LDAP over SSL doesn't work is not between ASA and AD server

Hi all.

We have configured clientless SSL WebVPN portal on an ASA5525 using LDAP authentication with an ad server. All is well until what we enable LDAP over SSL to allow users to change an expired password. They get just connection error every time, even if their password is correct.

The systems team have installed the necessary certificate on the AD server.

The newspaper of the ASDM I get

Joffrey.pcmtu.Keele.AC.UK marking AAA in aaa-Server CTU_LDAP04 group LDAP server down
Marking AAA 172.16.0.10 LDAP server group aaa-server active CTU_LDAP04

On the ASA, I get the debugging ldap following 255

[50] starting a session
[50] new application Session, framework 0x00007fffddc99a60, reqType = authentication
[50] the fiber began
[50] create LDAP context with uri = ldaps://172.16.0.10:636
[50] to connect to the LDAP server: ldaps://172.16.0.10:636, status = failure
[50] cannot read the rootDSE. Cannot contact the LDAP server.
[50] output fiber Tx = 0 bytes Rx = 0 bytes, status =-2
[50] end of session

On the ad server, the systems team report TLS Fatal Alert Code 48 which is...

Received a valid certificate chain or partial string, but the certificate has been refused because the authority , could not be located or couldn't be matched with a known, trusted CA. This message is always fatal.

Can someone shed some light on where we need to look at.

Thank you. Richard.

Richard,

This could be due to:

https://Tools.Cisco.com/bugsearch/bug/CSCus71190/?reffering_site=dumpcr

M.

Tags: Cisco Security

Similar Questions

  • Hyperlink button doesn't work is not a Drag and Drop Interaction

    I have an interaction drag-and - drop on the last slide of a project that work very well, but my button (arrow)

    that goes to a site Web does not work (nothing happens when the user clicks the button).  Button actions
    are defined as follows: success: open URL or file, check of the infinite attempts and URL is set to
    on new.

    Thanks for the tips.

    Kelvin

    Drag and Drop.png

    Haven't you set up your network drive as a trusted location in your security settings for Flash?  If this isn't the case, it will be the reason.  If that's how you want to deliver your learning (from a network drive), then anyone who consumes it will to do this. If things don't work out as planned.  A road LAN network is NOT a web server.

  • VMWare Player 6 - copy / paste doesn't work is not between the guest and host

    Hi all

    I am unable to cut and paste (text) or drag-and - drop (files) between the client and host and vice versa.

    I am running Windows 7 (32-bit) guest on a host Windows 8.1 (64-bit).

    Everything else works to date works and VMWare Tools are installed.

    I spent a few hours searching and have not been able to determine if this is a known issue or just a mismatch in my environment/configuration.

    Any suggestions or comments would be most welcome.

    Kind regards

    Hoops

    Hi all

    Seems I solved the problem.  It comes down to User Account Control (UAC) prompt (in my case Windows 7 (32 bit).  I have disabled UAC in the comments and drag and drop / cut and paste now works like a charm.

    Autologin also now works. I had not tried to set up that more early.  That's where I read an article to disable UAC for AutoLogin work.

    My VMWare tools icon now displays in the system tray.

    I hope this helps someone else out there!

    Thank you...

    Hoops

  • with firefox 43 yahoo and yahoo mail doesn't work does not correctly

    With the help of win 7 and firefox 43.0.1, I have 4 computers and now all have problems with yahoo and yahoo mail doesn't work does not correctly. Loading sites, but most of the features are missing and clicking on what whether changes to the lists of text. I have disabled flash / anti-spam etc., cleared cookies and cache and even firefox loaded down once again and have upgraded, no help. I'm forced to use IE now.

    I tried Yahoo support, they said try Firefox... In any case, it's Firefox and I found a solution using the 'Refresh Firefox' button. Whatever the problem was fixed on two of my computers so far. Got to update my setting again but it's 10 m, compared to the 10 hours I spent trying all that is nothing.

    Thanks for the help!

  • spell check doesn't work is not in outlook on windows 7

    Hi the spell checker doesn't work is not in my outlook for windows 7. This can be corrected?

