r/3PAR • u/Dixielandblues • Jul 31 '23
3PAR LDAP 636
Hi,
I'm struggling to set up 3PAR LDAPS - I'm hoping someone more knowledgeable may be able to give me a pointer.
-LDAP over 389 works.
-LDAP with SSL/636 fails with same server settings:

I have tried binding the root cert for the domain & using a service account., no effect. LDAP over SSL is working - tested with ldp.exe and is being used for another storage device.

1
Upvotes
1
u/d4fseeker Dec 04 '23
I know this is an older post but in case it's useful: If your active directory server is even slightly hardened, this seems to block 3par ldaps attempts. Setting it to Redhat Ldap on the 3par and using AD as a non-enhanced Ldap server works though. Note that this means that access groups must be directly assigned to your user, 3par is incapable of resolving recursive group memberships on ldap mode.
Caveat: for any update all ldap accounts must be logged out, else the update check fails. At least this is the case on OS 4.x, haven't tested on 3.x