cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1371
Views
0
Helpful
8
Replies

LDAP Error with VCS Control

Kim Fitzgerald
Level 1
Level 1

                   I am trying to set up LDAP communication on the VCS Control.  I am currently experiencing an error on the VCS Control with software X7.2.1.  error message reads Invalid VCS Bind Credentials.  All of the credentials and LDAp tree path have been validated, we have reset the password in AD and re-entered on the VCS, we have tried to use the digest setting as well as none on the SASL field.  Our LDAP administrator states the account is set up in AD, and is set as read only account with no special privledges.

Is anyone aware of any bugs with this particular setup?  Will the credentials fail if we are using a complex password (capital letters, lower case letters, characters, numbers) ? Any recommendations for the VCS Control?  The error message indicates this is on the LDAP side, however the administrator indicates the LDAP is set up correctly.

Has anyone else has run into a similar issue?

8 Replies 8

Zac Colton
Cisco Employee
Cisco Employee

Can you provide a screen shot of the settings you are using?

Sent from Cisco Technical Support iPhone App

Kim Fitzgerald
Level 1
Level 1

The following is entered in the screens:

Zac Colton
Cisco Employee
Cisco Employee

So it does not allow you to save the settings? Is that when the error is shown? I would recommend taking a tcpdump if the VCS at the time of saving the settings. You can filter the capture in wire shark for ldap. The response on the bind attempt should provide more details. I would also recommend looking at the windows event logs at the time. Quick question: is your Active Directory if a single domain, or are their subdomains?

Sent from Cisco Technical Support iPhone App

Hi Zachery,

We are able to save the settings, and then the invalid bind crendtials message comes up.  The account has been reset multiple times as well. they are using a single domain.

Thanks.

Kim,

I would suggest a packet capture to identify what the AD DC is returning in response to the bind request. Have you tried pointing to the Global Catalogue port (3268)?

- Zac

The VCS log is showing the following: 

2013-10-09T11:42:13-04:00 sshd[32364]: Module="nss_ldap" Level="ERROR" UTCTime="2013-10-09 15:42:13,120" Detail="Could not search LDAP server" Reason="Server is unavailable"

2013-10-09T11:42:13-04:00 sshd[32364]: Module="nss_ldap" Level="INFO" UTCTime="2013-10-09 15:42:13" Detail="Failed to bind to LDAP server" URI="

ldap://10.10.1.99" Reason="Invalid credentials"

2013-10-09T11:42:13-04:00 sshd[32364]: Module="nss_ldap" Level="ERROR" UTCTime="2013-10-09 15:42:13,120" Detail="Could not search LDAP server" Reason="Server is unavailable"

2013-10-09T11:42:13-04:00 sshd[32364]: Module="nss_ldap" Level="INFO" UTCTime="2013-10-09 15:42:13" Detail="Failed to bind to LDAP server" URI="

ldap://10.10.1.99" Reason="Invalid credentials"

And the windows server from what i currently have access/feedback on does not appear to have an attempt, i have this being rechecked.  i believe the communication from the control to the server is failing, yet under the active directory on the configuration page, it shows there is a link and communication between to the two. 

Any ideas on why we show a valid link to the exchange server, but the server may not respond or ever see the request? Do I need to be looking at other ports other than port 389 (nonsecure) for this communication? 

Apprecitate any thoughts/feeback.

Have you taken a packet caputure on the VCS while saving this configuration? In it you will see the bind request and the response form the server you are trying to bind to.

I'm assuming when you references your Exchange server that the Exchange server is a Domain Controller. The Active Directory Service page is not for LDAP. That is for the winbind service - the VCS being joined to and being a memeber of the Adctive Directory Domain. This is a completely different animal.

Unsing some 3rd party ldap tool and try to access the data might also be interesting.

You should know best what can be used to authenticate. But for me it looks that info is not ok.

Please remember to rate helpful responses and identify helpful or correct answers.

Please remember to rate helpful responses and identify