Monday, April 29, 2013

vCenter 5.1 configuring "Identity Source" error: LDAP: error code 8 - 00002028: LdapErr: DSID-0C0901FC

  • Cannot add a vCenter Single Sign On (SSO) Active Directory Identity Source
  • Adding an Active Directory Single Sign On Identity Source with a Primary Server URL starting with ldap:// or ldaps:// fails
  • Test Connection fails with one of these errors:

    • [LDAP: error code 8 - 00002028: LdapErr: DSID-0C0901FC, comment: The server requires binds to turn on integrity checking if SSL\TLS are not already active on the connection, data 0, v1db1]

    • simple bind failed

 

Cause

This issue occurs if the Active Directory Domain is configured with a Group Policy that requires all LDAP connections to be secured with SSL (ldaps required) and the Domain controller: LDAP server signing requirements policy is set to Require signing.

A certificate that establishes trust for the LDAPS endpoint of the Active Directory server is required when you use ldaps:// in the primary or secondary LDAP URL.

 

Resolution

To resolve this issue:

  1. Log in to the vSphere Web Client using the Admin@System-Domain credentials.
  2. Browse to Administration > Sign-On and Discovery > Configuration in the vSphere Web Client.
  3. Open the Edit Identity Source by right-clicking on the dialog of the Identity Source you want to edit.
  4. Change the URL from ldap://... to ldaps://...

    A Choose Certificate button appears below the settings.

  5. Click Choose Certificate.
  6. Select the correct .cer Root CA certificate of your AD/OpenLdap Identity Source.
  7. Click Test Connection.
  8. Click OK.

No comments:

Post a Comment