11-11-2015 11:16 AM - edited 03-17-2019 04:52 AM
Dears,
I have a CUCM & unity connection 11.0 which is integrated with Microsoft AD with an secure LDAP, i am able to sync users on port 636 but authentication fails for users on port 636,
i have installed root certificate of AD in unity connection & CUCM and restated the tomcat services ,,,when i do a telnet on port 636 the port is open on ldap, but authentication is not working,,, when i remove the SSL tick and keep port as 389 authentication works fine, now i want to justify to the windows admin how i can ???
The only difference in unity connection and cucm is TLS box in cucm and ssl box in unity connection,
thanks
11-12-2015 06:12 AM
Is the LDAP server also a global catalog? If so have you tried port 3269?
11-13-2015 10:37 PM
Dear Chris,
I tried all the possibilities but the authentication is not working. now i want to justify how could i do that.
thanks
10-04-2017 10:23 AM
i know this has been awhile but did you ever get this fixed..running into same issue
04-17-2020 10:20 AM - edited 04-20-2020 12:44 AM
Hey,
just in case some other poor soul stumbles on this issue and finds this thread...
There's a COP file for CUCM 11.x that has "ldap_ssl" (edit: Anthony has posted the title below) in the title, which hasn't fixed the issue for us but TAC recommended installing this on Unity first.
After telling TAC that that did not work, they told me to run this command via Unity's CLI:
utils ldap config ipaddr
That fixed it for me. We are running IP addresses instead of hostnames though. If you do, too, give this a try!
Best
Jan
04-17-2020 11:12 AM
04-20-2020 12:34 AM
Hey Anthony,
a colleague of mine gave me a hint and let me know that I might have overseen the key fact in my specific case: we haven't entered FQDNs in the LDAP config and that will lead to TLS verification not working.
So, maybe the COP file would have indeed helped with solving the bug behaviour, but I still have misconfiguration on my part.
The CLI command I posted would probably only really disable TLS verification at all and by that, fix the issue...
Best
Jan
06-16-2020 01:41 PM - edited 06-16-2020 01:41 PM
Hey Anthony,
I'm curious. Did the version 11 cop file work for 12.5?
Thanks,
Nick Bacon
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide