we are unable to switch to secure LDAP authentication

This support forum board is for support questions relating to Nagios XI, our flagship commercial network monitoring solution.
Locked
dlukinski
Posts: 1130
Joined: Tue Oct 06, 2015 9:42 am

we are unable to switch to secure LDAP authentication

Post by dlukinski »

Hello Nagios support

We've attempted implementing Secure LDAP authentication with XI, but no success.
After searching this forum: "Got the confirmation through a support ticket that Apache LDAP is not called by Nagios XI logins. Was a mistake from me to make the assumption that the authentication for Nagios XI and Nagios Core would work the same way and create this post in the wrong section. "
- would this be true? (our XI works with non-secure AD integration for years)


Neither TLS/SSL nor STARTTLS worked with our certificate. It might be that XI did not even try to query LDAP (similar cases other XI customers had)

What could be done to fix this problem?
- we have to switch to Secure LDAP in 1 week.


Thank you
dlukinski
Posts: 1130
Joined: Tue Oct 06, 2015 9:42 am

Re: we are unable to switch to secure LDAP authentication

Post by dlukinski »

dlukinski wrote:Hello Nagios support

We've attempted implementing Secure LDAP authentication with XI, but no success.
After searching this forum: "Got the confirmation through a support ticket that Apache LDAP is not called by Nagios XI logins. Was a mistake from me to make the assumption that the authentication for Nagios XI and Nagios Core would work the same way and create this post in the wrong section. "
- would this be true? (our XI works with non-secure AD integration for years)


Neither TLS/SSL nor STARTTLS worked with our certificate. It might be that XI did not even try to query LDAP (similar cases other XI customers had)

What could be done to fix this problem?
- we have to switch to Secure LDAP in 1 week.

--------------------------------------------------------
anything like
AuthLDAPURL "ldap://192.168.68.2/DC=cool,DC=blue?sAMAccountName?sub?(objectClass=*)" does not exist in in our /etc/httpd/conf.d

Thank you
User avatar
Box293
Too Basu
Posts: 5126
Joined: Sun Feb 07, 2010 10:55 pm
Location: Deniliquin, Australia
Contact:

Re: we are unable to switch to secure LDAP authentication

Post by Box293 »

Have you followed both of these guides?:

https://assets.nagios.com/downloads/nag ... ios-XI.pdf

https://assets.nagios.com/downloads/nag ... ponent.pdf

What exactly is not working?

This KB article provides troubleshooting steps:

https://support.nagios.com/kb/article/a ... n-600.html
As of May 25th, 2018, all communications with Nagios Enterprises and its employees are covered under our new Privacy Policy.
dlukinski
Posts: 1130
Joined: Tue Oct 06, 2015 9:42 am

Re: we are unable to switch to secure LDAP authentication

Post by dlukinski »

Box293 wrote:Have you followed both of these guides?:

https://assets.nagios.com/downloads/nag ... ios-XI.pdf

https://assets.nagios.com/downloads/nag ... ponent.pdf

What exactly is not working?

This KB article provides troubleshooting steps:

https://support.nagios.com/kb/article/a ... n-600.html
We followed the manuals, but cannot login in the end.
User avatar
Box293
Too Basu
Posts: 5126
Joined: Sun Feb 07, 2010 10:55 pm
Location: Deniliquin, Australia
Contact:

Re: we are unable to switch to secure LDAP authentication

Post by Box293 »

What information are you able to gather when following the troubleshooting article?

https://support.nagios.com/kb/article/a ... n-600.html
As of May 25th, 2018, all communications with Nagios Enterprises and its employees are covered under our new Privacy Policy.
dlukinski
Posts: 1130
Joined: Tue Oct 06, 2015 9:42 am

Re: we are unable to switch to secure LDAP authentication

Post by dlukinski »

Box293 wrote:What information are you able to gather when following the troubleshooting article?

https://support.nagios.com/kb/article/a ... n-600.html
Now down to 1 XI installation, refusing to switch (one that is not from your VM templates stock) and a LOG server.
- scheduled XI with you and waiting for LOG 2.1.5
benjaminsmith
Posts: 5324
Joined: Wed Aug 22, 2018 4:39 pm
Location: saint paul

Re: we are unable to switch to secure LDAP authentication

Post by benjaminsmith »

Hi Dimitri,

Can you enable debugging as described in the troubleshooting guide and post the log? Thanks.

Follow the steps in the last section for Nagios XI:

Active Directory / LDAP - Troubleshooting Authentication Integration
As of May 25th, 2018, all communications with Nagios Enterprises and its employees are covered under our new Privacy Policy.

Be sure to check out our Knowledgebase for helpful articles and solutions!
dlukinski
Posts: 1130
Joined: Tue Oct 06, 2015 9:42 am

Re: we are unable to switch to secure LDAP authentication

Post by dlukinski »

benjaminsmith wrote:Hi Dimitri,

Can you enable debugging as described in the troubleshooting guide and post the log? Thanks.

Follow the steps in the last section for Nagios XI:

Active Directory / LDAP - Troubleshooting Authentication Integration
Please close this one: only Nagios LOG remains (developers to patch one)
benjaminsmith
Posts: 5324
Joined: Wed Aug 22, 2018 4:39 pm
Location: saint paul

Re: we are unable to switch to secure LDAP authentication

Post by benjaminsmith »

Hi Dimitri,

Ok. We'll close this out. Thanks for the update.
As of May 25th, 2018, all communications with Nagios Enterprises and its employees are covered under our new Privacy Policy.

Be sure to check out our Knowledgebase for helpful articles and solutions!
Locked