Con't contact LDAP server when using AD integration with cert

This support forum board is for support questions relating to Nagios Log Server, our solution for managing and monitoring critical log data.
Post Reply
scheived
Posts: 18
Joined: Tue Jul 16, 2013 9:53 am

Con't contact LDAP server when using AD integration with cert

Post by scheived »

I'm attempting to set up Nagios log server AD Integration with a self signed ca cert on the domain controller.

Server Type: Active Directory
Encryption Method SSL/TLS
Added domain certificate

When I log in I'm receiving message Can't contact LDAP server.
Last edited by scheived on Wed Dec 13, 2023 3:51 pm, edited 1 time in total.
scheived
Posts: 18
Joined: Tue Jul 16, 2013 9:53 am

Re: Con't contact LDAP server when using AD integration with cert

Post by scheived »

I've verified I can get to the domain controller with,
nmap domain controller -p 636
Host is up (0.00024s latency).

PORT STATE SERVICE
636/tcp open ldapssl

Nmap done: 1 IP address (1 host up) scanned in 0.10 seconds
scheived
Posts: 18
Joined: Tue Jul 16, 2013 9:53 am

Re: Con't contact LDAP server when using AD integration with cert

Post by scheived »

Done everything I can think of.

Tried importing the domain cert multiple different ways including with the domain servers local cert
Tried using ldap as well as adding the cert to openldap's cert store
Changing Encryption Method to none the user is able to log in but not SSL/TLS

I assume other people are doing activedirectory integration how are you doing it?
jsimon
Posts: 104
Joined: Wed Aug 23, 2023 11:27 am

Re: Con't contact LDAP server when using AD integration with cert

Post by jsimon »

Hi @scheived,

Can you advise what Linux distro and version you are using? We have some troubleshooting steps that we can advise for AD issues, but there is a bug with the troubleshooting process on specific Enterprise Linux distros that we have a fix underway for. Knowing this would help in determining next steps.

If you are on Enterprise Linux 7 or older, or are on a Linux distro that is NOT using php-fpm, I would recommend following these steps to enable AD debugging, which should give you more insights.

https://nagiosenterprises.my.site.com/s ... n-4057bf19

Let us know if this doesn't work for you, or if you have any other questions.
Post Reply