LDAPS not connecting on 636. 36869


hi all,

we're unable connect ldaps port 636 using ldp.exe.

i following error message when attempt connect:

"ld = ldap_sslinit("srv-vdc1", 636, 1);
error 81 = ldap_set_option(hldap, ldap_opt_protocol_version, 3);
error 81 = ldap_connect(hldap, null);
server error: <empty>
error <0x51>: fail connect srv-vdc1."

this instantly throws event id: 36869

"the ssl server credential's certificate not have private key information property attached it. occurs when certificate backed incorrectly , later restored. message can indicate certificate enrollment failure."

all servers mentioned below 2012 r2 latest updates.

the server we're trying configure domain controller (dc1), weirdly our other dc (dc2) works perfectly, identical certificate (apart 'issued to' of-course.)

i requesting certificate our ca server, opposed importing manually.

the certificate in question, in dc1 local computer > personal store. cert has both client , server authentication, within valid from-to dates, , states "you have private key corresponds certificate".

have tried 'certutil -repairstore "serial number"' command no success.

i can confirm can connect standard ldap 389 dc1

any suggestions appreciated.

thanks in advance,

dg

is there certificate on dc1 in adds certificate store? open mmc.exe, add snap-in, select service account , select active directory domain services. in personal/certificates , see if there certificate being chosen on 1 in computer/personal/certificates store.

mark b. cooper, president , founder of pki solutions inc., former microsoft senior engineer , subject matter expert microsoft active directory certificate services (adcs). known “the pki guy” @ microsoft 10 years. connect mark @ http://www.pkisolutions.com



Windows Server  >  Security



Comments

Popular posts from this blog

WIMMount (HSM) causing cluster storage to go redirected (2012r2 DC)

Failed to delete the test record dcdiag-test-record in zone test.com

Azure MFA with Azure AD and RDS