My Oracle Support Banner

AD Password Filter To Single OID From Multiple AD Servers Not Working (Doc ID 1303141.1)

Last updated on OCTOBER 07, 2019

Applies to:

Oracle Internet Directory - Version 10.1.4.3 and later
Information in this document applies to any platform.

Symptoms

Ldap binds to both OID and remote primary AD Domain Controller works as expected, as follows:


$ ldapbind -U 2 -h <OID_HOSTNAME> -p <OID_SSL_PORT> -D cn=orcladmin -w <PASSWORD> -W file://<PATH_TO_WALLET> -P <WALLET_PASSWORD>
$ bind successful



$ ldapbind -U 2 -h <AD_HOSTNAME> -p <AD_SSL_PORT> -D administrator@<DOMAIN> -w <PASSWORD> -W file://<PATH_TO_WALLET> -P <WALLET_PASSWORD>
$ bind successful



When attempting to run the ldapbindssl.exe from a secondary AD Domain Controller the following error occurs.

ERROR
-----------------------
(01/18/2011 04:18:05 PM), ldapbind, Binding ...
(01/18/2011 04:18:05 PM), ldapbind, Ldap bindERROR
(01/18/2011 04:18:05 PM), ldapbind, Error: Unavailable
(01/18/2011 04:18:38 PM), ldapbind, Connecting server in SSL Mode
(01/18/2011 04:18:38 PM), ldapbind, Checking if SSL is enabled
(01/18/2011 04:18:38 PM), ldapbind, SSL not enabled.
SSL being enabled...
(01/18/2011 04:18:38 PM), ldapbind, Binding ...
(01/18/2011 04:18:38 PM), ldapbind, Ldap bindERROR
(01/18/2011 04:18:38 PM), ldapbind, Error: Unavailable



The issue can be reproduced at will with the following steps:


ldapbindssl.exe -h <OID_HOSTNAME> -p <OID_SSL_PORT> -D cn=orcladmin -w <PASSWORD>



Also, the following error will be seen in the oidldapd server log:

2011/02/03:11:12:35 * SSLthread:9 * ERROR * gslsflnNegotiateSSL * SSL Hand Shake failed Source address: <IP_ADDRESS>(<HOSTNAME>) * (NZerr 28862)

Changes

AD Password Filter was installed and working on one AD Domain Controller.

Then AD Password Filter was installed on a secondary AD Domain Controller.

OID Wallet was updated to include Additional AD Server

Cause

To view full details, sign in with your My Oracle Support account.

Don't have a My Oracle Support account? Click to get started!


In this Document
Symptoms
Changes
Cause
Solution
References

My Oracle Support provides customers with access to over a million knowledge articles and a vibrant support community of peers and Oracle experts.