    Sincerely, Robert H.C.

    Outlook.com has a manual spell at the top next to the options button controlIt won't appear that if you write an e-mail AND if your browser is not checking spelling himself. In most modern browsers the spell checking is done by the browser itself and may need to be enabled in this browser

    IE , it depends on the version you have.
  • DNG Converter doesn't work is not on a camera called raw photo

    DNG Converter doesn't work is not on a raw photo camera that always comes back with this Message "check if the camera is recognized.   "

    Supported cameras Camera Raw plugin | Compatible cameras

  • LR 5 doesn't work is not on the new Macbook Pro.

    LR 5 doesn't work is not on the new Macbook Pro.  Have tried 2 CC downloads, download licensed 5.6 and 5.5 download licensed, all the results in the same thing.  It comes up with the screen base but no signs and gives that an error occurred when changing the modules.  Nothing I have tried seems to help.  He also said "start with lightroom mobile at the top on the left, although it said it's Lr 5.6.  Anyone else having problems?  Calls to adobe are no help and have to wait until Monday for technical support.  Surely this must run on a NEW laptop with any other installed software!

    Setup logs was very good.  Application installed but is not working properly.  Finally got Adobe support and it turns out be a file permissions error.  Had to add applications and myself as accessors of the Lightroom folder under ~/Library/Adobe/ path and set permissions to read & write (was read only for everything except system) and apply to all the cases closed.   Works fine now.  Including this here in case when someone else is going through this issue.

  • The product I bought doesn't work! I need help and I was stuck in your 'contact us loop' for the last few days and I'm frustrated. How can I contact you for help!

    The product I bought doesn't work! I need help and I was stuck in your 'contact us loop' for the last few days and I'm frustrated. How can I contact you for help!

    Probably the best place to start is the right forum for your product. This is the forum for Distiller Server, a product used by corporations long dead, and probably not what you have. If you can't find the right forum, please let us know the FULL name of what you paid for (Please check your invoice, as Adobe have a lot of similar products), and we may be able to direct you. Good luck!

  • Problem with IPsec VPN between ASA and router Cisco - ping is not response

    Hello

    I don't know because the IPsec VPN does not work. This is my setup (IPsec VPN between ASA and R2):

    my network topology data:

    LAN 1 connect ASA - 1 (inside the LAN)

    PC - 10.0.1.3 255.255.255.0 10.0.1.1

    ASA - GigabitEthernet 1: 10.0.1.1 255.255.255.0

    -----------------------------------------------------------------

    ASA - 1 Connect (LAN outide) R1

    ASA - GigabitEthernet 0: 172.30.1.2 255.255.255.252

    R1 - FastEthernet 0/0: 172.30.1.1 255.255.255.252

    ---------------------------------------------------------------------

    R1 R2 to connect

    R1 - FastEthernet 0/1: 172.30.2.1 255.255.255.252

    R2 - FastEthernet 0/1: 172.30.2.2 255.255.255.252

    R2 for lan connection 2

    --------------------------------------------------------------------

    R2 to connect LAN2

    R2 - FastEthernet 0/0: 10.0.2.1 255.255.255.0

    PC - 10.0.2.3 255.255.255.0 10.0.2.1

    ASA configuration:

    1 GigabitEthernet interface
    nameif inside
    security-level 100
    IP 10.0.1.1 255.255.255.0
    no downtime
    interface GigabitEthernet 0
    nameif outside
    security-level 0
    IP 172.30.1.2 255.255.255.252
    no downtime
    Route outside 0.0.0.0 0.0.0.0 172.30.1.1

    ------------------------------------------------------------

    access-list scope LAN1 to LAN2 ip 10.0.1.0 allow 255.255.255.0 10.0.2.0 255.255.255.0
    object obj LAN
    subnet 10.0.1.0 255.255.255.0
    object obj remote network
    10.0.2.0 subnet 255.255.255.0
    NAT (inside, outside) 1 static source obj-local obj-local destination obj-remote control remote obj non-proxy-arp static

