<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: LDAP by SSL using WIndows 2012R2 cannot connect to Active Directory server in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/LDAP-by-SSL-using-WIndows-2012R2-cannot-connect-to-Active/m-p/267916#M51385</link>
    <description>&lt;P&gt;Can you paste the relevant error logs you are seeing with confidential information redacted. &lt;/P&gt;</description>
    <pubDate>Thu, 08 Dec 2016 00:46:53 GMT</pubDate>
    <dc:creator>rdimri_splunk</dc:creator>
    <dc:date>2016-12-08T00:46:53Z</dc:date>
    <item>
      <title>LDAP by SSL using WIndows 2012R2 cannot connect to Active Directory server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/LDAP-by-SSL-using-WIndows-2012R2-cannot-connect-to-Active/m-p/267915#M51384</link>
      <description>&lt;P&gt;Trying to use LDAP with SSL and running into issue 'Can't contact LDAP server'.  Looked on Splunk Answers and saw similar issue at URL &lt;A href="https://answers.splunk.com/answers/431970/ssl-ldap-breaks-from-633-to-635.html"&gt;https://answers.splunk.com/answers/431970/ssl-ldap-breaks-from-633-to-635.html&lt;/A&gt;  Tried the solution mentioned in this Answers post without success.  Has anyone else run into this issue?  Could this be a cipher suite issue between the LDAP server and Splunk?&lt;/P&gt;

&lt;P&gt;Splunk version 6.3.3&lt;BR /&gt;
OpenSSL version 1.0.2d&lt;BR /&gt;
Running Windows 2012R2 Standard edition&lt;BR /&gt;
Can connect over port 636 to the Active Directory server using Softerra&lt;BR /&gt;
LDAP over port 389 works fine with the same AD server&lt;/P&gt;</description>
      <pubDate>Wed, 07 Dec 2016 20:30:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/LDAP-by-SSL-using-WIndows-2012R2-cannot-connect-to-Active/m-p/267915#M51384</guid>
      <dc:creator>ewienholt</dc:creator>
      <dc:date>2016-12-07T20:30:45Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP by SSL using WIndows 2012R2 cannot connect to Active Directory server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/LDAP-by-SSL-using-WIndows-2012R2-cannot-connect-to-Active/m-p/267916#M51385</link>
      <description>&lt;P&gt;Can you paste the relevant error logs you are seeing with confidential information redacted. &lt;/P&gt;</description>
      <pubDate>Thu, 08 Dec 2016 00:46:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/LDAP-by-SSL-using-WIndows-2012R2-cannot-connect-to-Active/m-p/267916#M51385</guid>
      <dc:creator>rdimri_splunk</dc:creator>
      <dc:date>2016-12-08T00:46:53Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP by SSL using WIndows 2012R2 cannot connect to Active Directory server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/LDAP-by-SSL-using-WIndows-2012R2-cannot-connect-to-Active/m-p/267917#M51386</link>
      <description>&lt;P&gt;We believe the problem is matching the TLS_CIPHER_SUITE line in the ldap.conf file with the cipher suite on the AD server.  The pertinent output of the 'openssl s_client -showcerts -host hostname -port 636' command is.....&lt;BR /&gt;
SSL-Session:&lt;BR /&gt;
    Protocol  : TLSv1.2&lt;BR /&gt;
    Cipher    : ECDHE-RSA-AES256-SHA384&lt;/P&gt;

&lt;P&gt;The error log follows.....&lt;BR /&gt;
12-02-2016 13:34:34.407 DEBUG ExecProcessor - PipelineSet 0: Created new ExecedCommandPipe for ""D:\Program Files\Splunk\bin\splunk-powershell.exe" --ps2", uniqueId=32&lt;BR /&gt;
12-02-2016 13:34:34.537 WARN  ScopedLDAPConnection - strategy="NAME" Bind took longer than seems reasonable (20005 milliseconds). Might indicate slow ldap server.&lt;BR /&gt;
12-02-2016 13:34:34.537 ERROR ScopedLDAPConnection - strategy="NAME" Error binding to LDAP. reason="Can't contact LDAP server"&lt;BR /&gt;
12-02-2016 13:34:34.537 DEBUG ScopedLDAPConnection - strategy="NAME" Successfully performed unbind&lt;BR /&gt;
12-02-2016 13:34:34.537 ERROR AdminHandler:AuthenticationHandler - strategy="EPA" Error binding to LDAP. reason="Can't contact LDAP server"&lt;BR /&gt;
12-02-2016 13:34:34.537 DEBUG HTTPServer - GET PARAMS: { }, POST PARAMS: { groupNameAttribute:cn, timelimit:15, bindDNpassword:********, sizelimit:30000, groupBaseDN:OU=redacted,OU=redacted,OU=redacted,OU=redacted,OU=redacted,DC=redacted,DC=redacted,DC=redacted,DC=redacted;OU=redacted,OU=redacted,OU=redacted,OU=redacted,OU=redacted,OU=redacted,DC=redacted,DC=redacted,DC=redacted,DC=redacted, network_timeout:20, userBaseFilter:, nestedGroups:0, realNameAttribute:cn, userNameAttribute:samaccountname, groupMappingAttribute:dn, emailAttribute:mail, port:636, groupBaseFilter:, bindDN:CN=redacted,OU=redacted,OU=redacted,OU=redacted,OU=redacted,OU=redacted,OU=redacted,DC=redacted,DC=redacted,DC=redacted,DC=redacted, order:1, userBaseDN:OU=redacted,DC=redacted,DC=redacted,DC=redacted,DC=redacted, dynamicGroupFilter:, dynamicMemberAttribute:, SSLEnabled:1, host:HOSTNAME, groupMemberAttribute:member, anonymous_referrals:1}&lt;BR /&gt;
