Problems connecting to 389 directory server
Darren Boss
darren.boss at computecanada.ca
Mon Dec 4 12:58:09 EST 2017
I have experience using OpenLDAP for authentication and attribute
resolution, it's what our Compute Canada IdP uses and I've had no issues
establishing TLS connection.
For this installation we are attempting to setup an IdP for a platform
using our infrastructure and they use 389 Directory Server (
http://directory.fedoraproject.org/). Again, I'm setting it up for both
authentication and attribute resolution. On startup, here is a snipit of
the relevant error message.
2017-12-02 16:52:51,564 - ERROR
[net.shibboleth.idp.attribute.resolver.dc.ldap.impl.ConnectionFactoryValidator:152]
- Connection factory validation failed
org.ldaptive.provider.ConnectionException:
javax.naming.CommunicationException: <redacted>:636 [Root exception is
javax.net.ssl.SSLHandshakeException: sun.security.validator.Validato
rException: PKIX path building failed:
sun.security.provider.certpath.SunCertPathBuilderException: unable to find
valid certification path to requested target]
More of the log messages available at:
https://pastebin.com/huZK9FUB
--
*Darren Boss*
*Senior Programmer/Analyst*
*Programmeur-analyste principal*
*darren.boss at computecanada.ca <darren.boss at computecanada.ca>*
*(o) 416.228.1234 x *230
*(c) 919.525.0083*
155 University Ave, Suite 302 Toronto, ON M5H 3B7
www.computecanada.ca / www.calculcanada.ca
@ComputeCanada
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20171204/57e32dcd/attachment.html>
More information about the users
mailing list