<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic FMC External Authentication using LDAPs in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/fmc-external-authentication-using-ldaps/m-p/4067307#M1069243</link>
    <description>&lt;P&gt;I've setup the FMC (6.5.0.4) to use LDAP and that is working, but when i try to get LDAPS setup for authentication to the FMC itself it fails.&amp;nbsp; On the section when you choose the certificate I'm able to import the root CA, but when I go to test I get a warning that no certificate was selected.&amp;nbsp; Also, I should be using the hostnames of the domain controllers if I'm doing ssl or tls correct?&amp;nbsp; And will the root CA be sufficient or do I need to import a certifcate from both the primary and backup domain controllers so either can be used?&lt;/P&gt;</description>
    <pubDate>Thu, 16 Apr 2020 15:30:40 GMT</pubDate>
    <dc:creator>mumbles202</dc:creator>
    <dc:date>2020-04-16T15:30:40Z</dc:date>
    <item>
      <title>FMC External Authentication using LDAPs</title>
      <link>https://community.cisco.com/t5/network-security/fmc-external-authentication-using-ldaps/m-p/4067307#M1069243</link>
      <description>&lt;P&gt;I've setup the FMC (6.5.0.4) to use LDAP and that is working, but when i try to get LDAPS setup for authentication to the FMC itself it fails.&amp;nbsp; On the section when you choose the certificate I'm able to import the root CA, but when I go to test I get a warning that no certificate was selected.&amp;nbsp; Also, I should be using the hostnames of the domain controllers if I'm doing ssl or tls correct?&amp;nbsp; And will the root CA be sufficient or do I need to import a certifcate from both the primary and backup domain controllers so either can be used?&lt;/P&gt;</description>
      <pubDate>Thu, 16 Apr 2020 15:30:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-external-authentication-using-ldaps/m-p/4067307#M1069243</guid>
      <dc:creator>mumbles202</dc:creator>
      <dc:date>2020-04-16T15:30:40Z</dc:date>
    </item>
    <item>
      <title>Re: FMC External Authentication using LDAPs</title>
      <link>https://community.cisco.com/t5/network-security/fmc-external-authentication-using-ldaps/m-p/4067329#M1069246</link>
      <description>&lt;P&gt;I am also using 6.5.0.4 and it works for me&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ldap.PNG" style="width: 731px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/71856iF353F83C4F1C17F1/image-size/large?v=v2&amp;amp;px=999" role="button" title="ldap.PNG" alt="ldap.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Provide a screenshot of the error you receive.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you are using a certificate to authenticate, the name of the server in the certificate must match the server &lt;SPAN class="ph uicontrol"&gt;Hostname / IP Address&lt;/SPAN&gt;. For example, if you use 10.10.10.250 as the IP address but servername.domain.com in the certificate, the connection fails.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ensure you specifiy TLS not SSL&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Uploading the root certificate should be sufficient.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;</description>
      <pubDate>Thu, 16 Apr 2020 16:11:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-external-authentication-using-ldaps/m-p/4067329#M1069246</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2020-04-16T16:11:13Z</dc:date>
    </item>
    <item>
      <title>Re: FMC External Authentication using LDAPs</title>
      <link>https://community.cisco.com/t5/network-security/fmc-external-authentication-using-ldaps/m-p/4067396#M1069251</link>
      <description>&lt;P&gt;Thanks.&amp;nbsp; Yes, LDAP using 389 works.&amp;nbsp; It's when i change it to SSL and upload the root CA it fails to save. I can try changing the hostname to the FQDN and using TLS instead.&amp;nbsp; The root CA has a different name since the CA isn't on the domain controller.&amp;nbsp; Would that cause any issues?&lt;/P&gt;</description>
      <pubDate>Thu, 16 Apr 2020 17:10:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-external-authentication-using-ldaps/m-p/4067396#M1069251</guid>
      <dc:creator>mumbles202</dc:creator>
      <dc:date>2020-04-16T17:10:44Z</dc:date>
    </item>
    <item>
      <title>Re: FMC External Authentication using LDAPs</title>
      <link>https://community.cisco.com/t5/network-security/fmc-external-authentication-using-ldaps/m-p/4067415#M1069253</link>
      <description>The hostname/FQDN you use has to match the common name as defined in the certificate that is installed on the domain controller(s).</description>
      <pubDate>Thu, 16 Apr 2020 17:21:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-external-authentication-using-ldaps/m-p/4067415#M1069253</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2020-04-16T17:21:30Z</dc:date>
    </item>
    <item>
      <title>Re: FMC External Authentication using LDAPs</title>
      <link>https://community.cisco.com/t5/network-security/fmc-external-authentication-using-ldaps/m-p/4067559#M1069256</link>
