<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ArcGIS LDAP Configuration Errors in ArcGIS Online Questions</title>
    <link>https://community.esri.com/t5/arcgis-online-questions/arcgis-ldap-configuration-errors/m-p/707207#M35059</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, I have similar problem.&lt;/P&gt;&lt;P&gt;I &lt;STRONG&gt;can not get the listing of all LDAP&lt;/STRONG&gt; users.&lt;/P&gt;&lt;P&gt;Maybe you can help me to analyze it. Please,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is my config :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;BLOCKQUOTE class="jive_macro_quote jive-quote jive_text_macro"&gt;&lt;P&gt;{&lt;BR /&gt; "type": "LDAP",&lt;BR /&gt; "properties": {&lt;BR /&gt; "userPassword": "v24qDsZ1bH2U1cUst7n0Ng==",&lt;BR /&gt; "sAMAccountName": "CN=My Name,OU=User Accounts,OU=X,OU=Y,DC=Z,DC=com",&lt;BR /&gt; "userEmailAttribute": "mail",&lt;BR /&gt; "usernameAttribute": "cn",&lt;BR /&gt; "ldapURLForUsers": "ldap://ldap-server.com/&lt;SPAN style="background-color: #f6f6f6;"&gt;OU=User Accounts,OU=&lt;/SPAN&gt;&lt;SPAN style="background-color: #f6f6f6;"&gt;X&lt;/SPAN&gt;&lt;SPAN style="background-color: #f6f6f6;"&gt;,OU=&lt;/SPAN&gt;&lt;SPAN style="background-color: #f6f6f6;"&gt;Y&lt;/SPAN&gt;&lt;SPAN style="background-color: #f6f6f6;"&gt;,DC=&lt;/SPAN&gt;&lt;SPAN style="background-color: #f6f6f6;"&gt;Z&lt;/SPAN&gt;&lt;SPAN style="background-color: #f6f6f6;"&gt;,DC=com&lt;/SPAN&gt;",&lt;BR /&gt; "isPasswordEncrypted": "true"&lt;BR /&gt; }&lt;BR /&gt;}&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;I also tried a second config and doesn work :&lt;/P&gt;&lt;BLOCKQUOTE class="jive_macro_quote jive-quote jive_text_macro"&gt;&lt;P&gt;&lt;SPAN style="font-size: 9.0pt; color: #4c4c4c;"&gt;{&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 9.0pt; color: #4c4c4c;"&gt;&amp;nbsp; "type": "LDAP",&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 9.0pt; color: #4c4c4c;"&gt;&amp;nbsp; "properties": {&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 9.0pt; color: #4c4c4c;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; "userPassword": "v24qDsZ1bH2U1cUst7n0Ng==",&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 9.0pt; color: #4c4c4c;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; "sAMAccountName": "uid=My Name,ou=XX,&lt;STRONG&gt;ou&lt;/STRONG&gt;=User Accounts,&lt;STRONG&gt;ou&lt;/STRONG&gt;=X,&lt;STRONG&gt;ou&lt;/STRONG&gt;=Y&lt;SPAN style="background-color: #f6f6f6;"&gt;,dc=&lt;/SPAN&gt;&lt;SPAN style="background-color: #f6f6f6;"&gt;Z&lt;/SPAN&gt;&lt;SPAN style="background-color: #f6f6f6;"&gt;,dc=com&lt;/SPAN&gt;",&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 9.0pt; color: #4c4c4c;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; "caseSensitive": "false",&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 9.0pt; color: #4c4c4c;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; "userEmailAttribute": "mail",&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 9.0pt; color: #4c4c4c;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; "usernameAttribute": "uid",&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 9.0pt; color: #4c4c4c;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; "userFullnameAttribute": "cn",&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 9.0pt; color: #4c4c4c;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; "ldapURLForUsers": "ldap://&lt;SPAN