Page 1 of 1

we are unable to switch to secure LDAP authentication

Posted: Wed Jan 08, 2020 5:48 pm
by dlukinski
Hello Nagios support

We've attempted implementing Secure LDAP authentication with XI, but no success.
After searching this forum: "Got the confirmation through a support ticket that Apache LDAP is not called by Nagios XI logins. Was a mistake from me to make the assumption that the authentication for Nagios XI and Nagios Core would work the same way and create this post in the wrong section. "
- would this be true? (our XI works with non-secure AD integration for years)


Neither TLS/SSL nor STARTTLS worked with our certificate. It might be that XI did not even try to query LDAP (similar cases other XI customers had)

What could be done to fix this problem?
- we have to switch to Secure LDAP in 1 week.


Thank you

Re: we are unable to switch to secure LDAP authentication

Posted: Wed Jan 08, 2020 6:12 pm
by dlukinski
dlukinski wrote:Hello Nagios support

We've attempted implementing Secure LDAP authentication with XI, but no success.
After searching this forum: "Got the confirmation through a support ticket that Apache LDAP is not called by Nagios XI logins. Was a mistake from me to make the assumption that the authentication for Nagios XI and Nagios Core would work the same way and create this post in the wrong section. "
- would this be true? (our XI works with non-secure AD integration for years)


Neither TLS/SSL nor STARTTLS worked with our certificate. It might be that XI did not even try to query LDAP (similar cases other XI customers had)

What could be done to fix this problem?
- we have to switch to Secure LDAP in 1 week.

--------------------------------------------------------
anything like
AuthLDAPURL "ldap://192.168.68.2/DC=cool,DC=blue?sAMAccountName?sub?(objectClass=*)" does not exist in in our /etc/httpd/conf.d

Thank you

Re: we are unable to switch to secure LDAP authentication

Posted: Wed Jan 08, 2020 6:59 pm
by Box293
Have you followed both of these guides?:

https://assets.nagios.com/downloads/nag ... ios-XI.pdf

https://assets.nagios.com/downloads/nag ... ponent.pdf

What exactly is not working?

This KB article provides troubleshooting steps:

https://support.nagios.com/kb/article/a ... n-600.html

Re: we are unable to switch to secure LDAP authentication

Posted: Mon Jan 13, 2020 12:16 pm
by dlukinski
Box293 wrote:Have you followed both of these guides?:

https://assets.nagios.com/downloads/nag ... ios-XI.pdf

https://assets.nagios.com/downloads/nag ... ponent.pdf

What exactly is not working?

This KB article provides troubleshooting steps:

https://support.nagios.com/kb/article/a ... n-600.html
We followed the manuals, but cannot login in the end.

Re: we are unable to switch to secure LDAP authentication

Posted: Mon Jan 13, 2020 6:36 pm
by Box293
What information are you able to gather when following the troubleshooting article?

https://support.nagios.com/kb/article/a ... n-600.html

Re: we are unable to switch to secure LDAP authentication

Posted: Fri Feb 21, 2020 2:31 pm
by dlukinski
Box293 wrote:What information are you able to gather when following the troubleshooting article?

https://support.nagios.com/kb/article/a ... n-600.html
Now down to 1 XI installation, refusing to switch (one that is not from your VM templates stock) and a LOG server.
- scheduled XI with you and waiting for LOG 2.1.5

Re: we are unable to switch to secure LDAP authentication

Posted: Fri Feb 21, 2020 3:21 pm
by benjaminsmith
Hi Dimitri,

Can you enable debugging as described in the troubleshooting guide and post the log? Thanks.

Follow the steps in the last section for Nagios XI:

Active Directory / LDAP - Troubleshooting Authentication Integration

Re: we are unable to switch to secure LDAP authentication

Posted: Tue Mar 10, 2020 4:25 pm
by dlukinski
benjaminsmith wrote:Hi Dimitri,

Can you enable debugging as described in the troubleshooting guide and post the log? Thanks.

Follow the steps in the last section for Nagios XI:

Active Directory / LDAP - Troubleshooting Authentication Integration
Please close this one: only Nagios LOG remains (developers to patch one)

Re: we are unable to switch to secure LDAP authentication

Posted: Tue Mar 10, 2020 4:28 pm
by benjaminsmith
Hi Dimitri,

Ok. We'll close this out. Thanks for the update.