Problems connecting to 389 directory server
Daniel Fisher
dfisher at vt.edu
Mon Dec 4 12:39:19 EST 2017
On Mon, Dec 4, 2017 at 10:16 AM, Darren Boss <darren.boss at computecanada.ca>
wrote:
> Yes, this is another well documented "PKIX path building failed" issue but
> there is a twist. I've triple checked the LDAP server's cert and the CA
> cert, tried both by adding them to the ldap-server.crt file, constructed a
> trustStore and tweaked the settings to use ldap-server.truststore with the
> keyStoreTrust setting. We are using the CA cert from this deployment for
> sssd config, no issues. The certs are valid, not expired. Using ldapsearch
> I can test connection using LDAPTLS_CACERT=ldap-server.crt before the
> command, no connection issues. I've used the SSLPoke utility to make sure I
> can connect to to the LDAP server and I can when using the trust store I
> created for Shibboleth. I've tried all combinations of
> idp.authn.LDAP.useStartTLS and idp.authn.LDAP.useSSL.
>
> What else is there to check?
>
Are you using LDAP for authentication or attribute resolution?
What is the error message you are getting?
--Daniel Fisher
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20171204/434dfd7d/attachment.html>
More information about the users
mailing list