Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win

x
?
Solved

Graylog, LDAP bind issue when trying to make the connection, incorporate AD. Please help!

Posted on 2016-08-26
1
Medium Priority
?
220 Views
Last Modified: 2016-08-26
Here is the error message:
MessageType : BIND_RESPONSE
Message ID : 4
    BindResponse
        Ldap Result
            Result code : (INVALID_CREDENTIALS) invalidCredentials
            Matched Dn : ''
            Diagnostic message : '80090308: LdapErr: DSID-0C0903CF, comment: AcceptSecurityContext error, data 52e, v2580'
Also:
Diagnostic message : '80090308: LdapErr: DSID-0C0903CF, comment: AcceptSecurityContext error, data 775, v2580'

The server configuration makes a successful connection to Active Directory but cannot bind.
Here are my settings:

Server address: ldap://x.x.x.x:389
username: admin@domain.com
Search Base DN: dc=dc,dc=name,dc=com
User Search Pattern: (objectClass=user)
Display Name attribute: displayName
Group Search Base DN: dc=prod,dc=Admi,dc=Com
Group Search Pattern: (objectClass=group)
Group Name Attribute: cn
Default User Role: Administrator
ALL SEEMS WELL UNTIL...
Login test: Domain Admin
password: xxxxx
Tried: admin@domain.com as well...no luck
User account is fine, not locked out etc and works for everything BUT Graylog. I hit "Test Login":



MessageType : BIND_RESPONSE
Message ID : 4
    BindResponse
        Ldap Result
            Result code : (INVALID_CREDENTIALS) invalidCredentials
            Matched Dn : ''
            Diagnostic message : '80090308: LdapErr: DSID-0C0903CF, comment: AcceptSecurityContext error, data 775, v2580'
0
Comment
Question by:admitech
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
1 Comment
 

Accepted Solution

by:
admitech earned 0 total points
ID: 41772291
Had to reduce the search base dn down to the CN level. Worked fine.
CN=user,OU=whatever,dc=domain,dc=com
0

Featured Post

Important Lessons on Recovering from Petya

In their most recent webinar, Skyport Systems explores ways to isolate and protect critical databases to keep the core of your company safe from harm.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Had a business requirement to store the mobile number in an environmental variable. This is just a quick article on how this was done.
A bad practice commonly found during an account life cycle is to set its password to an initial, insecure password. The Password Reset Tool was developed to make the password reset process easier and more secure.
Learn several ways to interact with files and get file information from the bash shell. ls lists the contents of a directory: Using the -a flag displays hidden files: Using the -l flag formats the output in a long list: The file command gives us mor…
Are you ready to implement Active Directory best practices without reading 300+ pages? You're in luck. In this webinar hosted by Skyport Systems, you gain insight into Microsoft's latest comprehensive guide, with tips on the best and easiest way…
Suggested Courses

610 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question