style="color: #3d3d3d; background-color: #f6f6f6;"&gt;ldap-server.com&lt;/SPAN&gt;/ou=xx,ou=User Accounts,ou=X,ou=Y,dc=Z,dc=com",&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 9.0pt; color: #4c4c4c;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; "isPasswordEncrypted": "true",&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 9.0pt; color: #4c4c4c;"&gt;&amp;nbsp; }&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 9.0pt; color: #4c4c4c;"&gt;}&lt;/SPAN&gt;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;The errors&amp;nbsp;ARE the same when I do "Get Enterprise User" (Home-&amp;gt;Security-.user-&amp;gt;&lt;SPAN&gt;Get&amp;nbsp;Enterprise User )&lt;/SPAN&gt;:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Portal Administrator Directory&lt;/P&gt;&lt;DIV class=""&gt;&lt;H3&gt;[LDAP: error code 1 - 000004DC: LdapErr: DSID-0C0907C2, comment: In order to perform this operation a successful bind must be completed on the connection., data 0, v2580]&lt;/H3&gt;&lt;P&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;P&gt;Here is the structure of my user in LDAP:&lt;/P&gt;&lt;P&gt;~ CN=My Name,OU=XX,&lt;STRONG&gt;OU&lt;/STRONG&gt;=User Accounts,&lt;STRONG&gt;OU&lt;/STRONG&gt;=X,&lt;STRONG&gt;OU&lt;/STRONG&gt;=Y,DC=Z,DC=com&lt;/P&gt;&lt;P&gt;~ there is no "UID" attribute in my LDAP.&amp;nbsp;&lt;BR /&gt;~ I am not using PKI&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I need assistance please. If anyone knows any way out of setting it correctly, please inform me.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 02 Sep 2019 07:52:44 GMT</pubDate>
    <dc:creator>yockee</dc:creator>
    <dc:date>2019-09-02T07:52:44Z</dc:date>
    <item>
      <title>ArcGIS LDAP Configuration Errors</title>
      <link>https://community.esri.com/t5/arcgis-online-questions/arcgis-ldap-configuration-errors/m-p/707206#M35058</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So, I needed to switch from Windows authentication to LDAP authentication, and our company has set up its own certificate authority trusted root certificates, and I've found the LDAP setup documentation doesn't cover this very well, so I'm posting my findings here for everyone else.&lt;/P&gt;&lt;P&gt;The docs are here:&lt;/P&gt;&lt;P&gt;&lt;A href="https://enterprise.arcgis.com/en/server/latest/administer/linux/configuring-a-highly-available-ldap-with-arcgis-server.htm"&gt;https://enterprise.arcgis.com/en/server/latest/administer/linux/configuring-a-highly-available-ldap-with-arcgis-server.htm&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, I had to actually go through with support and try a lot of variations to the parameters to get this right.&amp;nbsp; The error it was giving at first was "simple bind failed: &amp;lt;servername&amp;gt;:636", when I provided a secure LDAPS://servername:636/ou=..... link.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This was because I needed to import the trusted root certificate authority, which I tried to do in the ArcGIS/admin page, under machines/machinename/sslcertificates, but the error persisted.&amp;nbsp; So... it turns out the jvm's have their own keystore, and here are all of the other steps you may need to follow to get your secure ldap working with ArcGIS server, in excruciatingly overdetailed glory.