Trying to connect to Active Directory via LDAPS

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



Hi all,

I have a need to connect securely to AD via LDAP.

My AD Server appears to have both a self-signed cert and a purchased cert
stored locally.

When I connect remotely to AD via 636 it fails because it cant verify the
cert. see below:

TLS trace: SSL_connect:SSLv3 read server hello A
TLS certificate verification: Error, self signed certificate
tls_write: want=7, written=7
0000: 15 03 01 00 02 02 30 ......0
TLS trace: SSL3 alert write:fatal:unknown CA
TLS trace: SSL_connect:error in SSLv3 read server certificate B
TLS trace: SSL_connect:error in SSLv3 read server certificate B
TLS: can't connect.
ldap_perror
ldap_bind: Can't contact LDAP server (-1)
additional info: error:14090086:SSL
routines:SSL3_GET_SERVER_CERTIFICATE:certificate verify failed


When I look at my AD server¹s local certificates it has both the self-signed
and my 3rd party cert installed but the one that AD is using for
connections on 636 appears to be the self-signed cert.
The 3rd party cert works fine for OWA and Outlook connections.

How do I get AD to use the 3rd party cert?

In an effort to force it to use the installed signed cert, I removed the
self-signed cert.

Now, when I connect via 636 it logs event 1220¹s in the Directory Server
event logs, see below:

LDAP over Secure Sockets Layer (SSL) will be unavailable at this time
because the server was unable to obtain a certificate.


Is it not possible to have AD use a 3rd party cert for SSL connections to
LDAP.

Did I just mess up my system?


Any help would be greatly appreciated.

TIA
Alan


Relevant Pages

  • Re: LDAP Authentication from Linux
    ... I already have an SSL cert thats used by IIS, but the SBS server has already set itself up with the necassary CA Certs. ... Dana Epp [Microsoft Security MVP] ... So I have non-ssl based authentication working for LDAP binds.. ... I know I can modify the AuthLDAPURL directive to use ldaps://, and I've verified the SBS server is serving LDAP/SSL. ...
    (microsoft.public.windows.server.sbs)
  • RE: IIS Key pairs (how to export an IIS 4.0 self-issued Root CA a nd import into new IIS 4.0 box)
    ... it prompts the user for what client cert they want to use to connect to the ... it issues client certificates to the end users. ... Step I - Installing the New Server ... Install NT SP 3 ONLY ...
    (Focus-Microsoft)
  • Re: LDAP Authentication from Linux
    ... Went into the Ceritifcate Authority MMC, right click on the server, view the certificate and then save it. ... I already have an SSL cert thats used by IIS, but the SBS server has already set itself up with the necassary CA Certs. ... Dana Epp [Microsoft Security MVP] ... So I have non-ssl based authentication working for LDAP binds.. ...
    (microsoft.public.windows.server.sbs)
  • Re: ActiveSync error 0x85010004 from Windows Mobile 6 to SBS 2003
    ... I found a link suggesting a test of the OMA using a desktop browser by ... the server and from the phone. ... I then reinstalled the cert, ... Before installing the cert, I could ...
    (microsoft.public.windows.server.sbs)
  • RE: Certificate logon on Unix
    ... I don't know of any package but there is prolly one out there you should ... The good news is that getting fulle client ... and server side authentication is pretty easy so it will work as a quick ... setup your CA and make the root cert Pbk available to everyone. ...
    (Security-Basics)