由于证书不合适、站点发现期间显示secd.ldap.noServers:EMERGENCY
适用场景
- ONTAP 9
- 站点发现
- Domain Controller(域控制器)(DC)
- 安全轻型目录身份验证协议(LdAPS)
- 证书
问题描述
secd.conn.auth.failure
和secd.ldap.noServers
会显示在事件日志中:
[node_name: secd: secd.conn.auth.failure:notice]: Vserver (vserver_name) could not authenticate over the network to server (dc_server_name). Error: Can't contact LDAP server (Service: LDAP (Active Directory), Operation: SiteDiscovery).
[node_name: secd: secd.ldap.noServers:EMERGENCY]: None of the LDAP servers configured for Vserver (vserver_name) are currently accessible via the network for LDAP service type (Service: LDAP (Active Directory), Operation: SiteDiscovery).
- 已在Vserver上启用LdAPS
- 与DC服务器的通信成功,但证书握手期间发生错误-在
SECD.log
中观察到:
[kern_secd:info:15263] | [000.005.771] debug: Connection type LDAP (Active Directory) translated to LIF service = 99 { in getLifService() at src/connection_manager/secd_connection_shim.cpp:278 }
[kern_secd:info:15263] | [000.005.780] debug: CM_STATS: Tracking connect() to server 10.99.99.1, port 636 { in startConnectTracking() at src/cm/secd_cm_stats_manager.cpp:885 }
[kern_secd:info:15263] | [000.005.993] info : Successfully connected to ip 10.99.99.1, port 636 using TCP { in _connect() at src/connection_manager/secd_connection_shim.cpp:555 }
[kern_secd:info:15263] | [000.013.579] debug: LDAP TLS Alert generated is 'fatal:unsupported certificate'
[kern_secd:info:15263] | [000.013.705] debug: ldap_sasl_bind_s returned -1 { in ldapSaslBindSpnego() at src/connection_manager/secd_connection.cpp:854 }
[kern_secd:info:15263] | [000.013.727] ERR : Additional Error Message: error:0A000086:SSL routines::certificate verify failed (unsuitable certificate purpose) { in ldapSaslBindSpnego() at src/connection_manager/secd_connection.cpp:860 }
[kern_secd:info:15263] | [000.013.734] ERR : RESULT_ERROR_LDAPSERVER_SERVER_DOWN:7642 in ldapSaslBindSpnego() at src/connection_manager/secd_connection.cpp:864
[kern_secd:info:15263] | [000.013.741] ERR : ldapSaslBindSpnego: LDAP Error: (-1): 'Can't contact LDAP server':
[kern_secd:info:15263] | [000.014.185] ERR : RESULT_ERROR_LDAPSERVER_SERVER_DOWN:7642 in ldapSaslBind() at src/connection_manager/secd_connection.cpp:1098