<div dir="ltr"><div class="gmail_extra"><div class="gmail_quote">On Mon, Dec 4, 2017 at 10:16 AM, Darren Boss <span dir="ltr"><<a href="mailto:darren.boss@computecanada.ca" target="_blank">darren.boss@computecanada.ca</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div dir="ltr"><div><div><div>Yes, this is another well documented "PKIX path building failed" issue but there is a twist. I've triple checked the LDAP server's cert and the CA cert, tried both by adding them to the ldap-server.crt file, constructed a trustStore and tweaked the settings to use ldap-server.truststore with the keyStoreTrust setting. We are using the CA cert from this deployment for sssd config, no issues. The certs are valid, not expired. Using ldapsearch I can test connection using <span class="gmail-m_3394228090755736729inbox-inbox-st">LDAPTLS_CACERT=ldap-server.crt before the command, no connection issues. I've used the SSLPoke utility to make sure I can connect to to the LDAP server and I can when using the trust store I created for Shibboleth. <span class="gmail-m_3394228090755736729inbox-inbox-inbox-inbox-st">I've tried all combinations of idp.authn.LDAP.useStartTLS and idp.authn.LDAP.useSSL.</span><br><br></span></div><span class="gmail-m_3394228090755736729inbox-inbox-st">What else is there to check?</span></div></div></div></blockquote><div><br></div>Are you using LDAP for authentication or attribute resolution?<div>What is the error message you are getting? </div><div><br></div><div>--Daniel Fisher<br></div><div><br></div></div></div></div>