AIX

AIX

Connect with fellow AIX users and experts to gain knowledge, share insights, and solve problems.

 View Only
  • 1.  SSL-LDAP to Microsoft AD server stopped working after LDAP certificate changed

    Posted Fri March 26, 2021 03:30 PM

    Hello,

    we run LMT 9.5.17 here with LMT server 9.2.22/23 and noticed that LDAP authentication stopped working after the MS-AD guys changed their LDAP certificate before it expires.

    LMT noticed the certificate change and placed the dialogue to trust the new certificates. We did that, but login is still not possible.

    The error in tema.log looks like this:

    [3/26/21 11:32:21:540 UTC] 00000037 com.ibm.ws.webcontainer.webapp I SRVE0292I: Servlet Message - [tema]:.[WARN] An error occurred while attempting to connect to server adserver.domain:636: IOException(LDAPException(resultCode=91 (connect error), errorMessage='An error occurred while attempting to establish a connection to server adserver.domain/10.x.x.x:636: SSLException(Connection reset), ldapSDKVersion=4.0.14, revision=c0fb784eebf9d36a67c736d0428fb3577f2e25bb'))

    I suspect that the old trust is still configured somewhere and doesn't work anymore because the certificate is expired.

    Any suggestions on how to bring encrypted LDAP back to work?



    #AIX
    #Support
    #SupportMigration


  • 2.  RE: SSL-LDAP to Microsoft AD server stopped working after LDAP certificate changed

    Posted Wed March 31, 2021 09:38 AM

    Sadly, nobody of the LMT support seems to read questions...



    #AIX
    #Support
    #SupportMigration


  • 3.  RE: SSL-LDAP to Microsoft AD server stopped working after LDAP certificate changed

    Posted Tue April 06, 2021 12:11 AM

    Please open a case with IBM. This appears to be a bug introduced in 9.2.23 (APAR IJ31909). You will have to open a case to get the work around file.

    https://www.ibm.com/support/pages/apar/IJ31909



    #AIX
    #Support
    #SupportMigration


  • 4.  RE: SSL-LDAP to Microsoft AD server stopped working after LDAP certificate changed

    Posted Wed April 07, 2021 04:59 PM

    Thanks. A colleague of mine opened a case and supplied me with the workaround. Didn't work. Test connection is again working, but authentication still not. I tried both login name and login name with "" appended. Suggestions?



    #AIX
    #Support
    #SupportMigration


  • 5.  RE: SSL-LDAP to Microsoft AD server stopped working after LDAP certificate changed

    Posted Wed April 07, 2021 06:23 PM

    Two technotes were published last night about this issue, that I think are relevant.

    https://www.ibm.com/support/pages/node/6440615

    https://www.ibm.com/support/pages/node/6440621



    #AIX
    #Support
    #SupportMigration


  • 6.  RE: SSL-LDAP to Microsoft AD server stopped working after LDAP certificate changed

    Posted Thu April 08, 2021 08:54 AM

    Thanks!

    This first one is what was suggested by IBM support.

    The second one is not relevant because we didn't enable FIPS (as of my knowledge).


    Sadly, it's still not working correctly after we changed the config according to the first note.




    #AIX
    #Support
    #SupportMigration