<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic LDAPS and Active Directory issue in Security</title>
    <link>https://community.splunk.com/t5/Security/LDAPS-and-Active-Directory-issue/m-p/23326#M785</link>
    <description>&lt;P&gt;I have splunk 4.3.3 connecting to AD for auth fine. Users/groups mapped. It's all working.&lt;/P&gt;

&lt;P&gt;But I can't get it to work over SSL. If switch the port to 636 or 3269 and click the SSL box, it fails with a "Can't contact LDAP server"&lt;/P&gt;

&lt;P&gt;But here's the thing - it works fine with ldapsearch. I've confirmed the certs are all in place (I've done similar auth setups on apache and other products).&lt;/P&gt;

&lt;P&gt;All 3 of these return correctly ("# search result search: 2 result: 0 Success"):&lt;/P&gt;

&lt;P&gt;ldapsearch -x -H ldap://dc5.me.local -D "CN=LDAPReader,OU=Utility,DC=me,DC=local" -w "secret" -b "DC=me,DC=local" "userNameAttribute=*"&lt;/P&gt;

&lt;P&gt;ldapsearch -x -H ldaps://dc5.me.local -D "CN=LDAPReader,OU=Utility,DC=me,DC=local" -w "secret" -b "DC=me,DC=local" "userNameAttribute=*"&lt;/P&gt;

&lt;P&gt;ldapsearch -x -H ldaps://dc5.me.local:3269 -D "CN=LDAPReader,OU=Utility,DC=me,DC=local" -w "secret" -b "DC=me,DC=local" "userNameAttribute=*"&lt;/P&gt;

&lt;P&gt;I've copied the same CA bundle files from /etc/pki/tls/certs/.&lt;BR /&gt;
I've edited the ldap.conf files (both splunk's and the box) so they point to the right certs/files. Everything back to the root is world readable (plus, splunk is running as root).&lt;/P&gt;

&lt;P&gt;I'm obviously missing something but I don't know where to look next since all the debugging steps I've seen in the docs and forums all work right.&lt;/P&gt;</description>
    <pubDate>Wed, 01 Aug 2012 23:21:44 GMT</pubDate>
    <dc:creator>bwieseeps</dc:creator>
    <dc:date>2012-08-01T23:21:44Z</dc:date>
    <item>
      <title>LDAPS and Active Directory issue</title>
      <link>https://community.splunk.com/t5/Security/LDAPS-and-Active-Directory-issue/m-p/23326#M785</link>
      <description>&lt;P&gt;I have splunk 4.3.3 connecting to AD for auth fine. Users/groups mapped. It's all working.&lt;/P&gt;

&lt;P&gt;But I can't get it to work over SSL. If switch the port to 636 or 3269 and click the SSL box, it fails with a "Can't contact LDAP server"&lt;/P&gt;

&lt;P&gt;But here's the thing - it works fine with ldapsearch. I've confirmed the certs are all in place (I've done similar auth setups on apache and other products).&lt;/P&gt;

&lt;P&gt;All 3 of these return correctly ("# search result search: 2 result: 0 Success"):&lt;/P&gt;

&lt;P&gt;ldapsearch -x -H ldap://dc5.me.local -D "CN=LDAPReader,OU=Utility,DC=me,DC=local" -w "secret" -b "DC=me,DC=local" "userNameAttribute=*"&lt;/P&gt;

&lt;P&gt;ldapsearch -x -H ldaps://dc5.me.local -D "CN=LDAPReader,OU=Utility,DC=me,DC=local" -w "secret" -b "DC=me,DC=local" "userNameAttribute=*"&lt;/P&gt;

&lt;P&gt;ldapsearch -x -H ldaps://dc5.me.local:3269 -D "CN=LDAPReader,OU=Utility,DC=me,DC=local" -w "secret" -b "DC=me,DC=local" "userNameAttribute=*"&lt;/P&gt;

&lt;P&gt;I've copied the same CA bundle files from /etc/pki/tls/certs/.&lt;BR /&gt;
I've edited the ldap.conf files (both splunk's and the box) so they point to the right certs/files. Everything back to the root is world readable (plus, splunk is running as root).&lt;/P&gt;

&lt;P&gt;I'm obviously missing something but I don't know where to look next since all the debugging steps I've seen in the docs and forums all work right.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Aug 2012 23:21:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/LDAPS-and-Active-Directory-issue/m-p/23326#M785</guid>
      <dc:creator>bwieseeps</dc:creator>
      <dc:date>2012-08-01T23:21:44Z</dc:date>
    </item>
    <item>
      <title>Re: LDAPS and Active Directory issue</title>
      <link>https://community.splunk.com/t5/Security/LDAPS-and-Active-Directory-issue/m-p/23327#M786</link>
      <description>&lt;P&gt;so the /en-GB/debug/sso page doesn't show anything that is broken?&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jan 2014 02:39:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/LDAPS-and-Active-Directory-issue/m-p/23327#M786</guid>
      <dc:creator>Lucas_K</dc:creator>
      <dc:date>2014-01-08T02:39:34Z</dc:date>
    </item>
  </channel>
</rss>