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also one other note: if you get an error more like this, your password or userid is wrong:&lt;/P&gt;&lt;P&gt;LDAP: error code 49 - 80090308: LdapErr: DSID-0C09042F, comment: AcceptSecurityContext error, data 775, v2580&lt;/P&gt;&lt;P&gt;If you get an error like this, your OU values are probably wrong, skip to step 3A to see how to find what they should be:&lt;/P&gt;&lt;P&gt;[LDAP: error code 49 - 80090308: LdapErr: DSID-0C09042A, comment: AcceptSecurityContext error, data 52e, v3839]&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0in 0in 0pt;"&gt;1: Import the certificates into the background jvm keystore as follows (rather than importing through the url:6443/arcgis/admin web page):&lt;/P&gt;&lt;UL style="margin-top: 0in;"&gt;&lt;LI style="margin: 0in 0in 10pt 0.25in;"&gt;browse to &amp;lt;installroot&amp;gt;\arcgis\server\framework\runtime\jre\lib\security&lt;/LI&gt;&lt;LI style="margin: 0in 0in 10pt 0.25in;"&gt;copy the cacerts file to cacerts.bak (just in case).&lt;/LI&gt;&lt;LI style="margin: 0in 0in 10pt 0.25in;"&gt;Also back up your arcgissserver\config-store folder.&lt;/LI&gt;&lt;LI style="margin: 0in 0in 10pt 0.25in;"&gt;From a command prompt, run the following commands adjusted for your install location, and location you placed the .cer file(s) for each of your new trusted root authority certificates:&lt;UL style="margin-top: 0in;"&gt;&lt;LI style="margin: 0in 0in 0pt 0.25in;"&gt;&amp;lt;installroot&amp;gt;&lt;SPAN style="font-size: 12pt;"&gt;\ArcGIS\Server\framework\runtime\jre\bin\keytool -import -keystore &lt;/SPAN&gt;&amp;lt;installroot&amp;gt;\ar&lt;SPAN style="font-size: 12pt;"&gt;cgis\server\framework\runtime\jre\lib\security\cacerts -trustcacerts -alias "certificatename" -file "&amp;lt;trusted root certs folder&amp;gt;\certificatename.cer"&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI style="margin: 0in 0in 10pt 0.25in;"&gt;Note the default arcgis jre keystore pass is “changeit”&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P style="margin: 0in 0in 0pt;"&gt;2: Restart ArcGIS Server Windows service.&lt;/P&gt;&lt;P style="margin: 0in 0in 0pt;"&gt;3: go to https://&amp;lt;machinename&amp;gt;:6443/arcgis/admin and log in as the local arcgis admin account, then browse to Home =&amp;gt; security =&amp;gt; config =&amp;gt; testIdentityStore, and test the following LDAP configs for “Connection Successful!” message, after adjusting for your password and your mechid, and all of the OU / DC values to match those of your own company. If you don’t know them, see step 3A below to find out how to get them.&lt;/P&gt;&lt;P style="margin: 0in 0in 0pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; User Store Configuration:&lt;/P&gt;&lt;P style="margin: 0in 0in 0pt 0.5in;"&gt;{&lt;/P&gt;&lt;P style="margin: 0in 0in 0pt 0.5in;"&gt;"type": "LDAP",&lt;/P&gt;&lt;P style="margin: 0in 0in 0pt 0.5in;"&gt;"properties": {&lt;/P&gt;&lt;P style="margin: 0in 0in 0pt 0.5in;"&gt;&amp;nbsp;&amp;nbsp; "isPasswordEncrypted": "false",&lt;/P&gt;&lt;P style="margin: 0in 0in 0pt 0.5in;"&gt;&amp;nbsp;&amp;nbsp; "adminUserPassword": "&amp;lt;password&amp;gt;",&lt;/P&gt;&lt;P style="margin: 0in 0in 0pt 0.5in;"&gt;&amp;nbsp;&amp;nbsp; "adminUser": "CN=&amp;lt;your userid&amp;gt;,OU=userids,OU=esriusers,DC=redmond,DC=esri,DC=com",&lt;/P&gt;&lt;P style="margin: 0in 0in 0pt 0.5in;"&gt;&amp;nbsp;&amp;nbsp; "ldapURLForUsers": "ldaps://ldapserver.it.esri.com:636/OU=userids,OU=esriusers,DC=redmond,DC=esri,DC=com",&lt;/P&gt;&lt;P style="margin: 