Using LDAPS (SSL), ! Couldn't initialize TLS [Connect error]: (unknown error code)

Viewed 695

I'm getting:

ubuntu20:~$ sudo /usr/sbin/adcli join --verbose --domain vmmachine.cat --domain-realm VMMACHINE.CAT --use-ldaps --domain-controller 172.16.86.147 --login-type user --login-user test1@VMMACHINE.CAT
 * Using domain name: vmmachine.cat
 * Calculated computer account name from fqdn: UBUNTU20
 * Using domain realm: vmmachine.cat
 * Sending NetLogon ping to domain controller: 172.16.86.147
 ! Couldn't perform discovery search: Can't contact LDAP server
 * Using LDAPS to connect to 172.16.86.147
 ! Couldn't initialize TLS [Connect error]: (unknown error code)
adcli: couldn't connect to vmmachine.cat domain: Couldn't initialize TLS [Connect error]: (unknown error code)

/etc/ldap/ldap.conf:

ubuntu20:~$ cat /etc/ldap/ldap.conf
#
# LDAP Defaults
#

# See ldap.conf(5) for details
# This file should be world readable but not world writable.

#BASE   dc=vmmachine,dc=cat
#wURI   ldaps://vmmachine.cat:636

#SIZELIMIT  12
#TIMELIMIT  15
#DEREF      never

# TLS certificates (needed for GnuTLS)
TLS_CACERT  /home/testuser/Desktop/win-ad2019-ldaps.pem
TLS_REQCERT try

I want to join Active Directory domain with ldap ssl, but I'm getting some issues, any suggestion for me?

1 Answers

• As per the logs posted by you from the ‘ldap.conf’ file, it states that the certificate couldn’t be verified in the path as stated by you, i.e., ‘/home/testuser/Desktop/win-ad2019-ldaps.pem’. The ‘TLS_REQCERT try’ output in the log file itself asserts that it requests for the server certificates and if no certificates are provided the session proceeds normally and if a bad certificate is provided, the session is terminated immediately.

Thus, the certificate for SSL connection regarding the LDAP protocol couldn’t be verified correctly and validated in that path for the LDAP SSL connected to be initiated. Please ensure that the SSL certificate is correct according to the required configurations for the domain controller to be contacted and a connection to be initiated for the domain joining process.

• Please ensure that TCP RPC dynamic ports, i.e., 49152 – 65535 are open and allowed from the client side and LDAP SSL TCP 636 port is open from the server side for the netlogon ping communication to happen to the domain controller for domain joining purposes.

Please find the below link for more details regarding the openLDAP SSL configurations: -

https://www.openldap.org/software//man.cgi?query=ldap.conf&sektion=5&apropos=0&manpath=OpenLDAP+2.4-Release

Related