<div dir="ltr">And to be clear, the jaas.config for this lone "ldaps" source is ldaps with tls=false and ssl=true; did not see explicit mention of the ssl=true component, so I've tried with ssl=false as well, receiving same logged error on attempted connection:<br>





<p class="gmail-p1" style="margin:0px;font-variant-numeric:normal;font-variant-east-asian:normal;font-stretch:normal;font-size:14px;line-height:normal;font-family:Courier;color:rgb(59,35,34);background-color:rgba(215,211,183,0.85)"><span class="gmail-s1" style="font-variant-ligatures:no-common-ligatures">DEBUG [137.229.6.122] org.ldaptive.provider.jndi.JndiConnectionFactory:105 ><span class="gmail-Apple-converted-space">  </span>Error connecting to LDAP URL: ldaps://<a href="http://cas-auth-t.alaska.edu:6361">cas-auth-t.alaska.edu:6361</a></span></p>
<p class="gmail-p1" style="margin:0px;font-variant-numeric:normal;font-variant-east-asian:normal;font-stretch:normal;font-size:14px;line-height:normal;font-family:Courier;color:rgb(59,35,34);background-color:rgba(215,211,183,0.85)"><span class="gmail-s1" style="font-variant-ligatures:no-common-ligatures">org.ldaptive.provider.ConnectionException: javax.naming.CommunicationException: <a href="http://cas-auth-t.alaska.edu:6361">cas-auth-t.alaska.edu:6361</a> [Root exception is javax.net.ssl.SSLHandshakeException: sun.security.validator.ValidatorException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target]</span></p><br>





<p class="gmail-p1" style="margin:0px;font-variant-numeric:normal;font-variant-east-asian:normal;font-stretch:normal;font-size:14px;line-height:normal;font-family:Courier;color:rgb(59,35,34);background-color:rgba(215,211,183,0.85)"><span class="gmail-s1" style="font-variant-ligatures:no-common-ligatures"><span class="gmail-Apple-converted-space"> </span>// UA Authenticator is proxy to AD allows some expired accounts to authenticate</span></p>
<p class="gmail-p1" style="margin:0px;font-variant-numeric:normal;font-variant-east-asian:normal;font-stretch:normal;font-size:14px;line-height:normal;font-family:Courier;color:rgb(59,35,34);background-color:rgba(215,211,183,0.85)"><span class="gmail-s1" style="font-variant-ligatures:no-common-ligatures"><span class="gmail-Apple-converted-space">  </span>org.ldaptive.jaas.LdapLoginModule sufficient</span></p>
<p class="gmail-p1" style="margin:0px;font-variant-numeric:normal;font-variant-east-asian:normal;font-stretch:normal;font-size:14px;line-height:normal;font-family:Courier;color:rgb(59,35,34);background-color:rgba(215,211,183,0.85)"><span class="gmail-s1" style="font-variant-ligatures:no-common-ligatures"><span class="gmail-Apple-converted-space">    </span>ldapUrl="ldaps://<a href="http://cas-auth-t.alaska.edu:6361">cas-auth-t.alaska.edu:6361</a>"</span></p>
<p class="gmail-p1" style="margin:0px;font-variant-numeric:normal;font-variant-east-asian:normal;font-stretch:normal;font-size:14px;line-height:normal;font-family:Courier;color:rgb(59,35,34);background-color:rgba(215,211,183,0.85)"><span class="gmail-s1" style="font-variant-ligatures:no-common-ligatures"><span class="gmail-Apple-converted-space">    </span>baseDn="dc=ua,dc=adt,dc=alaska,dc=edu"</span></p>
<p class="gmail-p1" style="margin:0px;font-variant-numeric:normal;font-variant-east-asian:normal;font-stretch:normal;font-size:14px;line-height:normal;font-family:Courier;color:rgb(59,35,34);background-color:rgba(215,211,183,0.85)"><span class="gmail-s1" style="font-variant-ligatures:no-common-ligatures"><span class="gmail-Apple-converted-space">    </span>bindDn="CN=...,ou=...,dc=ua,dc=adt,dc=alaska,dc=edu"</span></p>
<p class="gmail-p1" style="margin:0px;font-variant-numeric:normal;font-variant-east-asian:normal;font-stretch:normal;font-size:14px;line-height:normal;font-family:Courier;color:rgb(59,35,34);background-color:rgba(215,211,183,0.85)"><span class="gmail-s1" style="font-variant-ligatures:no-common-ligatures"><span class="gmail-Apple-converted-space">    </span>bindCredential="•••••••••••"</span></p>
<p class="gmail-p1" style="margin:0px;font-variant-numeric:normal;font-variant-east-asian:normal;font-stretch:normal;font-size:14px;line-height:normal;font-family:Courier;color:rgb(59,35,34);background-color:rgba(215,211,183,0.85)"><span class="gmail-s1" style="font-variant-ligatures:no-common-ligatures"><span class="gmail-Apple-converted-space">    </span>subtreeSearch="true"</span></p>
