<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ACS 5.2 : LDAPS error in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-5-2-ldaps-error/m-p/1757958#M223788</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I configured a LDAP identity store.&lt;/P&gt;&lt;P&gt;When I use LDAP without Secure Authentication, connection works.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I use LDAP with Secure Authentication, I have to configure root CA.&lt;/P&gt;&lt;P&gt;I check LDAP connectivity with "Test Bind to Server" button --&amp;gt; "Connection test bind Succeeded"&lt;/P&gt;&lt;P&gt;After "Directory Organization" configuration, I check with "Test Configuration" button --&amp;gt; "Number of Subjects &amp;gt;100, Number of Groups &amp;gt; 100"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When ACS receives a real authentication, I got this error:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE id="S2"&gt;&lt;TBODY&gt;&lt;TR align="left" style="font-weight: normal; color: #000000; padding: 1pt 2pt; border: thin none solid #8499a2;" valign="middle"&gt;&lt;TD style="padding: 2pt 4pt;" valign="middle"&gt;&lt;P style="margin-top: 0pt;"&gt;24016&amp;nbsp; Looking up user in LDAP Server - username&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" style="font-weight: normal; color: #ff0000; padding: 1pt 2pt; border: thin none solid #8499a2;" valign="middle"&gt;&lt;TD style="padding: 2pt 4pt;" valign="middle"&gt;&lt;P style="margin-top: 0pt;"&gt;24030&amp;nbsp; SSL connection error was encountered&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" style="font-weight: normal; color: #ff0000; padding: 1pt 2pt; border: thin none solid #8499a2;" valign="middle"&gt;&lt;TD style="padding: 2pt 4pt;" valign="middle"&gt;&lt;P style="margin-top: 0pt;"&gt;24033&amp;nbsp; Primary server failover. Switching to secondary server&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And this description by ACS: &lt;/P&gt;&lt;TABLE id="__TOC_0" style="border-collapse: collapse; empty-cells: show; width: 98%; font-family: sans-serif; font-size: small; margin: 0pt; border: 1px none solid solid #e3e3e3 #808080 #808080;"&gt;&lt;TBODY&gt;&lt;TR align="left" style="font-family: arial; font-weight: bold; font-size: 10pt; color: #000000; text-transform: none;" valign="middle"&gt;&lt;TH align="center" style="font-family: arial; font-weight: normal; font-size: 10pt; padding-top: 1pt; padding-right: 2pt; padding-left: 2pt; background-color: #d9e3e9; border: 1px 1px 1px thin solid #8499a2 #ffffff #8499a2 #8499a2;" valign="middle"&gt;&lt;P id="AUTOGENBOOKMARK_5" style="text-align: left; padding-top: 1pt; padding-left: 5pt;"&gt;Description&lt;/P&gt;&lt;/TH&gt; &lt;/TR&gt;&lt;TR align="left" style="font-weight: normal; color: #000000; padding: 1pt 2pt; background-color: #f5f9fd; border: thin none solid #8499a2;" valign="middle"&gt;&lt;TD style="padding: 2pt 4pt;" valign="middle"&gt;&lt;P style="text-align: left; padding-top: 1pt; padding-left: 5pt;"&gt;SSL connection error was encountered&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE id="__TOC_1" style="border-collapse: collapse; empty-cells: show; width: 98%; font-family: sans-serif; font-size: small; margin: 3pt 0pt 0pt; border: 1px none solid solid #e3e3e3 #808080 #808080;"&gt;&lt;COL style="width: 98%;" /&gt; &lt;TBODY&gt;&lt;TR align="left" style="font-family: arial; font-weight: bold; font-size: 10pt; color: #000000; text-transform: none;" valign="middle"&gt;&lt;TH align="center" style="font-family: arial; font-weight: normal; font-size: 10pt; padding-top: 1pt; padding-right: 2pt; padding-left: 2pt; background-color: #d9e3e9; border: 1px solid #8499a2 #ffffff #8499a2 #8499a2;" valign="middle"&gt;&lt;P id="AUTOGENBOOKMARK_6" style="text-align: left; padding-top: 1pt; padding-left: 5pt;"&gt;Resolution Steps&lt;/P&gt;&lt;/TH&gt; &lt;/TR&gt;&lt;TR align="left" style="font-weight: normal; color: #000000; padding: 1pt 2pt; background-color: #f5f9fd; border: thin none solid #8499a2;" valign="middle"&gt;&lt;TD style="padding: 2pt 4pt;" valign="middle"&gt;&lt;DIV style="text-align: left; padding-top: 1pt; padding-left: 5pt;"&gt;Check&amp;nbsp; whether Use Secure Connection is enabled for the appropriate LDAP&amp;nbsp; server and the appropriate root CA is selected to have SSL connection to&amp;nbsp; LDAP Server&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't understand what is the problem...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If someone has an idea...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Patrick&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 01:26:21 GMT</pubDate>
    <dc:creator>Patrick Tran</dc:creator>
    <dc:date>2019-03-11T01:26:21Z</dc:date>
    <item>
