Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    LDAP Authentication fails but it Binds to the AD

    Scheduled Pinned Locked Moved General pfSense Questions
    5 Posts 2 Posters 654 Views 2 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • K Offline
      Knick
      last edited by

      Hello,

      i have a pfsene version 2.5.2-RELEASE (amd64) and i am trying to configure LDAPS Authnetication.

      I set the Authentication Server with a User and it binds Succsessfully to the Server and Retrives the OUs. Now i sepecified the Authentication Container with my User in it, and the Authentication just dosent work. With Wireshark i see the Connection building up and Tearing down at the End.
      With the Diagnostics function Authentication i get an Error.

      The weird thing is that it worked and then all of the Suddon it stopt.
      If ther are mor Informations Requierd just ask i try to answer them.

      Thanks for yout help
      Knick

      1 Reply Last reply Reply Quote 0
      • stephenw10S Offline
        stephenw10 Netgate Administrator
        last edited by

        Does it work if you set it to plain LDAP as a test?

        You can pcap the traffic and usually see what problem is if you do.

        Does the server show any errors?

        Steve

        1 Reply Last reply Reply Quote 0
        • K Offline
          Knick
          last edited by

          @stephenw10, no i still get the same error. The Server just says Authentication Error in the System logs. In a Packet Capture is nothing out o the Ordinary.

          MfG
          Knick

          1 Reply Last reply Reply Quote 0
          • stephenw10S Offline
            stephenw10 Netgate Administrator
            last edited by

            Something must have changed. I would look for something that has expired. Usually the cert but that would be proven by just using LDAP. So maybe the user?

            K 1 Reply Last reply Reply Quote 0
            • K Offline
              Knick @stephenw10
              last edited by

              @stephenw10, the User to Authenticate is mine. And i can Logon, also if the User was Expired the "Select Container" function woulden work. But it dose and i selectet a Container for Authentication.

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.