AD Password Filter To Single OID From Multiple AD Servers Not Working (Doc ID 1303141.1)

Last updated on MARCH 08, 2017

Applies to:

Oracle Internet Directory - Version 10.1.4.3 and later
Information in this document applies to any platform.

Symptoms

Ldap binds to both OID and remote primary AD Domain Controller works as expected, as follows:


$ ldapbind -U 2 -h myOIDhost -p 1636 -D cn=orcladmin -w ******* -W file://etc/oracle/walletsTEST/sslwallets -P ********
$ bind successful



$ ldapbind -U 2 -h myADhost -p 636 -D administrator@oracle.com -w ******* -W file://etc/oracle/walletsTEST/sslwallets -P ********
$ bind successful



When attempting to run the ldapbindssl.exe from a secondary AD Domain Controller the following error occurs.

ERROR
-----------------------
(01/18/2011 04:18:05 PM), ldapbind, Binding ...
(01/18/2011 04:18:05 PM), ldapbind, Ldap bindERROR
(01/18/2011 04:18:05 PM), ldapbind, Error: Unavailable
(01/18/2011 04:18:38 PM), ldapbind, Connecting server in SSL Mode
(01/18/2011 04:18:38 PM), ldapbind, Checking if SSL is enabled
(01/18/2011 04:18:38 PM), ldapbind, SSL not enabled.
SSL being enabled...
(01/18/2011 04:18:38 PM), ldapbind, Binding ...
(01/18/2011 04:18:38 PM), ldapbind, Ldap bindERROR
(01/18/2011 04:18:38 PM), ldapbind, Error: Unavailable



The issue can be reproduced at will with the following steps:

ldapbindssl.exe -h <hostname> -p <portname> -D cn=orcladmin -w <passwd> for example:

ldapbindssl.exe -h myOIDhost -p 1636 -D cn=orcladmin -w xxxxxxxx



Also, the following error will be seen in the oidldapd server log:

2011/02/03:11:12:35 * SSLthread:9 * ERROR * gslsflnNegotiateSSL * SSL Hand Shake failed Source address: 172.16.250.44(prt-ldap-test08.prtext.local) * (NZerr 28862)

Changes

AD Password Filter was installed and working on one AD Domain Controller.

Then AD Password Filter was installed on a secondary AD Domain Controller.

OID Wallet was updated to include Additional AD Server

Cause

Sign In with your My Oracle Support account

Don't have a My Oracle Support account? Click to get started

My Oracle Support provides customers with access to over a
Million Knowledge Articles and hundreds of Community platforms