      <title>ACS 5.2 : LDAPS error</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-2-ldaps-error/m-p/1757958#M223788</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I configured a LDAP identity store.&lt;/P&gt;&lt;P&gt;When I use LDAP without Secure Authentication, connection works.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I use LDAP with Secure Authentication, I have to configure root CA.&lt;/P&gt;&lt;P&gt;I check LDAP connectivity with "Test Bind to Server" button --&amp;gt; "Connection test bind Succeeded"&lt;/P&gt;&lt;P&gt;After "Directory Organization" configuration, I check with "Test Configuration" button --&amp;gt; "Number of Subjects &amp;gt;100, Number of Groups &amp;gt; 100"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When ACS receives a real authentication, I got this error:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE id="S2"&gt;&lt;TBODY&gt;&lt;TR align="left" style="font-weight: normal; color: #000000; padding: 1pt 2pt; border: thin none solid #8499a2;" valign="middle"&gt;&lt;TD style="padding: 2pt 4pt;" valign="middle"&gt;&lt;P style="margin-top: 0pt;"&gt;24016&amp;nbsp; Looking up user in LDAP Server - username&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" style="font-weight: normal; color: #ff0000; padding: 1pt 2pt; border: thin none solid #8499a2;" valign="middle"&gt;&lt;TD style="padding: 2pt 4pt;" valign="middle"&gt;&lt;P style="margin-top: 0pt;"&gt;24030&amp;nbsp; SSL connection error was encountered&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" style="font-weight: normal; color: #ff0000; padding: 1pt 2pt; border: thin none solid #8499a2;" valign="middle"&gt;&lt;TD style="padding: 2pt 4pt;" valign="middle"&gt;&lt;P style="margin-top: 0pt;"&gt;24033&amp;nbsp; Primary server failover. Switching to secondary server&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And this description by ACS: &lt;/P&gt;&lt;TABLE id="__TOC_0" style="border-collapse: collapse; empty-cells: show; width: 98%; font-family: sans-serif; font-size: small; margin: 0pt; border: 1px none solid solid #e3e3e3 #808080 #808080;"&gt;&lt;TBODY&gt;&lt;TR align="left" style="font-family: arial; font-weight: bold; font-size: 10pt; color: #000000; text-transform: none;" valign="middle"&gt;&lt;TH align="center" style="font-family: arial; font-weight: normal; font-size: 10pt; padding-top: 1pt; padding-right: 2pt; padding-left: 2pt; background-color: #d9e3e9; border: 1px 1px 1px thin solid #8499a2 #ffffff #8499a2 #8499a2;" valign="middle"&gt;&lt;P id="AUTOGENBOOKMARK_5" style="text-align: left; padding-top: 1pt; padding-left: 5pt;"&gt;Description&lt;/P&gt;&lt;/TH&gt; &lt;/TR&gt;&lt;TR align="left" style="font-weight: normal; color: #000000; padding: 1pt 2pt; background-color: #f5f9fd; border: thin none solid #8499a2;" valign="middle"&gt;&lt;TD style="padding: 2pt 4pt;" valign="middle"&gt;&lt;P style="text-align: left; padding-top: 1pt; padding-left: 5pt;"&gt;SSL connection error was encountered&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE id="__TOC_1" style="border-collapse: collapse; empty-cells: show; width: 98%; font-family: sans-serif; font-size: small; margin: 3pt 0pt 0pt; border: 1px none solid solid #e3e3e3 #808080 #808080;"&gt;&lt;COL style="width: 98%;" /&gt; &lt;TBODY&gt;&lt;TR align="left" style="font-family: arial; font-weight: bold; font-size: 10pt; color: #000000; text-transform: none;" valign="middle"&gt;&lt;TH align="center" style="font-family: arial; font-weight: normal; font-size: 10pt; padding-top: 1pt; padding-right: 2pt; padding-left: 2pt; background-color: #d9e3e9; border: 1px solid #8499a2 #ffffff #8499a2 #8499a2;" valign="middle"&gt;&lt;P id="AUTOGENBOOKMARK_6" style="text-align: left; padding-top: 1pt; padding-left: 5pt;"&gt;Resolution Steps&lt;/P&gt;&lt;/TH&gt; &lt;/TR&gt;&lt;TR align="left" style="font-weight: normal; color: #000000; padding: 1pt 2pt; background-color: #f5f9fd; border: thin none solid #8499a2;" valign="middle"&gt;&lt;TD style="padding: 2pt 4pt;" valign="middle"&gt;&lt;DIV style="text-align: left; padding-top: 1pt; padding-left: 5pt;"&gt;Check&amp;nbsp; whether Use Secure Connection is enabled for the appropriate LDAP&amp;nbsp; server and the appropriate root CA is selected to have SSL connection to&amp;nbsp; LDAP Server&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't understand what is the problem...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If someone has an idea...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Patrick&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 01:26:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-2-ldaps-error/m-p/1757958#M223788</guid>
      <dc:creator>Patrick Tran</dc:creator>
      <dc:date>2019-03-11T01:26:21Z</dc:date>
    </item>
    <item>
      <title>ACS 5.2 : LDAPS error</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-2-ldaps-error/m-p/1757959#M223792</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Solved!&lt;/P&gt;&lt;P&gt;I used an Intermediate CA instead of root CA...&lt;/P&gt;&lt;P&gt;My bad!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Unfortunately, I was focused on LDAP test which succeeded...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Patrick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Sep 2011 11:31:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-2-ldaps-error/m-p/1757959#M223792</guid>
      <dc:creator>Patrick Tran</dc:creator>
      <dc:date>2011-09-28T11:31:08Z</dc:date>
    </item>
  </channel>
</rss>