0in 0in 0pt 0.5in;"&gt;&amp;nbsp;&amp;nbsp; "usernameAttribute": "cn",&lt;/P&gt;&lt;P style="margin: 0in 0in 0pt 0.5in;"&gt;&amp;nbsp;&amp;nbsp; "caseSensitive": "false",&lt;/P&gt;&lt;P style="margin: 0in 0in 0pt 0.5in;"&gt;&amp;nbsp;&amp;nbsp; "userSearchAttribute": "samaccountname"&lt;/P&gt;&lt;P style="margin: 0in 0in 0pt 0.5in;"&gt;}&lt;/P&gt;&lt;P style="margin: 0in 0in 0pt 0.5in;"&gt;}&lt;/P&gt;&lt;P style="margin: 0in 0in 0pt 0.5in;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="margin: 0in 0in 0pt 0.5in;"&gt;Role Store Configuration:&lt;/P&gt;&lt;P style="margin: 0in 0in 0pt 0.5in;"&gt;{&lt;/P&gt;&lt;P style="margin: 0in 0in 0pt 0.5in;"&gt;"type": "LDAP",&lt;/P&gt;&lt;P style="margin: 0in 0in 0pt 0.5in;"&gt;"properties": {&lt;/P&gt;&lt;P style="margin: 0in 0in 0pt 0.5in;"&gt;&amp;nbsp;&amp;nbsp; "ldapURLForRoles": "ldaps://ldapserver.it.esri.com:636/ou=roles,dc=redmond,dc=esri,dc=com",&lt;/P&gt;&lt;P style="margin: 0in 0in 0pt 0.5in;"&gt;&amp;nbsp;&amp;nbsp; "isPasswordEncrypted": "false",&lt;/P&gt;&lt;P style="margin: 0in 0in 0pt 0.5in;"&gt;&amp;nbsp;&amp;nbsp; "adminUserPassword": "&amp;lt;password&amp;gt;",&lt;/P&gt;&lt;P style="margin: 0in 0in 0pt 0.5in;"&gt;&amp;nbsp;&amp;nbsp; "memberAttributeInRoles": "uniquemember",&lt;/P&gt;&lt;P style="margin: 0in 0in 0pt 0.5in;"&gt;&amp;nbsp;&amp;nbsp; "adminUser": "CN=&amp;lt;your userid&amp;gt;,OU=userids,OU=esriusers,DC=redmond,DC=esri,DC=com",&lt;/P&gt;&lt;P style="margin: 0in 0in 0pt 0.5in;"&gt;&amp;nbsp;&amp;nbsp; "ldapURLForUsers": "ldaps://ldapserver.it.esri.com:636/OU=userids,OU=esriusers,DC=redmond,DC=esri,DC=com",&lt;/P&gt;&lt;P style="margin: 0in 0in 0pt 0.5in;"&gt;&amp;nbsp;&amp;nbsp; "rolenameAttribute": "cn",&lt;/P&gt;&lt;P style="margin: 0in 0in 0pt 0.5in;"&gt;&amp;nbsp;&amp;nbsp; "usernameAttribute": "cn"&lt;/P&gt;&lt;P style="margin: 0in 0in 0pt 0.5in;"&gt;}&lt;/P&gt;&lt;P style="margin: 0in 0in 0pt 0.5in;"&gt;}&lt;/P&gt;&lt;P style="margin: 0in 0in 0pt;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="margin: 0in 0in 0pt;"&gt;3A: If you do not know your baseDN and OU values… Install the Windows RSAT application tools package with DSQUERY command from Microsoft, then go to control panel =&amp;gt; programs (and features) =&amp;gt; add windows feature, “Remote Server Administration Tools” and enable the Role Administration Tools and all subitems there. Note that in my examples, I totally made up “userid”, “esriusers”, and “redmond” as values, as these will always vary by your own company’s domain setup. Make sure you run the DSQuery tool to get the right values YOU should be using.&lt;/P&gt;&lt;P style="margin: 0in 0in 0pt;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="margin: 0in 0in 0pt;"&gt;Go to command prompt and run this command, with the quotes: dsquery user -name “&amp;lt;username&amp;gt;”&lt;/P&gt;&lt;P style="margin: 0in 0in 0pt;"&gt;Result will look like: “CN=&amp;lt;username&amp;gt;,OU=someparam,OU=maybe-a-secondparam,DC=domain1,DC=domain2,DC=domain3-typically-just-com”&lt;/P&gt;&lt;P style="margin: 0in 0in 0pt;"&gt;So something like: “CN=abc1234,OU=userids,OU=esriusers,DC=redmond,DC=esri,DC=com” would go into your JSON config value like this:&lt;/P&gt;&lt;P style="margin: 0in 0in 0pt 0.5in;"&gt;&amp;nbsp;&amp;nbsp; "adminUser": "CN=abc1234,OU=userids,OU= esriusers,DC=redmond,DC=esri,DC=com”,&lt;/P&gt;&lt;P style="margin: 0in 0in 0pt;"&gt;Take the resulting value and use it