EcoStruxure IT forum
Schneider Electric support forum about installation and configuration for DCIM including EcoStruxure IT Expert, IT Advisor, Data Center Expert, and NetBotz
Link copied. Please paste this link to share this article on your social media post.
Posted: 2020-07-04 12:09 AM . Last Modified: 2024-04-05 04:41 AM
We are currently using StruxureWare Data Center Expert 7.2.6 which is configured to use LDAP authentication for user logons. We recently added two Windows Server 2016 Domain Controllers to our network and would like to move the StruxureWare LDAP authentication to these new 2016 servers.
In StruxureWare, we select the System menu and then Users and Device Group Access. In the Authentication Servers tab, we add the new 2016 server address and click Next. On the next page, we enter the Bind User DN and Password, the Search Base, and then click Next. We receive back the error message "Bind was unsuccessful. Check your settings."
We've tried using SSL, not using SSL, using server port 389, and using server port 636. No matter what settings we select, we receive back the "Bind was unsuccessful" error message. If we change the server address to a 2008 DC or 2012 DC, the bind is successful - we are able to continue without any problems. We only receive the error message when using a 2016 DC.
Is this a known issue? Is there any workaround? Would upgrading the software help? Any assistance is appreciated.
(CID:126158682)
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: 2020-07-04 12:09 AM . Last Modified: 2024-04-05 04:41 AM
Hi davidf,
I'm also interested in your question. But I can not check it out for myself. Therefore, I highly recommend that you download from DCE Virtual Machine and deploy latest VMware VM DCE-7.4.3 and check this current DCE-version with your Microsoft Server 2016 AD DC servers.
I doubt the success of this test, but it is necessary to test it.
Most likely, the problem is that even the latest DCE-7.4.3 only supports NTLMv1, which is forcibly disabled for security reasons in current versions of Microsoft OS. But I can be wrong 😀.
With respect.
(CID:126158944)
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: 2020-07-04 12:09 AM . Last Modified: 2024-04-05 04:41 AM
I deployed DCE-7.4.3 and ran into the same issue. I can bind to 2008 DCs and 2012 DCs, but not 2016 DCs.
(CID:126159347)
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: 2020-07-04 12:09 AM . Last Modified: 2024-04-05 04:40 AM
Hi davidf,
...As I expected ☹️.
If you are not difficult, you can make a download capture logs from DCE? How to do this is well written in topic .
It is very possible, after understanding a little of these DCE system logs, you can find a mention of the problem that leads to your message "Bind was unsuccessful" for MS Windows Server 2016 DC. To understand the DCE system logs my tips in topic will help.
Always glad to answer your questions.
(CID:126159359)
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: 2020-07-04 12:09 AM . Last Modified: 2024-04-05 04:40 AM
Hi davidf,
I created the appropriate Feature Requests on this issue with a link to this topic. I am also interested in this 😀.
With respect.
(CID:126160091)
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: 2020-07-04 12:09 AM . Last Modified: 2024-04-05 04:40 AM
Thanks. I downloaded the capture logs and hope to review them this afternoon.
(CID:126160210)
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: 2020-07-04 12:10 AM . Last Modified: 2024-04-05 04:40 AM
Also having the same problem!! Server 2016.
(CID:132652028)
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: 2020-07-04 12:10 AM . Last Modified: 2024-04-05 04:40 AM
Has this ever been resolved?
(CID:134033901)
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: 2020-07-04 12:10 AM . Last Modified: 2024-04-05 04:40 AM
Dear Jonathan,
As far as I know, so far nothing has changed, at least from the latest software DCE-7.5.0.
With respect.
(CID:134034069)
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: 2020-07-04 12:10 AM . Last Modified: 2024-04-05 04:40 AM
I found the policy preventing the bind from working. It is located in Group Policy Management at Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\Security Options. The Policy "Domain Controller: LDAP server signing requirements" was set to "Require signing". Once we changed this to "None", we were able to bind to the Domain Controller.
(CID:126160282)
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: 2020-07-04 12:10 AM . Last Modified: 2024-04-05 04:40 AM
Hi davidf,
Many thanks for the feedback and for solving the problem 😀.
(CID:126160342)
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: 2020-07-04 12:10 AM . Last Modified: 2023-10-22 02:54 AM
This question is closed for comments. You're welcome to start a new topic if you have further comments on this issue.
Link copied. Please paste this link to share this article on your social media post.
Create your free account or log in to subscribe to the board - and gain access to more than 10,000+ support articles along with insights from experts and peers.