Problems connecting to 389 directory server

Darren Boss darren.boss at computecanada.ca
Mon Dec 4 10:16:31 EST 2017


Yes, this is another well documented "PKIX path building failed" issue but
there is a twist. I've triple checked the LDAP server's cert and the CA
cert, tried both by adding them to the ldap-server.crt file, constructed a
trustStore and tweaked the settings to use ldap-server.truststore with the
keyStoreTrust setting. We are using the CA cert from this deployment for
sssd config, no issues. The certs are valid, not expired. Using ldapsearch
I can test connection using LDAPTLS_CACERT=ldap-server.crt before the
command, no connection issues. I've used the SSLPoke utility to make sure I
can connect to to the LDAP server and I can when using the trust store I
created for Shibboleth. I've tried all combinations of
idp.authn.LDAP.useStartTLS and idp.authn.LDAP.useSSL.

What else is there to check? It doesn't seem to be an issue with Java as
I've been able to get a connection with SSLPoke using the same JVM. The
only thing I can see different about the certificate used by this ldap
server and my working ldap server is that the failing 389 certs is that
their signature algo is sha1WithRSAEncryption where our production ldap
uses sha256WithRSAEncryption.

I'm using version 3.3.2. My JVM is Zulu version 8.25.0.1 which is Java
8.0.152.
-- 

*Darren Boss*
*Senior Programmer/Analyst*
*Programmeur-analyste principal*
*darren.boss at computecanada.ca <darren.boss at computecanada.ca>*
*(o) 416.228.1234 x *230
*(c) 919.525.0083*

155 University Ave, Suite 302 Toronto, ON M5H 3B7
www.computecanada.ca / www.calculcanada.ca
@ComputeCanada
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20171204/f584a9a7/attachment.html>


More information about the users mailing list