in the adminUser attribute in the json code in step 3. Paste the portion after the CN=&amp;lt;username&amp;gt;, starting with the first OU=, and paste that into the ldapURL parameter. Following the example above, this would go in your JSON config value:&lt;/P&gt;&lt;P style="margin: 0in 0in 0pt; text-indent: 0.5in;"&gt;&amp;nbsp;&amp;nbsp; "ldapURLForUsers": "ldaps://ldapserver.it.esri.com:636/OU=userids,OU=esriusers,DC=redmond,DC=esri,DC=com”,&lt;/P&gt;&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;/P&gt;&lt;P style="margin: 0in 0in 0pt;"&gt;These values may not be needed based on your company’s LDAP settings, so try without them first... samaccountname is the standard value for windows active-directory setups.&lt;/P&gt;&lt;P style="margin: 0in 0in 0pt 0.5in;"&gt;&amp;nbsp;&amp;nbsp; "caseSensitive": "false",&lt;/P&gt;&lt;P style="margin: 0in 0in 0pt 0.5in;"&gt;&amp;nbsp;&amp;nbsp; "userSearchAttribute": "samaccountname"&lt;/P&gt;&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;/P&gt;&lt;P style="margin: 0in 0in 0pt;"&gt;The ldapURLForRoles OU value of “roles” may indicate success in the test page, but it works with anything and is not apparently truly tested, so also use the command “dsquery ou” to see a list of all OUs in your company and find the one that looks like ou=groups or ou=roles.&lt;/P&gt;&lt;P style="margin: 0in 0in 0pt;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="margin: 0in 0in 0pt;"&gt;4: If those functioned, you can browse back to the “config” level in the arcgis/admin page, and use the updateIdentityStore link to change the identity store config to use the adjusted configs you just tested.&lt;/P&gt;&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;/P&gt;&lt;P style="margin: 0in 0in 0pt;"&gt;Hope that helps someone!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Aug 2019 19:17:11 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-online-questions/arcgis-ldap-configuration-errors/m-p/707206#M35058</guid>
      <dc:creator>JoshuaDalton</dc:creator>
      <dc:date>2019-08-07T19:17:11Z</dc:date>
    </item>
    <item>
      <title>Re: ArcGIS LDAP Configuration Errors</title>
      <link>https://community.esri.com/t5/arcgis-online-questions/arcgis-ldap-configuration-errors/m-p/707207#M35059</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, I have similar problem.&lt;/P&gt;&lt;P&gt;I &lt;STRONG&gt;can not get the listing of all LDAP&lt;/STRONG&gt; users.&lt;/P&gt;&lt;P&gt;Maybe you can help me to analyze it. Please,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is my config :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;BLOCKQUOTE class="jive_macro_quote jive-quote jive_text_macro"&gt;&lt;P&gt;{&lt;BR /&gt; "type": "LDAP",&lt;BR /&gt; "properties": {&lt;BR /&gt; "userPassword": "v24qDsZ1bH2U1cUst7n0Ng==",&lt;BR /&gt; "sAMAccountName": "CN=My Name,OU=User Accounts,OU=X,OU=Y,DC=Z,DC=com",&lt;BR /&gt; "userEmailAttribute": "mail",&lt;BR /&gt; "usernameAttribute": "cn",&lt;BR /&gt; "ldapURLForUsers": "ldap://ldap-server.com/&lt;SPAN style="background-color: #f6f6f6;"&gt;OU=User Accounts,OU=&lt;/SPAN&gt;&lt;SPAN style="background-color: #f6f6f6;"&gt;X&lt;/SPAN&gt;&lt;SPAN style="background-color: #f6f6f6;"&gt;,OU=&lt;/SPAN&gt;&lt;SPAN style="background-color: #f6f6f6;"&gt;Y&lt;/SPAN&gt;&lt;SPAN style="background-color: #f6f6f6;"&gt;,DC=&lt;/SPAN&gt;&lt;SPAN style="background-color: #f6f6f6;"&gt;Z&lt;/SPAN&gt;&lt;SPAN