      <description>&lt;P&gt;So TLS works w/o any issues.&amp;nbsp; It's just the SSL over 636 that I can't get going.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Apr 2020 20:27:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-external-authentication-using-ldaps/m-p/4067559#M1069256</guid>
      <dc:creator>mumbles202</dc:creator>
      <dc:date>2020-04-16T20:27:49Z</dc:date>
    </item>
    <item>
      <title>Re: FMC External Authentication using LDAPs</title>
      <link>https://community.cisco.com/t5/network-security/fmc-external-authentication-using-ldaps/m-p/4067611#M1069257</link>
      <description>&lt;P&gt;Why must you use SSL and not TLS? SSL is depreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I test using SSL on port 636, I successfully connect. A packet capture confirms that the connection was actually established using TLS, even though SSL was specified.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;If you use TLS on port 389 then you are using StartTLS. Run a packet capture and you will see the initial connection on LDAP, followed by a TLS handshake and subsequent data transfer is encrypted. Or you can run LDAPS on port 636, both StartTLS and LDAPS are secure and encrypt the communication.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Apr 2020 21:48:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-external-authentication-using-ldaps/m-p/4067611#M1069257</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2020-04-16T21:48:33Z</dc:date>
    </item>
    <item>
      <title>Re: FMC External Authentication using LDAPs</title>
      <link>https://community.cisco.com/t5/network-security/fmc-external-authentication-using-ldaps/m-p/4067639#M1069260</link>
      <description>&lt;P&gt;Thanks.&amp;nbsp; I set it up using TLS and 389 and confirmed working so will leave it as is.&amp;nbsp; I appreciate the assistance.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Apr 2020 22:28:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-external-authentication-using-ldaps/m-p/4067639#M1069260</guid>
      <dc:creator>mumbles202</dc:creator>
      <dc:date>2020-04-16T22:28:25Z</dc:date>
    </item>
    <item>
      <title>Re: FMC External Authentication using LDAPs</title>
      <link>https://community.cisco.com/t5/network-security/fmc-external-authentication-using-ldaps/m-p/4150970#M1073917</link>
      <description>&lt;P&gt;So this was working fine but stopped working as of this morning.&amp;nbsp; It was confirmed that it worked Friday but when trying to login this morning LDAP users are failing to login.&amp;nbsp; No changes were made to either the DC or the FMC over the weekend.&lt;/P&gt;</description>
      <pubDate>Mon, 14 Sep 2020 21:22:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-external-authentication-using-ldaps/m-p/4150970#M1073917</guid>
      <dc:creator>mumbles202</dc:creator>
      <dc:date>2020-09-14T21:22:51Z</dc:date>
    </item>
    <item>
      <title>Re: FMC External Authentication using LDAPs</title>
      <link>https://community.cisco.com/t5/network-security/fmc-external-authentication-using-ldaps/m-p/4404046#M1080831</link>
      <description>&lt;P&gt;I dont know if you solve this or not. but i have the same issue with external auth using LDAPS with certificate. the issue is the cert. it need to be PEM file. your server cert and sub ca or root ca. export the cert on the server as base. open them and copy the content in there to a file and save it as PEM.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 17 May 2021 13:16:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-external-authentication-using-ldaps/m-p/4404046#M1080831</guid>
      <dc:creator>chong00011</dc:creator>
      <dc:date>2021-05-17T13:16:31Z</dc:date>
    </item>
    <item>
      <title>Re: FMC External Authentication using LDAPs</title>
      <link>https://community.cisco.com/t5/network-security/fmc-external-authentication-using-ldaps/m-p/4854050#M1101554</link>
      <description>&lt;P&gt;I wanted to follow up on this. Someone mentioned that the certificate must match the IP of name of the DC server. How does on verify that. I am having issues connecting and i think the certificate i am using is wrong. How do i verify that?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jun 2023 17:54:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-external-authentication-using-ldaps/m-p/4854050#M1101554</guid>
      <dc:creator>Knassi</dc:creator>
      <dc:date>2023-06-13T17:54:52Z</dc:date>
    </item>
    <item>
      <title>Re: FMC External Authentication using LDAPs</title>
      <link>https://community.cisco.com/t5/network-security/fmc-external-authentication-using-ldaps/m-p/4855792#M1101685</link>
      <description>The certificate must match the FQDN of the domain controller not ip address.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Thu, 15 Jun 2023 22:16:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-external-authentication-using-ldaps/m-p/4855792#M1101685</guid>
      <dc:creator>chong00011</dc:creator>
      <dc:date>2023-06-15T22:16:52Z</dc:date>
    </item>
  </channel>
</rss>

