IBM Guardium

IBM Guardium

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  Error connecting to LDAP while configuring user import from Microsoft Active Director

    Posted 23 days ago
    Edited by Duc Tran Anh 22 days ago

    Have a nice day everyone,

    I am configuring LDAP integration to enable user login at Guardium VM On-Premise version 12.1. When I set up the LDAP config and test the connection, Guardium shows a warning: 'unable to connect', even though I've checked the connection via CLI and confirmed that the firewall allows it.

    Additionally, when I attempt to run 'import user from LDAP query', it also fails with the error: 'java.lang.RuntimeException: Connection timeout'. Note that the same AD information I'm using for LDAP works normally with other systems.



    ------------------------------
    Duc Tran Anh
    ------------------------------



  • 2.  RE: Error connecting to LDAP while configuring user import from Microsoft Active Director

    Posted 23 days ago

    Hi @Duc Tran Anh,

    There's a few things I notice about your configuration that may be a problem, but start with correcting your Log in as value first. It needs to be the service account that's connecting to LDAP to establish the connection, not a string within your LDAP tree. 



    ------------------------------
    Wendy Zemba
    Sr. Consultant, Data Protection
    Converge Technology Solutions
    wendy.zemba@convergetp.com

    Need help with your Guardium deployment? Contact me directly to discuss engagement opportunities. Currently serving North America.
    ------------------------------



  • 3.  RE: Error connecting to LDAP while configuring user import from Microsoft Active Director

    Posted 22 days ago
    Edited by Duc Tran Anh 22 days ago

    HI @Wendy Zemba

    Thank you I've double-checked and was able to successfully import the LDAP user, as shown in the screenshot below.

    However, when I try to log in using the account information for duc.ta that was imported, along with the password from the AD server, the login at GUI with LDAP user unsuccessfully with Error Message : "Invalid user name and/or password. Please reenter your credential ".

    It also fails when testing the account on the portal. I would greatly appreciate your support and guidance.



    ------------------------------
    Duc Tran Anh
    ------------------------------



  • 4.  RE: Error connecting to LDAP while configuring user import from Microsoft Active Director

    Posted 21 days ago

    Hi Duc Tran Anh,

    From the Guardium Portal page, add =search to the Default User RDN Type (sAMAccountName=search). Then restart the GUI/Guardium Portal and try logging in with your duc.ta account.



    ------------------------------
    Wendy Zemba
    Sr. Consultant, Data Protection
    Converge Technology Solutions
    wendy.zemba@convergetp.com

    Need help with your Guardium deployment? Contact me directly to discuss engagement opportunities. Currently serving North America.
    ------------------------------