12-02-2016 13:34:34.537 INFO  UserManager - Unwound user context: edward.wienholt -&amp;gt; NULL&lt;BR /&gt;
12-02-2016 13:34:34.537 DEBUG InThreadActor - this=0000009117559BC0 waitForActorToComplete start actor=0000009123AAF720&lt;BR /&gt;
12-02-2016 13:34:34.537 DEBUG InThreadActor - this=0000009117559BC0 waitForActorToComplete end actor=0000009123AAF720&lt;BR /&gt;
12-02-2016 13:34:34.577 DEBUG ExecProcessor - PipelineSet 0: Got EOF from ""D:\Program Files\Splunk\bin\splunk-admon.exe"", uniqueId=29&lt;BR /&gt;
12-02-2016 13:34:34.577 DEBUG Queue - insertAndClear: [success] loop count 0&lt;BR /&gt;
12-02-2016 13:34:34.591 DEBUG Queue - insertAndClear: [success] loop count 1&lt;BR /&gt;
12-02-2016 13:34:34.592 DEBUG EventLoop - Inside EventLoop::run() for thread=TcpChannelThread&lt;BR /&gt;
12-02-2016 13:34:34.593 DEBUG InThreadActor - this=00000091193D1018 waitForActorToComplete start actor=0000009125F0F730&lt;BR /&gt;
12-02-2016 13:34:34.593 DEBUG InThreadActor - this=00000091193D1018 waitForActorToComplete end actor=0000009125F0F730&lt;BR /&gt;
12-02-2016 13:34:34.593 DEBUG UiPythonFallback - Decremented in-flight request count to 0 for appserver process at &lt;A href="http://127.0.0.1:8065" target="_blank"&gt;http://127.0.0.1:8065&lt;/A&gt;&lt;BR /&gt;
12-02-2016 13:34:34.593 DEBUG InThreadActor - this=000000911DC43AF8 waitForActorToComplete start actor=0000009125F0FB30&lt;BR /&gt;
12-02-2016 13:34:34.593 INFO  WebUiAccess - 134.67.234.22 - edward.wienholt [02/Dec/2016:13:34:14.035 -0500] "POST /en-US/manager/hp_cde_monitoring/authentication/providers/LDAP/EPA HTTP/1.1" 200 174 "&lt;A href="https://v18h1n-splunk.aa.ad.epa.gov:8000/en-US/manager/hp_cde_monitoring/authentication/providers/LDAP/EPA?action=edit&amp;amp;ns=system&amp;amp;uri=%2FservicesNS%2Fnobody%2Fsystem%2Fauthentication%2Fproviders%2FLDAP%2FNAME" target="_blank"&gt;https://v18h1n-splunk.aa.ad.epa.gov:8000/en-US/manager/hp_cde_monitoring/authentication/providers/LDAP/EPA?action=edit&amp;amp;ns=system&amp;amp;uri=%2FservicesNS%2Fnobody%2Fsystem%2Fauthentication%2Fproviders%2FLDAP%2FNAME&lt;/A&gt;" "Mozilla/5.0 (Windows NT 6.3; WOW64; Trident/7.0; rv:11.0) like Gecko" - 8b17eb96e566643402e6edd741fa86ea 20558ms&lt;BR /&gt;
12-02-2016 13:34:34.593 DEBUG InThreadActor - this=000000911DC43AF8 waitForActorToComplete end actor=0000009125F0FB30&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 13:57:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/LDAP-by-SSL-using-WIndows-2012R2-cannot-connect-to-Active/m-p/267917#M51386</guid>
      <dc:creator>ewienholt</dc:creator>
      <dc:date>2020-09-29T13:57:30Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP by SSL using WIndows 2012R2 cannot connect to Active Directory server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/LDAP-by-SSL-using-WIndows-2012R2-cannot-connect-to-Active/m-p/267918#M51387</link>
      <description>&lt;P&gt;Same issue here, any solution?,&lt;/P&gt;</description>
      <pubDate>Thu, 04 May 2017 19:09:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/LDAP-by-SSL-using-WIndows-2012R2-cannot-connect-to-Active/m-p/267918#M51387</guid>
      <dc:creator>tsfraley</dc:creator>
      <dc:date>2017-05-04T19:09:58Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP by SSL using WIndows 2012R2 cannot connect to Active Directory server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/LDAP-by-SSL-using-WIndows-2012R2-cannot-connect-to-Active/m-p/267919#M51388</link>
      <description>&lt;P&gt;No.  I actually surrendered and closed the support case with Splunk.  We had the customer domain admins helping and we still could not solve the problem.  Very frustrating.&lt;/P&gt;</description>
      <pubDate>Thu, 04 May 2017 19:43:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/LDAP-by-SSL-using-WIndows-2012R2-cannot-connect-to-Active/m-p/267919#M51388</guid>
      <dc:creator>ewienholt</dc:creator>
      <dc:date>2017-05-04T19:43:21Z</dc:date>
    </item>
  </channel>
</rss>

