported the LDAPS certificate successfully, but it always fails whenever testing the connection.
The FQDN and administrative credentials are supplied. RSA Authentication Manager version is 8.5.
Similar to the issue linked below.
connect to Active Directory via ldaps
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
First off, does regular LDAP work? If not then LDAPS has no chance. Also, is your certificate 2048 bit? Starting with 8.4, 1024 bit certs no longer work for LDAPS in Auth Manager.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Have you checked if the authentication manager IP address is able to reach the identity source through TCP 636 ?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes. I logged into Authentication Manager server using a SSH client and then used openssl command line to establish a connection to my server using port 636. That was how I got the server certificate to import into the Operations Console.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
First off, does regular LDAP work? If not then LDAPS has no chance. Also, is your certificate 2048 bit? Starting with 8.4, 1024 bit certs no longer work for LDAPS in Auth Manager.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
LDAP does work. The certificate is not 2048 bit.
However, I'm also testing against a different AD server where the certificate is 2048 bit. I'm still getting the same results over SSL and non-SSL. LDAP and LDAPS is working on this server.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I had to add the IP to the hosts file in Auth Manager for it to map to the domain. After that, it was able to connect over LDAP and I was able to successfully retrieve users from AD.
Thanks for the assistance.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Is the authentication manager DNS IP settings pointing to a different server were the AD is installed on ?
- Tags:
- Do yu
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes. They're on different servers within the same network. They're able to ping each other.
When creating a new external identity source, it doesn't seem to like IP address because the imported server certificate contains the FQDN. Since the FQDN is pointing to a different server, it didn't resolve the IP correctly until I added it to the host file.