    -----------------------------------------------------------
    IKEv1 crypto policy 10
    preshared authentication
    aes encryption
    sha hash
    Group 2
    life 3600
    Crypto ikev1 allow outside
    crypto isakmp identity address

    ------------------------------------------------------------
    tunnel-group 172.30.2.2 type ipsec-l2l
    tunnel-group 172.30.2.2 ipsec-attributes
    IKEv1 pre-shared-key cisco123
    Crypto ipsec transform-set esp-aes-192 ASA1TS, esp-sha-hmac ikev1

    -------------------------------------------------------------
    card crypto ASA1VPN 10 is the LAN1 to LAN2 address
    card crypto ASA1VPN 10 set peer 172.30.2.2
    card crypto ASA1VPN 10 set transform-set ASA1TS ikev1
    card crypto ASA1VPN set 10 security-association life seconds 3600
    ASA1VPN interface card crypto outside

    R2 configuration:

    interface fastEthernet 0/0
    IP 10.0.2.1 255.255.255.0
    no downtime
    interface fastEthernet 0/1
    IP 172.30.2.2 255.255.255.252
    no downtime

    -----------------------------------------------------

    router RIP
    version 2
    Network 10.0.2.0
    network 172.30.2.0

    ------------------------------------------------------
    access-list 102 permit ahp 172.30.1.2 host 172.30.2.2
    access-list 102 permit esp 172.30.1.2 host 172.30.2.2
    access-list 102 permit udp host 172.30.1.2 host 172.30.2.2 eq isakmp
    interface fastEthernet 0/1
    IP access-group 102 to

    ------------------------------------------------------
    crypto ISAKMP policy 110
    preshared authentication
    aes encryption
    sha hash
    Group 2
    life 42300

    ------------------------------------------------------
    ISAKMP crypto key cisco123 address 172.30.1.2

    -----------------------------------------------------
    Crypto ipsec transform-set esp - aes 128 R2TS

    ------------------------------------------------------

    access-list 101 permit tcp 10.0.2.0 0.0.0.255 10.0.1.0 0.0.0.255

    ------------------------------------------------------

    R2VPN 10 ipsec-isakmp crypto map
    match address 101
    defined by peer 172.30.1.2
    PFS Group1 Set
    R2TS transformation game
    86400 seconds, life of security association set
    interface fastEthernet 0/1
    card crypto R2VPN

    I don't know what the problem

    Thank you

    If the RIP is not absolutely necessary for you, try adding the default route to R2:

    IP route 0.0.0.0 0.0.0.0 172.16.2.1

    If you want to use RIP much, add permissions ACL 102:

    access-list 102 permit udp any any eq 520

  • Parachute does not not between iOS and Mac devices... Does anyone have a good solution for it nor a lot of garbage to support

    Parachute does not not between iOS and Mac devices... Does anyone have a good solution for it nor a lot of garbage to support

    You want the solution? Why not tell us what Mac and Apple, mobile devices you have the OS and version?

    Also what troubleshooting steps you took?

    We do not have a crystal ball, and we're not sitting next to you.

  • WiFi doesn't work do not

    A year and half ago we bought a new Mac and the Time Capsule (TC) to go with it. I tried to set up at the start and think about this topic, I do not think that it has never worked properly. I say this because we got a new modem without router because time Capsule has an inside, and we are unable to connect to wifi. I have a TB Ethernet connection and if I can get online in this way, but the WiFi does not work. Last night, I went through and set up and the WiFi worked, but today it no longer works and I can't seem to do it again.

    The indication of WiFi signal says I'm connected, on my Mac and on our phones, but when you disconnect from data it no longer works. It's very frustrating because I don't want to have to go back to a modem/router of the rental of our cable company.

    We have just upgraded to OS X El Capitan 10.11.6

    When it worked last night I created everything from scratch. But I do not think that I would have to do every time I need to use the internet. I also tried to create a WiFi with a custom DNS but that doesn't work anymore.

    Any help would be appreciated.

    Thank you.

    Amazing!

    I am so embarrassed but understand that I would update in the case where everyone does the same thing.