<p class="gmail-p1" style="margin:0px;font-variant-numeric:normal;font-variant-east-asian:normal;font-stretch:normal;font-size:14px;line-height:normal;font-family:Courier;color:rgb(59,35,34);background-color:rgba(215,211,183,0.85)"><span class="gmail-s1" style="font-variant-ligatures:no-common-ligatures"><span class="gmail-Apple-converted-space">    </span>sslSocketFactory="{trustCertificates=file:/opt/shibboleth-idp-D/credentials/UAADrootCAs-P-Q-D-T-InC.pem}"</span></p>
<p class="gmail-p1" style="margin:0px;font-variant-numeric:normal;font-variant-east-asian:normal;font-stretch:normal;font-size:14px;line-height:normal;font-family:Courier;color:rgb(59,35,34);background-color:rgba(215,211,183,0.85)"><span class="gmail-s1" style="font-variant-ligatures:no-common-ligatures"><span class="gmail-Apple-converted-space">    </span>ssl="true"</span></p>
<p class="gmail-p1" style="margin:0px;font-variant-numeric:normal;font-variant-east-asian:normal;font-stretch:normal;font-size:14px;line-height:normal;font-family:Courier;color:rgb(59,35,34);background-color:rgba(215,211,183,0.85)"><span class="gmail-s1" style="font-variant-ligatures:no-common-ligatures"><span class="gmail-Apple-converted-space">    </span>tls="false"</span></p>
<p class="gmail-p1" style="margin:0px;font-variant-numeric:normal;font-variant-east-asian:normal;font-stretch:normal;font-size:14px;line-height:normal;font-family:Courier;color:rgb(59,35,34);background-color:rgba(215,211,183,0.85)"><span class="gmail-s1" style="font-variant-ligatures:no-common-ligatures"><span class="gmail-Apple-converted-space">    </span>userFilter="(|(sAMAccountName={user})(uaIdentifier={user}))"</span></p>
<p class="gmail-p1" style="margin:0px;font-variant-numeric:normal;font-variant-east-asian:normal;font-stretch:normal;font-size:14px;line-height:normal;font-family:Courier;color:rgb(59,35,34);background-color:rgba(215,211,183,0.85)"><span class="gmail-s1" style="font-variant-ligatures:no-common-ligatures"><span class="gmail-Apple-converted-space">    </span>connectTimeout="3000"</span></p>
<p class="gmail-p1" style="margin:0px;font-variant-numeric:normal;font-variant-east-asian:normal;font-stretch:normal;font-size:14px;line-height:normal;font-family:Courier;color:rgb(59,35,34);background-color:rgba(215,211,183,0.85)"><span class="gmail-s1" style="font-variant-ligatures:no-common-ligatures"><span class="gmail-Apple-converted-space">    </span>resultTimeout="3000"</span></p>
<p class="gmail-p1" style="margin:0px;font-variant-numeric:normal;font-variant-east-asian:normal;font-stretch:normal;font-size:14px;line-height:normal;font-family:Courier;color:rgb(59,35,34);background-color:rgba(215,211,183,0.85)"><span class="gmail-s1" style="font-variant-ligatures:no-common-ligatures"><span class="gmail-Apple-converted-space">    </span>;</span></p></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Wed, Jun 3, 2020 at 7:32 AM <a href="mailto:db@alaska.edu">db@alaska.edu</a> <<a href="mailto:dabantz@alaska.edu">dabantz@alaska.edu</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div dir="auto">IdP 3.4.6 java 8.5.55<div><div><br></div><div>Trust configured in JAAS config with explicitly trusted CAs in PEM trust file. </div><div><br></div><div>[Primary authN ldap servers used (7 AD DCs in 4 domains) use private CAs; this failover proxy is the exception using “known” CA, but I used the same strategy: its CA - and now server cert itself - are both in the same file as the private CAs.</div><div><br></div><div>This is the only one of 11 ldap services using “ldaps” - AD DCs all use StartTLS; other proxies use ldap.]<br><br><div dir="ltr"><div>David.Bantz<span>@Alaska.edu</span><div><span><br></span></div></div></div><div dir="ltr"><br><blockquote type="cite">On Jun 3, 2020, at 04:39, Daniel Fisher:<br></blockquote></div><blockquote type="cite"><div dir="ltr"><div dir="ltr"><div class="gmail_quote"><div><br></div><div class="gmail_default" style="font-family:verdana,sans-serif">Do you want to configure trust as part of the JAAS config or are you attempting to use the default JVM trust? Also, just to confirm, we're talking about IDPv3?</div><div class="gmail_default" style="font-family:verdana,sans-serif"><br></div><div class="gmail_default" style="font-family:verdana,sans-serif">--Daniel Fisher</div><div class="gmail_default" style="font-family:verdana,sans-serif"></div></div></div>
<br></div></blockquote></div></div></div></blockquote></div>