style="background-color: #f6f6f6;"&gt;,DC=com&lt;/SPAN&gt;",&lt;BR /&gt; "isPasswordEncrypted": "true"&lt;BR /&gt; }&lt;BR /&gt;}&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;I also tried a second config and doesn work :&lt;/P&gt;&lt;BLOCKQUOTE class="jive_macro_quote jive-quote jive_text_macro"&gt;&lt;P&gt;&lt;SPAN style="font-size: 9.0pt; color: #4c4c4c;"&gt;{&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 9.0pt; color: #4c4c4c;"&gt;&amp;nbsp; "type": "LDAP",&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 9.0pt; color: #4c4c4c;"&gt;&amp;nbsp; "properties": {&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 9.0pt; color: #4c4c4c;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; "userPassword": "v24qDsZ1bH2U1cUst7n0Ng==",&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 9.0pt; color: #4c4c4c;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; "sAMAccountName": "uid=My Name,ou=XX,&lt;STRONG&gt;ou&lt;/STRONG&gt;=User Accounts,&lt;STRONG&gt;ou&lt;/STRONG&gt;=X,&lt;STRONG&gt;ou&lt;/STRONG&gt;=Y&lt;SPAN style="background-color: #f6f6f6;"&gt;,dc=&lt;/SPAN&gt;&lt;SPAN style="background-color: #f6f6f6;"&gt;Z&lt;/SPAN&gt;&lt;SPAN style="background-color: #f6f6f6;"&gt;,dc=com&lt;/SPAN&gt;",&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 9.0pt; color: #4c4c4c;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; "caseSensitive": "false",&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 9.0pt; color: #4c4c4c;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; "userEmailAttribute": "mail",&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 9.0pt; color: #4c4c4c;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; "usernameAttribute": "uid",&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 9.0pt; color: #4c4c4c;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; "userFullnameAttribute": "cn",&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 9.0pt; color: #4c4c4c;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; "ldapURLForUsers": "ldap://&lt;SPAN style="color: #3d3d3d; background-color: #f6f6f6;"&gt;ldap-server.com&lt;/SPAN&gt;/ou=xx,ou=User Accounts,ou=X,ou=Y,dc=Z,dc=com",&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 9.0pt; color: #4c4c4c;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; "isPasswordEncrypted": "true",&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 9.0pt; color: #4c4c4c;"&gt;&amp;nbsp; }&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 9.0pt; color: #4c4c4c;"&gt;}&lt;/SPAN&gt;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;The errors&amp;nbsp;ARE the same when I do "Get Enterprise User" (Home-&amp;gt;Security-.user-&amp;gt;&lt;SPAN&gt;Get&amp;nbsp;Enterprise User )&lt;/SPAN&gt;:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Portal Administrator Directory&lt;/P&gt;&lt;DIV class=""&gt;&lt;H3&gt;[LDAP: error code 1 - 000004DC: LdapErr: DSID-0C0907C2, comment: In order to perform this operation a successful bind must be completed on the connection., data 0, v2580]&lt;/H3&gt;&lt;P&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;P&gt;Here is the structure of my user in LDAP:&lt;/P&gt;&lt;P&gt;~ CN=My Name,OU=XX,&lt;STRONG&gt;OU&lt;/STRONG&gt;=User Accounts,&lt;STRONG&gt;OU&lt;/STRONG&gt;=X,&lt;STRONG&gt;OU&lt;/STRONG&gt;=Y,DC=Z,DC=com&lt;/P&gt;&lt;P&gt;~ there is no "UID" attribute in my LDAP.&amp;nbsp;&lt;BR /&gt;~ I am not using PKI&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I need assistance please. If anyone knows any way out of setting it correctly, please inform me.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 Sep 2019 07:52:44 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-online-questions/arcgis-ldap-configuration-errors/m-p/707207#M35059</guid>
