<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Unable to read rootDSE Error (LDAPs to Microsoft AD) in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/unable-to-read-rootdse-error-ldaps-to-microsoft-ad/m-p/3820430#M13725</link>
    <description>&lt;P&gt;I know this post is old, but I had a similar problem -- shows the 'Connect to LDAP Server... ' as successful, but fails with the '&lt;SPAN&gt;Unable to read rootDSE.' error.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;In my case I was missing the 'ldap-over-ssl enable' on my LDAPS aaa-server profile.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 15 Mar 2019 21:13:07 GMT</pubDate>
    <dc:creator>lisa1800</dc:creator>
    <dc:date>2019-03-15T21:13:07Z</dc:date>
    <item>
      <title>Unable to read rootDSE Error (LDAPs to Microsoft AD)</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-read-rootdse-error-ldaps-to-microsoft-ad/m-p/3696633#M13723</link>
      <description>&lt;P&gt;Does anyone know how to fix this error below:&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;[-2147483518] Session Start&lt;BR /&gt;[-2147483518] New request Session, context 0x00007f8c52c4f7e8, reqType = Authentication&lt;BR /&gt;[-2147483518] Fiber started&lt;BR /&gt;[-2147483518] Creating LDAP context with uri=ldap://x.x.x.x:636&lt;BR /&gt;[-2147483518] Connect to LDAP server: ldap://x.x.x.x:636, status = Successful&lt;BR /&gt;[-2147483518] Unable to read rootDSE. Can't contact LDAP server.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I tried following this URL,&amp;nbsp;&lt;A href="https://paulgporter.net/2013/01/03/cisco-asa-ldap-ssl/" target="_blank"&gt;https://paulgporter.net/2013/01/03/cisco-asa-ldap-ssl/&lt;/A&gt;, but it is not working and the URL is for OpenLDAP and not Microsoft LDAPs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I followed this step when configuring LDAPs on the Microsoft Server:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://blogs.msdn.microsoft.com/microsoftrservertigerteam/2017/04/10/step-by-step-guide-to-setup-ldaps-on-windows-server/" target="_blank"&gt;https://blogs.msdn.microsoft.com/microsoftrservertigerteam/2017/04/10/step-by-step-guide-to-setup-ldaps-on-windows-server/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 16:09:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-read-rootdse-error-ldaps-to-microsoft-ad/m-p/3696633#M13723</guid>
      <dc:creator>latenaite2011</dc:creator>
      <dc:date>2020-02-21T16:09:37Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to read rootDSE Error (LDAPs to Microsoft AD)</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-read-rootdse-error-ldaps-to-microsoft-ad/m-p/3820429#M13724</link>
      <description>&lt;P&gt;I know this post is old, but I had a similar problem -- shows the 'Connect to LDAP Server... ' as successful, but fails with the '&lt;SPAN&gt;Unable to read rootDSE.' error.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;In my case I was missing the 'ldap-over-ssl enable' on my LDAPS aaa-server profile.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Mar 2019 21:12:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-read-rootdse-error-ldaps-to-microsoft-ad/m-p/3820429#M13724</guid>
      <dc:creator>lisa1800</dc:creator>
      <dc:date>2019-03-15T21:12:27Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to read rootDSE Error (LDAPs to Microsoft AD)</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-read-rootdse-error-ldaps-to-microsoft-ad/m-p/3820430#M13725</link>
      <description>&lt;P&gt;I know this post is old, but I had a similar problem -- shows the 'Connect to LDAP Server... ' as successful, but fails with the '&lt;SPAN&gt;Unable to read rootDSE.' error.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;In my case I was missing the 'ldap-over-ssl enable' on my LDAPS aaa-server profile.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Mar 2019 21:13:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-read-rootdse-error-ldaps-to-microsoft-ad/m-p/3820430#M13725</guid>
      <dc:creator>lisa1800</dc:creator>
      <dc:date>2019-03-15T21:13:07Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to read rootDSE Error (LDAPs to Microsoft AD)</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-read-rootdse-error-ldaps-to-microsoft-ad/m-p/4725388#M1095204</link>
      <description>&lt;P&gt;I know this is an old post, but I've hit it a few times and every time "Unable to read rootDSE" combined with the use of LDAPs turned out to be the ASA unable to reach the CRL service associated with the certificate coming back from the LDAPs server.&lt;/P&gt;&lt;P&gt;These debugs helped me:&lt;/P&gt;&lt;PRE&gt;debug ldap 255 - not that useful. Just showed "Unable to read rootDSE"
debug crypto ca 14 - showed the SSL negotiation, including the CRL checks&lt;BR /&gt;capture CAP1 interface inside match tcp any any eq 636 THEN copy /pcap capture CAP1 ... - showed the Domain Controller issuing a ServerHello so presumably it was happy with the ASA ciphers&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;I'm sure there are other reasons for "Unable to read rootDSE", but the above debugs will narrow it down.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Nov 2022 19:05:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-read-rootdse-error-ldaps-to-microsoft-ad/m-p/4725388#M1095204</guid>
      <dc:creator>j.a.m.e.s</dc:creator>
      <dc:date>2022-11-21T19:05:15Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to read rootDSE Error (LDAPs to Microsoft AD)</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-read-rootdse-error-ldaps-to-microsoft-ad/m-p/4851570#M1101394</link>
      <description>&lt;P&gt;Error can be caused by cert verification failing due to weak algorithms: "crypto ca permit-weak-crypto" would override that check&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jun 2023 18:17:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-read-rootdse-error-ldaps-to-microsoft-ad/m-p/4851570#M1101394</guid>
      <dc:creator>tfs128</dc:creator>
      <dc:date>2023-06-08T18:17:51Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to read rootDSE Error (LDAPs to Microsoft AD)</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-read-rootdse-error-ldaps-to-microsoft-ad/m-p/5378216#M1124790</link>
      <description>&lt;P&gt;Thank you very much.&amp;nbsp; Debugging the crypto ca 14 showed me the problem.&amp;nbsp; The DC was presenting a cert signed by the default Windows Server CA, rather than the one generated by their PKI CA root which they had exported to me.&lt;/P&gt;&lt;P&gt;Thanks again!&lt;/P&gt;</description>
      <pubDate>Fri, 20 Mar 2026 20:20:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-read-rootdse-error-ldaps-to-microsoft-ad/m-p/5378216#M1124790</guid>
      <dc:creator>grrr</dc:creator>
      <dc:date>2026-03-20T20:20:42Z</dc:date>
    </item>
  </channel>
</rss>

