LDAP Authentication with StartTLS

Need help? Post your questions here.

Moderator: moderators

LDAP Authentication with StartTLS

Postby namedJim » Fri Aug 09, 2019 7:10 am

Hello!

I just installed using subsonic and love it already. Really excited to see what it can do.

Running in a OracleVM with Ubuntu 18.04.3 Server, fresh install/update.

I'm trying to configure LDAP Authentication to another 18.04.3 VM with required TLS, connecting through a manager DN.

Both servers are secured with Let's Encrypt DNS Certificates via Apache DigitalOcean API, but I'm not sure how to get a connection between subsonic and the LDAP server. The connection works to a test unsecured LDAP Server with an identical schema (except for TLS), and there are no problems with http/https/proxy.

I'll post any config/log files that might help, but not sure where to start. Even if someone can point me in the direction of where to look for debug/log info beyond the browser gui, that would be a big help.

Thanks!
namedJim
 
Posts: 2
Joined: Fri Aug 09, 2019 6:59 am

Re: LDAP Authentication with StartTLS

Postby namedJim » Fri Aug 09, 2019 9:15 am

Update --

I've followed through this thread viewtopic.php?f=2&t=18263#p76960, and put (think I've) put together a keystore for the subsonic server Let's Encrypt certificates following the same how-to that helped there - http://www.richgrundy.com/blog/setting- ... -subsonic/

Good news is that the https site loads much faster; but TLS to the LDAP Server is still not going through.

subsonic.log includes this error:

Code: Select all
Caused by: Java.naming.AuthenticationNotSupportedException: [LDAP: error code 13 - TLS confidentiality required]


(I'll post more of that log if it helps?)

I've never really done anything with Java before, so I'm not even sure if I'm asking the right ballpark of question here - but is it possible/necessary to include multiple .keystore files, and pass the LDAP certs to Subsonic that way? Or is there something else I'm missing for how LDAP & Subsonic servers share TLS confidentiality?
namedJim
 
Posts: 2
Joined: Fri Aug 09, 2019 6:59 am


Return to Help

Who is online

Users browsing this forum: No registered users and 16 guests