Page 2 of 3

Re: LDAP with TLS on Log Server

Posted: Mon Nov 09, 2015 1:10 pm
by CFT6Server
Any Update? Thanks.

Re: LDAP with TLS on Log Server

Posted: Mon Nov 09, 2015 2:43 pm
by scottwilkerson
ssax wrote:Can you post some sanitized screenshots of your current settings in NNA and in LS? I want to see what your settings are (and if you are using ldaps:// in the server box).

Re: LDAP with TLS on Log Server

Posted: Mon Nov 09, 2015 3:25 pm
by CFT6Server
That was PM'd to SSAX a while ago.....

Re: LDAP with TLS on Log Server

Posted: Mon Nov 09, 2015 4:21 pm
by ssax
Sorry about that, I think this may be that you need to import your CA certificates into openldap.

If you look at this file on your NNA server:

Code: Select all

/etc/openldap/ldap.conf
You should see a TLS_CACERT line, if you transfer the file that it points to over to your LS server and run this command, does it work?

Code: Select all

service httpd restart

Here is a guide to setting it up from scratch (I know it says it's for XI button the same process is needed):

https://assets.nagios.com/downloads/nag ... ponent.pdf

Re: LDAP with TLS on Log Server

Posted: Tue Nov 24, 2015 6:41 pm
by CFT6Server
Actually looking at our NNA server, it doesn't have the LDAP cert, but still seems to work with TLS.

I will go through and test this, but the first instance that I tested this on is still returning with "Can't contact LDAP server", but once TLS is taken off, it works.

Re: LDAP with TLS on Log Server

Posted: Wed Nov 25, 2015 1:54 pm
by hsmith
Let us know what testing it returns.

Thanks!

Re: LDAP with TLS on Log Server

Posted: Thu Nov 26, 2015 1:13 pm
by CFT6Server
So I confirmed that on NNA, I did not have to go through the certificate steps in order for LDAP to function. I just go to the page and set up LDAP and it works.
Now on Log server, I went ahead and installed the certificates but still getting the same issue when using TLS. Tested this on two separate Log servers.

Did you guys get TLS working in your testing?

Re: LDAP with TLS on Log Server

Posted: Thu Nov 26, 2015 7:09 pm
by Box293
Thanks for that. It's currently Thanksgiving holidays in the USA and the support office is closed. I would not expect a reply until next week.

Re: LDAP with TLS on Log Server

Posted: Fri Nov 27, 2015 1:51 pm
by CFT6Server
Thanks Box293. I gather as much. I have LDAP configured without TLS at the moment, so not dire. I'll see what the support team comes back with.

Re: LDAP with TLS on Log Server

Posted: Mon Nov 30, 2015 11:15 am
by ssax
I think it's probably best for us to move this into a ticket so that we can schedule a remote to dig into it. Please send an email to [email protected] with a descriptive subject and detailed body with a link back to this thread so that we can get it set up.

Thank you