Version Affected: All
Overview
Testing an AD LDS (Active Directory Lightweight Directory Services) datastore connection over SSL can fail with the following error, even when the connection settings otherwise follow the standard configuration documentation:
The specified directory service attribute or value does not exist
Cause
The datastore's connection string is configured incorrectly -- specifically, a domain name is entered in the Domain field, and the Service Account isn't specified as a full distinguished name.
Resolution:
- Go to the realm's Data Store tab and open the AD LDS datastore's Membership Connection Settings.
- Clear the Domain field in both the Datastore Connection section and the Datastore Credentials section -- leave it blank.
- Set Service Account to the account's full distinguished name (for example, CN=ServiceAccount,OU=SAUsers,DC=domain,DC=name), instead of a domain\username or UPN-style value.
- Click Test Connection to confirm.
SecureAuth Knowledge Base Articles provide information based on specific use cases and may not apply to all appliances or configurations. Be advised that these instructions could cause harm to the environment if not followed correctly or if they do not apply to the current use case.
Customers are responsible for their own due diligence prior to utilizing this information and agree that SecureAuth is not liable for any issues caused by misconfiguration directly or indirectly related to SecureAuth products.
Comments
Please sign in to leave a comment.