cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Issue registering LDAP server

We're having trouble registering a new LDAP server in our ePO Console (version 5.9.1 Build 251).

We have tested communications from the ePO server to the LDAP server via command console successfully. 

Then, we configured the server in the ePO console and the following error pops up:

image001.png

 

 

 

 

 

Does anyone know why could this be happening?

Thank you.

8 Replies
cdinet
McAfee Employee
McAfee Employee
Report Inappropriate Content
Message 2 of 9

Re: Issue registering LDAP server

What if you disable use ssl?  Does it succeed then?  Also, be careful posting company info on a public forum.  

Was my reply helpful?
If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?

Re: Issue registering LDAP server

If we try to add the server while disabling the use of SSL it still gives an error message.

It says that it's not able to authenticate with the LDAP server.

Also, the info in the screenshot is a placeholder for the actual company login credentials and IPs, we tried to register the server with correct data.

Thank you.

uday-
McAfee Employee
McAfee Employee
Report Inappropriate Content
Message 4 of 9

Re: Issue registering LDAP server

Hello SiacloudNetsec,

Reviewing from the screenshot,

1. Is the domain name in The credentials used which is "dominio\usuario" correct or should it be "kioskos\usuario". Input the correct username "domain\username". (Also verify if the username is a domain admin and is in the active state)


2. Also try unchecking the SSL option, If you have not enabled SSL on active directory.

Was my reply helpful?

If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?

Re: Issue registering LDAP server

1. The credentials in the screenshot are just placeholders, we tried to register the server with the actual company credentials and IPs.

2. Unchecking the SSL option just changes the error message to "Unable to authenticate with the LDAP server. Verify that the username and password are correct.". The username and password are indeed correct.

By the way, are there any previous requirements that a server must fulfill in order to be able to be registered as a LDAP server in McAfee ePO? Like having connectivity to the ePO server in the 636 port?

I'm asking this because the root of the problem may not even be in the way we're trying to register it, but in the server config itself.

Thank you.
cdinet
McAfee Employee
McAfee Employee
Report Inappropriate Content
Message 6 of 9

Re: Issue registering LDAP server

If there are any firewalls in the way, the port would need to be open from epo to ldap server.  Is the epo server on the same domain?  Did you use domain name, IP or NetBIOS name of the ldap server?  Does orion log show anything?  Does the event log on the domain controller show any errors?

 

Was my reply helpful?
If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?

Re: Issue registering LDAP server

We attach evidence that this is not a connectivity problem between the servers. 

2020-04-17 12_12_25-Window.png

2020-04-17 12_12_10-Window.png

Nslookup, ping and even Telnet connections in the 636 port are successful (both via IP and via server name). I believe we can discard connectivity between servers as the main issue in this case. 

Could you tell us where the Orion logs are located? Checking them might be useful.

Do you have any other ideas to why this might be happening?

Thank you.

cdinet
McAfee Employee
McAfee Employee
Report Inappropriate Content
Message 8 of 9

Re: Issue registering LDAP server

Orion logs are located in the epo install directory under server\logs.  Is the epo server on the same domain as the domain controller or is either in a sub domain or different domain?

Was my reply helpful?
If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?

cdinet
McAfee Employee
McAfee Employee
Report Inappropriate Content
Message 9 of 9

Re: Issue registering LDAP server

You can also try this to see if it returns the correct domain controller that epo is authenticating with.

Please run the following commands from a "run as administrator" command shell (For the second and third commands, replace DOMAIN with the name of the domain the server belongs to.)

SET > c:\%computername%_set.txt
nltest /dsgetdc:DOMAIN > c:\%computername%_getdc.txt
nltest /dclist:DOMAIN > c:\%computername%_dclist.txt

Was my reply helpful?
If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?

You Deserve an Award
Don't forget, when your helpful posts earn a kudos or get accepted as a solution you can unlock perks and badges. Those aren't the only badges, either. How many can you collect? Click here to learn more.

Community Help Hub

    New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

  • Find Forum FAQs
  • Learn How to Earn Badges
  • Ask for Help
Go to Community Help

Join the Community

    Thousands of customers use the McAfee Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

  • Get helpful solutions from McAfee experts.
  • Stay connected to product conversations that matter to you.
  • Participate in product groups led by McAfee employees.
Join the Community
Join the Community