grouper-users - Re: [grouper-users] Re: dealing with grouper, certificates, and connecting to sldap
Subject: Grouper Users - Open Discussion List
List archive
Re: [grouper-users] Re: dealing with grouper, certificates, and connecting to sldap
Chronological Thread
- From: David Langenberg <>
- To: Rob Gorrell <>
- Cc: "" <>
- Subject: Re: [grouper-users] Re: dealing with grouper, certificates, and connecting to sldap
- Date: Mon, 22 Jul 2013 09:43:03 -0600
If it is doing tls=true, then you need to be using port 389. Try setting ldap.tls=false and ldap.ssl=true.
Dave
On Mon, Jul 22, 2013 at 9:40 AM, Rob Gorrell <> wrote:
So, yes, my URL does include ldaps:// as directed by the comments in grouper-loader.properties:
#note the URL should start with ldap: or ldaps: if it is SSL.
#It should contain the server and port (optional if not default), and baseDn,
#e.g. ldaps://ldapserver.school.edu:636/dc=school,dc=edu
ldap.campusLdap.url = "ldaps://prddc02.campus.uncg.edu:636/dc=campus,dc=uncg,dc=edu
how do i know if grouper is using edu.vt.middleware.ldap.tls=true somewhere else? should I change the url back to ldap:// but leave port 636 assuming grouper is doing edu.vt.middleware.ldap.tls=true somewhere else despite what the comment says?
-RobOn Mon, Jul 22, 2013 at 11:19 AM, David Langenberg <> wrote:
From the looks of that error, it seems your problem isn't with the TLS part, but rather something like you're telling it to use STARTTLS while speaking to AD over SSL. In other words, ensure if your ldapUrl is ldaps:// that later on you're not settingedu.vt.middleware.ldap.tls=true.Dave--On Mon, Jul 22, 2013 at 9:02 AM, Rob Gorrell <> wrote:
i'm still not able to get the SSL ldap connection working through grouper loader. I've got both the domain's CA and the ldap server's authentication certificate (consequently signed by the domain CA) in Java's keystore (/etc/pki/java/cacerts).
since this is new ground for me, i wanted to make sure the certs and the keystore was working properly, so I borrowed a sample java program from oracle that connects to ldap over ssl thus requiring use of the same keystore. Running the program on the grouper server, it works. To prove my point, I backed the two certificates out of the keystore I had added and ran again, this time I received the expected "unable to find valid certification path to requested target" error (same java error grouper gives me on the original java keystore). so my confidence i have the keystore setup correctly with the appropriate certs is there.
but when I put back in place the keystore with my added certs, the one that works on the same java ssl program, grouper is still returning:
[main] ERROR DefaultLdapFactory.create(109) - - unabled to connect to the ldap
javax.naming.NamingException: [LDAP: error code 1 - 00000000: LdapErr: DSID-0C090DE6, comment: TLS or SSL already in effect, data 0, v1772]; remaining name ''
any suggestions? is there anyone out there using grouper to connect over SSL to an Active Directory LDAP source thats had to deal with this before? what does "TLS or SSL already in effect" possibly mean?
-Rob
--Robert W. Gorrell
Middleware Engineer, Identity and Access ManagementUniversity of NC at Greensboro
336-334-5954
David LangenbergIdentity & Access ManagementThe University of Chicago
--Robert W. Gorrell
Middleware Engineer, Identity and Access ManagementUniversity of NC at Greensboro
336-334-5954
David Langenberg
Identity & Access Management
The University of Chicago
- [grouper-users] dealing with grouper, certificates, and connecting to sldap, Rob Gorrell, 07/12/2013
- [grouper-users] Re: dealing with grouper, certificates, and connecting to sldap, Rob Gorrell, 07/22/2013
- Re: [grouper-users] Re: dealing with grouper, certificates, and connecting to sldap, David Langenberg, 07/22/2013
- Re: [grouper-users] Re: dealing with grouper, certificates, and connecting to sldap, Rob Gorrell, 07/22/2013
- Re: [grouper-users] Re: dealing with grouper, certificates, and connecting to sldap, David Langenberg, 07/22/2013
- Re: [grouper-users] Re: dealing with grouper, certificates, and connecting to sldap, Rob Gorrell, 07/22/2013
- Re: [grouper-users] Re: dealing with grouper, certificates, and connecting to sldap, David Langenberg, 07/22/2013
- Re: [grouper-users] Re: dealing with grouper, certificates, and connecting to sldap, Rob Gorrell, 07/22/2013
- Re: [grouper-users] Re: dealing with grouper, certificates, and connecting to sldap, David Langenberg, 07/22/2013
- [grouper-users] Re: dealing with grouper, certificates, and connecting to sldap, Rob Gorrell, 07/22/2013
Archive powered by MHonArc 2.6.16.