<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>Network Access ControlのトピックACS 4.2 Generic LDAP with SSL</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-4-2-generic-ldap-with-ssl/m-p/2052353#M184610</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have a similar issue.&amp;nbsp; Trying to set up EAP-TLS against an ADAM instance (Generic LDAP) with ACS 4.2.&amp;nbsp; I'm not able to enumerate the directory (not sure if this works anyway - have never worked with LDAP in ACS before) or authenticate against it.&amp;nbsp; I can successfully authenticate against the same AD using EAP-TLS via windows (user and machine), but it's not working as LDAP.&amp;nbsp; I'm also getting the "&lt;EM&gt;External DB reports about an error condition&lt;/EM&gt;" message in the failed log.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 30 Oct 2012 20:43:36 GMT</pubDate>
    <dc:creator>mmletzko</dc:creator>
    <dc:date>2012-10-30T20:43:36Z</dc:date>
    <item>
      <title>ACS 4.2 Generic LDAP with SSL</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-4-2-generic-ldap-with-ssl/m-p/2052352#M184590</link>
      <description>&lt;P&gt;Dear all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have ACS 4.2 and try to configure it with Generic LDAP. &lt;/P&gt;&lt;P&gt;Unfortunately, the TLS is enabled on the AD and so the SSL checkbox must be enabled on the ACS configuration, and the port to be changed to 636.&lt;/P&gt;&lt;P&gt;I have joined the server in the domain where the LDAP is.&lt;/P&gt;&lt;P&gt;I have installed the root certificate in the ACS server.&lt;/P&gt;&lt;P&gt;I have installed the domain controller certificate in the ACS server.&lt;/P&gt;&lt;P&gt;I have all those in the trusted list of CAs in the application and in the OS.&lt;/P&gt;&lt;P&gt;I can query the LDAP with the same settings with a 3rd party application with the same user as the one configured in ACS, and it works.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The config is:&lt;/P&gt;&lt;P&gt;The ip address of the primary dc,&lt;/P&gt;&lt;P&gt;port 636,&lt;/P&gt;&lt;P&gt;Use LDAPv3 (as it is on the ldap server)&lt;/P&gt;&lt;P&gt;Use secure authentication&lt;/P&gt;&lt;P&gt;Use the already installed and trusted Root CA certificate&lt;/P&gt;&lt;P&gt;the user with which I used in the 3rd party application and it could query the domain.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Still, when I try to query the LDAP, it does not work giving an error that &lt;/P&gt;&lt;P&gt;External DB reports about an error condition&lt;/P&gt;&lt;P&gt;I put a sniffer and I saw that the primary DC sends its' certificate and immediately after that the ACS server replies with Unknown CA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas why?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Chris&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 02:40:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-4-2-generic-ldap-with-ssl/m-p/2052352#M184590</guid>
      <dc:creator>cstamataras</dc:creator>
      <dc:date>2019-03-11T02:40:41Z</dc:date>
    </item>
    <item>
      <title>ACS 4.2 Generic LDAP with SSL</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-4-2-generic-ldap-with-ssl/m-p/2052353#M184610</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have a similar issue.&amp;nbsp; Trying to set up EAP-TLS against an ADAM instance (Generic LDAP) with ACS 4.2.&amp;nbsp; I'm not able to enumerate the directory (not sure if this works anyway - have never worked with LDAP in ACS before) or authenticate against it.&amp;nbsp; I can successfully authenticate against the same AD using EAP-TLS via windows (user and machine), but it's not working as LDAP.&amp;nbsp; I'm also getting the "&lt;EM&gt;External DB reports about an error condition&lt;/EM&gt;" message in the failed log.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Oct 2012 20:43:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-4-2-generic-ldap-with-ssl/m-p/2052353#M184610</guid>
      <dc:creator>mmletzko</dc:creator>
      <dc:date>2012-10-30T20:43:36Z</dc:date>
    </item>
  </channel>
</rss>

