EcoStruxure IT forum
Schneider Electric support forum about installation and configuration for DCIM including EcoStruxure IT Expert, IT Advisor, Data Center Expert, and NetBotz
Link copied. Please paste this link to share this article on your social media post.
Posted: 2020-07-03 03:22 AM . Last Modified: 2024-04-08 11:59 PM
Hi,
I had an issue with Active Directory authentication in DCO and was not able to view the related certificate (no result after clicking on the button, see screenhost)
From time to time I have to trust again the LDAPs certificate
How to permanently install the Issuing Certificate to validate?
In the server.log log file I get:
javax.net.ssl.SSLHandshakeException: sun.security.validator.ValidatorException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target
And how to check the installed certificates?
Regards,
Yannick
(CID:106205841)
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: 2020-07-03 03:22 AM . Last Modified: 2024-04-08 11:59 PM
Hi Jannick,
If I understand correctly this is likely due to the certificate change on the authentication server itself, and then the new certificate (from the AD/LDAP server) must be updated/trusted on DCO (otherwise the AD users won't be able to log in). And concerning the last question, eg, checking the installed certificates, I will see what I can find for you, thanks.
Kind regards
(CID:106205915)
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: 2020-07-03 03:22 AM . Last Modified: 2024-04-08 11:59 PM
Hi Jef, I confirm, I get this message after certificate changes In fact, the server name I specified is an alias that points to some LDAP servers and from time to time the target server is modified That's why I would like to add the Public Issuing Certificate into the certificate store to trust any children certificates Best Regards, Yannick
(CID:106207286)
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: 2020-07-03 03:22 AM . Last Modified: 2024-04-08 11:59 PM
Hi Yannick, Many thanks for the additional comments, I had a brief talk with developers and I've been told that the certificates must be handled on the LDAP server(s). Kind regards
(CID:106207599)
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: 2020-07-03 03:22 AM . Last Modified: 2023-10-31 10:48 PM
This question is closed for comments. You're welcome to start a new topic if you have further comments on this issue.
Link copied. Please paste this link to share this article on your social media post.
Create your free account or log in to subscribe to the board - and gain access to more than 10,000+ support articles along with insights from experts and peers.