Security

last person joined: 16 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

clearpass and ldap server settings help

This thread has been viewed 7 times
  • 1.  clearpass and ldap server settings help

    Posted May 28, 2019 02:24 PM
      |   view attached

    Under Administration -> Operator Logins -> Servers 

    I have put in all the Ldap server information but I get the following error:

     

    Authentication failed (username unknown)


    I have also verified I can connect with the username password. I tested this by using ldp on the domain controller and I was able to bind and search.

     

    I have tried various different settings but I Can't get it to work. 

    Attached is a screenshot of my settings.


    Also,

    The documentation for this is wrong. 

    It says

     

    "Bind DN

    The password to use when binding to the LDAP server. For an anonymous bind, leave this field empty."

     

    The bind DN is not the password!

     

    Any suggestions?

     

    https://www.arubanetworks.com/techdocs/ClearPass/CPGuest_UG_HTML_6.5/Default.htm#OperatorLogins/CreatingLDAPServer.htm#kanchor549



  • 2.  RE: clearpass and ldap server settings help

    EMPLOYEE
    Posted May 28, 2019 02:34 PM

    This is what I have:

     

    BindDN cn=domainuser,cn=users,dc=domain,dc=com

     

    BaseDN dc=domain,dc=com

     

     



  • 3.  RE: clearpass and ldap server settings help

    Posted May 28, 2019 02:45 PM

    I do not have a BaseDN  in clearpass 6.7



  • 4.  RE: clearpass and ldap server settings help

    EMPLOYEE
    Posted May 28, 2019 02:57 PM

    Are you editing the authentication source?



  • 5.  RE: clearpass and ldap server settings help

    EMPLOYEE
    Posted May 28, 2019 03:19 PM

    You are correct that the doc has an error.  The UI hint is correct but the guide has a missed copy-paste from the password field.

     

    Base DN is there for the POSIX compliant option.  AD just has the username and password.  There are varying formats for username so make sure you are entering the one your system wants.

     

    What scheme are you using?  ldap3s:///?



  • 6.  RE: clearpass and ldap server settings help
    Best Answer

    Posted Jun 05, 2019 02:46 PM

    Here are the settings that made it work finally. 

     

    It does not work without the bind dn empty. They should really clarify what is needed for this in the docs. Literally every application whats differerent settings. Also important was specifying dc=mydomain,dc=local in the server url. Hope this helps someone else.


    clearpass-ldap-server-settings.PNG