Howdy,
We enabled new AD GPO settings for LDAP channel binding and LDAP signing. I added the CA cert and configured our XI server for the new security and it works. I can't get the LS server to allow logins. The error is: "Can't contact LDAP server." The settings and cert are the same for the LS & XI servers.
I'd appreciate any help you can provide! Thanks!
Can't contact LDAP server
- jmichaelson
- Posts: 375
- Joined: Wed Aug 23, 2023 1:02 pm
Re: Can't contact LDAP server
Which version of Nagios Log Server are you using?
Here's an LDAP Troubleshooting document that we provide:
https://nagiosenterprises.my.site.com/s ... n-4057bf19
Here's an LDAP Troubleshooting document that we provide:
https://nagiosenterprises.my.site.com/s ... n-4057bf19
Please let us know if you have any other questions or concerns.
-Jason
-Jason
-
Jacobjsdhfg
- Posts: 9
- Joined: Tue Nov 07, 2023 1:57 am
Re: Can't contact LDAP server
It's difficult to provide a definitive solution[email protected] wrote: ↑Tue Jan 30, 2024 5:05 pm Howdy,
Cookie Clicker
We enabled new AD GPO settings for LDAP channel binding and LDAP signing. I added the CA cert and configured our XI server for the new security and it works. I can't get the LS server to allow logins. The error is: "Can't contact LDAP server." The settings and cert are the same for the LS & XI servers.
I'd appreciate any help you can provide! Thanks!
- jmichaelson
- Posts: 375
- Joined: Wed Aug 23, 2023 1:02 pm
Re: Can't contact LDAP server
As a follow up, can you use something like wireshark, or tcpdump to capture traffic going between your log server and the LDAP server? They'll be communicating on TCP port 389 or 636.
If your log server version is new enough, we've made some big improvements in the logging of LDAP problems, so if you're not on the latest version, I highly recommend moving toward it.
If your log server version is new enough, we've made some big improvements in the logging of LDAP problems, so if you're not on the latest version, I highly recommend moving toward it.
Please let us know if you have any other questions or concerns.
-Jason
-Jason