grouper-users - RE: [grouper-users] Re: dealing with grouper, certificates, and connecting to sldap
Subject: Grouper Users - Open Discussion List
List archive
RE: [grouper-users] Re: dealing with grouper, certificates, and connecting to sldap
Chronological Thread
- From: Gagné Sébastien <>
- To: "Rob Gorrell" <>, <>
- Subject: RE: [grouper-users] Re: dealing with grouper, certificates, and connecting to sldap
- Date: Wed, 18 Sep 2013 15:47:32 -0400
It might be easier to spot the problem if you can provide a sanitized ldap.properties, especially the “edu.vt.middleware.ldap.” parameters Have you tried connecting in non-ssl ? Do you have a firewall blocking the connection ? As you saw, the error simply says that it couldn’t connect to LDAP, it might be a bad URL or a SSL problem, do you have anything else in grouper’s logs ? De : [mailto:] De la part de Rob Gorrell So not to rehash an old issue, but I'm once more stuck in ssl ldap connection problems... though not exactly the same as before. I've added a new source to my sources.xml that I need for the PSP to provision against. Its an Active Directory domain and a different source than I've used for anything in the past. What I'm getting when I just attempt to start up gsh and load the new sources.xml with the additional source in it is: this is different from before, but I think i read that "Ldap Exception: Pool is empty and object creation failed" has some dealings with ssl issues. has anyone encountered this sort of ldap error before? I have no problem connecting to the same source through an independent ldap client. the certificate used by this ldap server is in java's cacert bundle. Thanks, -Rob On Mon, Jul 22, 2013 at 11:56 AM, Rob Gorrell <> wrote: Bingo... that looks to be it. My loader job still didn't run, but looks like I'm pasted connectivity issues. On Mon, Jul 22, 2013 at 11:43 AM, David Langenberg <> wrote: If it is doing tls=true, then you need to be using port 389. Try setting ldap.tls=false and ldap.ssl=true. Dave On Mon, Jul 22, 2013 at 9:40 AM, Rob Gorrell <> wrote: So, yes, my URL does include ldaps:// as directed by the comments in grouper-loader.properties: On Mon, Jul 22, 2013 at 11:19 AM, David Langenberg <> wrote: From the looks of that error, it seems your problem isn't with the TLS part, but rather something like you're telling it to use STARTTLS while speaking to AD over SSL. In other words, ensure if your ldapUrl is ldaps:// that later on you're not setting edu.vt.middleware.ldap.tls=true. Dave On Mon, Jul 22, 2013 at 9:02 AM, Rob Gorrell <> wrote: i'm still not able to get the SSL ldap connection working through grouper loader. I've got both the domain's CA and the ldap server's authentication certificate (consequently signed by the domain CA) in Java's keystore (/etc/pki/java/cacerts). Robert W. Gorrell University of NC at Greensboro -- Identity & Access Management The University of Chicago
Robert W. Gorrell University of NC at Greensboro -- Identity & Access Management The University of Chicago
Robert W. Gorrell University of NC at Greensboro
Robert W. Gorrell University of NC at Greensboro |
- Re: [grouper-users] Re: dealing with grouper, certificates, and connecting to sldap, Rob Gorrell, 09/18/2013
- RE: [grouper-users] Re: dealing with grouper, certificates, and connecting to sldap, Gagné Sébastien, 09/18/2013
- Re: [grouper-users] Re: dealing with grouper, certificates, and connecting to sldap, Rob Gorrell, 09/19/2013
- RE: [grouper-users] Re: dealing with grouper, certificates, and connecting to sldap, Gagné Sébastien, 09/18/2013
Archive powered by MHonArc 2.6.16.