    When I put in 1.5 years ago I went from ethernet cables. The Ethernet cable from the modem was connected to the LAN port and the Ethernet cable from the Mac was connected to the WAN. Once I put the cable from the modem to the WAN everything has worked.

    Sometimes, just come back to square one.

  • Crossfade doesn't work does not in iTunes 12.4

    I use OS x El Capitan 10.11.1. set iTunes to automatically level to 12.4. I played music on a playlist with crossfade turned on, but none of the songs crossfaded. I am aware of crossfade doesn't work every time that the songs are played in order any of the same artist and album, but my playlist was not organized as such, so it should work. I tried to turn the market feature and quit iTunes and restart, but no luck. Any suggestions?

    Although I usually do not use this feature, you seem to be correct.  Can operate either...  You can report the problem here

    https://www.Apple.com/feedback/ (under OS X Apps - iTunes)

  • Touchscreen doesn't work is not for the Satellite U920t - 10 p

    Please read this completely before you answer with your copied and pasted answers.

    My touch screen lets you stop work, but was still attached with a reboot of the machine.
    Now it doesn't work at all and * I've tried everything posted elsewhere in this forum *.

    I tried to change the settings for battery power, try to update the drivers (not exactly who is right though!).

    Please can anyone help because it is a new machine and it's very frustrating.

    Serial number: 7D054633H
    Model: Toshiba Satellite U920t - PSUL1E-01900JEN 10 p

    Thanks in advance.

    > Please read this completely before you answer with your copied and pasted answers.
    IMHO, I n t think that someone here in the forum doesn t read the messages before playback
    I hope that this part of your post is just the result of frustration due to the malfunction of the notebook...

    Back to your question:
    > I tried everything already posted elsewhere in this forum.
    and what does this mean? What have you tried exactly?
    Have you given zero and plant control panel?

    If not try and in the case where this help not the laptop's hardware could be affected which requires new checks of material by an authorized

  • HP 14-r206nv: light wireless led doesn't work do not

    I have a very minor issue that don't mind operating of the laptop, but I'm curious to know why it does not work, because I know that before reinstalling windows it worked normally.

    Well well, to the point now. After a hard drive failure and replacement, Windows 8.1 are installed again and each driver has been installed and works well. The only thing that doesn't work is the led light button wireless (F12). The button is working correctly, activation and deactivation of the Wi - fi, but not the led. It lights, neither white nor red, it is always disabled.

    The model of the wireless card is Realtek RTL8723BE.

    I installed the drivers from the HP site.

    Version of the driver for the wireless card is 2013.8.915.2014

    The version of the wireless button driver is 1.1.7.1

    I tried the latest drivers for the card (an optional windows updates finds) implemented to date for this and the wireless button (if I try update driver in Device Manager, it installs a new) but nothing has changed for good so I decided to go back to what the official site suggests and post here.

    Hi @v1184,

    Thank you for your inquiry.

    I understand that you had a hard drive failure and he had to be replaced, you did. You reinstalled Windows 8.1 and all drivers are up to date.  The only problem you are having is that the wireless button light does not illuminate, but it does not work.

    You tried to update the wireless driver button, but has not changed, so you returned back to the recommended HP driver.  As the wireless button does not work it is not the driver, however, it could be that the light burned. The other possibility would be that when you replaced the hard drive, the connection has been dislodged or disconnected and must be reconnected.

    Please let me know if this information helps you solve the problem by marking this message as 'accept as Solution', this will help others easily find the information they seek.  In addition, by clicking on ' Thumbs Up ' below is a great way to say thank you!

  • IPhone 6s off right speaker doesn't work is not on the helmet

    IPhone 6s off right speaker doesn't work don't not on the helmet, tried 3 different sets of headphones, have tried to clean shooting, reloading the OS etc., checked the slider etc, still no joy, any suggestions very welcome. It works on both speakers if I don't push the CAP fully home (but he then falls easily).

    Are you sure that you're pushing all the way?  If you are, this looks like a connector damaged in the phone. As a 6 s that it is still under warranty, then take it to an Apple store.

Maybe you are looking for