LDAP Error Codes using Microsoft Active Directory authentication
Sabo, Eric
Eric.Sabo at calu.edu
Fri May 31 07:56:55 EDT 2013
Paul,
Thanks for the information. I will relay this on.
From: users-bounces at shibboleth.net [mailto:users-bounces at shibboleth.net] On Behalf Of Caskey, Paul
Sent: Friday, May 31, 2013 7:46 AM
To: users at shibboleth.net
Subject: RE: LDAP Error Codes using Microsoft Active Directory authentication
It generally means bad credentials specified in your LDAP DataConnector in attribute-resolver.xml (bad username or password).
Specifically, I've encountered this when trying to get away with not putting a full DN as the user/principal name. In other words, don't specify the service account username as "domain\user" or "user at domain" which will work many times for AD, but rather give the config the full DN of the user (CN=name,OU=unit,DC=domain,DC=tld).
Also check for a disabled or expired service account.
From: users-bounces at shibboleth.net<mailto:users-bounces at shibboleth.net> [mailto:users-bounces at shibboleth.net] On Behalf Of Sabo, Eric
Sent: Friday, May 31, 2013 6:00 AM
To: users at shibboleth.net<mailto:users at shibboleth.net>
Subject: LDAP Error Codes using Microsoft Active Directory authentication
We are getting the following errors codes: Credentials not recognized [LDAP: error code 49 - 80090308: LdapErr: DSID-0C0903A9, comment: AcceptSecurityContext error, data 52e, v1db1], we are running Windows 2008 R2 AD forest level. Can anyone point us to how to resolve? Would a recent patch cause this?
If you need more information I can provide.
Thanks in advanced.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20130531/0f0db110/attachment-0001.html
More information about the users
mailing list