Actions
Bug #14943
closedAuthentication server LDAPs Unknown CA
Status:
Not a Bug
Priority:
Low
Assignee:
-
Category:
Authentication
Target version:
-
Start date:
Due date:
% Done:
0%
Estimated time:
Release Notes:
Default
Affected Plus Version:
23.05.1
Affected Architecture:
4100
Description
Found that if you configure an authentication server without authentication (Standard TCP 389), and after that you change the configuration to SSL/TLS encrypted, connection works but you get a Unknown CA after a while.
Unknown CA message comes from pfSense's IP address.
Found this capturing packets on port 636 from the firewall to the LDAP server (samba-ad).
To solve this, you have to delete the authentication server completely, and recreate it again using the TLS/SSL 636 option, with the same settings.
Files
Actions