<html><head></head><body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; "><div><br></div><div>Yes, but not just ADsvr2012, AD in general.</div><div><br></div><div>One thing to check is the certificate you have and what each of the DCs offer for the handshake.</div><div><br></div><div>They may offer different certs and one may not be in your java keystore of the IdP.</div><div>Also ensure the DNS resolution is what you expect it to be. </div><div>Do you override /etc/hosts? Do the pair of DC's respond to the same name?</div><div><br></div><div>Jacking up the log level for LDAP in the IdP will also highlight some of this too.</div><div><br></div><div>Using openssl you can quickly eyeball the chain to check:</div><div><br></div><div>openssl s_client -showcerts -connect 1.2.3.4:3269</div><div><br></div><div>HTH</div><div><br></div><div>Chris.</div><div><br></div><div><br></div><div><br></div><br><div><div>On 2014-05-20, at 8:59 AM, Tim Larson wrote:</div><br class="Apple-interchange-newline"><blockquote type="cite"><div lang="EN-US" link="#0563C1" vlink="#954F72"><div class="WordSection1" style="page: WordSection1; "><div style="margin-top: 0in; margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: 11pt; font-family: Calibri, sans-serif; ">Has anyone experience problems connecting the Shibboleth IDP to Active Directory running on Server 2012?<o:p></o:p></div><div style="margin-top: 0in; margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: 11pt; font-family: Calibri, sans-serif; "><o:p> </o:p></div><div style="margin-top: 0in; margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: 11pt; font-family: Calibri, sans-serif; ">We are running the Shibboleth 2.40 IDP and trying to authenticate against a Server 2012 Domain Controller. The exact same configuration works fine when connecting to a Server 2008 Domain controller in the same AD Domain. We are connecting on the global catalog port 3269, but have tried the LDAP ports as well.<o:p></o:p></div><div style="margin-top: 0in; margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: 11pt; font-family: Calibri, sans-serif; "><o:p> </o:p></div><div style="margin-top: 0in; margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: 11pt; font-family: Calibri, sans-serif; ">Does anyone know of any services that changed with 2012 or levels of encryption supported that may be causing problems with authenticating against this version of Active Directory?<o:p></o:p></div><div style="margin-top: 0in; margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: 11pt; font-family: Calibri, sans-serif; "><o:p> </o:p></div><div style="margin-top: 0in; margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: 11pt; font-family: Calibri, sans-serif; ">Tim Larson<o:p></o:p></div><div style="margin-top: 0in; margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: 11pt; font-family: Calibri, sans-serif; ">University of Central Florida<o:p></o:p></div><div style="margin-top: 0in; margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: 11pt; font-family: Calibri, sans-serif; "><o:p> </o:p></div><div style="margin-top: 0in; margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: 11pt; font-family: Calibri, sans-serif; "><o:p> </o:p></div></div>--<br>To unsubscribe from this list send an email to<span class="Apple-converted-space"> </span><a href="mailto:users-unsubscribe@shibboleth.net" style="color: rgb(5, 99, 193); text-decoration: underline; ">users-unsubscribe@shibboleth.net</a></div></blockquote></div><br></body></html>