      <dc:creator>yockee</dc:creator>
      <dc:date>2019-09-02T07:52:44Z</dc:date>
    </item>
    <item>
      <title>Re: ArcGIS LDAP Configuration Errors</title>
      <link>https://community.esri.com/t5/arcgis-online-questions/arcgis-ldap-configuration-errors/m-p/707208#M35060</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A href="https://community.esri.com/migrated-users/51067"&gt;Joshua Dalton&lt;/A&gt;‌, thanks for sharing.&amp;nbsp; My I suggest, since this is more information sharing than a question, that you convert this question to a discussion and change the title to reflect that fact.&amp;nbsp; For example, instead of "ArcGIS LDAP Configuration Errors" maybe "Steps (or tips) for Addressing ArcGIS LDAP Configuration Errors"&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 Sep 2019 14:26:46 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-online-questions/arcgis-ldap-configuration-errors/m-p/707208#M35060</guid>
      <dc:creator>JoshuaBixby</dc:creator>
      <dc:date>2019-09-02T14:26:46Z</dc:date>
    </item>
    <item>
      <title>Re: ArcGIS LDAP Configuration Errors</title>
      <link>https://community.esri.com/t5/arcgis-online-questions/arcgis-ldap-configuration-errors/m-p/707209#M35061</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;After nearly a week of agonizing pain and nearly commit suicide, i finally just made it working :&lt;/P&gt;&lt;P&gt;Here is the setup :&lt;/P&gt;&lt;BLOCKQUOTE class="jive_macro_quote jive-quote jive_text_macro"&gt;&lt;P style="margin-bottom: .0001pt;"&gt;&lt;SPAN style="font-size: 10.0pt;"&gt;{&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-bottom: .0001pt;"&gt;&lt;SPAN style="font-size: 10.0pt;"&gt;&amp;nbsp; "type": "LDAP",&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-bottom: .0001pt;"&gt;&lt;SPAN style="font-size: 10.0pt;"&gt;&amp;nbsp; "properties": {&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-bottom: .0001pt;"&gt;&lt;SPAN style="font-size: 10.0pt;"&gt;&amp;nbsp; &amp;nbsp;&amp;nbsp;"userPassword": "v24qDsZ1bH2U1cUst7n0Ng==",&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-bottom: .0001pt;"&gt;&lt;SPAN style="font-size: 10.0pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; "userEmailAttribute": "mail",&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-bottom: .0001pt;"&gt;&lt;SPAN style="font-size: 10.0pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; "usernameAttribute": "cn",&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-bottom: .0001pt;"&gt;&lt;SPAN style="font-size: 10.0pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; "&lt;STRONG&gt;user&lt;/STRONG&gt;": "&lt;STRONG&gt;sAMAccountName&lt;/STRONG&gt;=MY&amp;nbsp;Name,OU=XX,OU=User Accounts,OU=X,OU=Y,DC=Z,DC=com",&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-bottom: .0001pt;"&gt;&lt;SPAN style="font-size: 10.0pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; "ldapURLForUsers": "ldap://LDAP-address.com/OU=User Accounts,OU=X,OU=Y,DC=Z,DC=com",&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-bottom: .0001pt;"&gt;&lt;SPAN style="font-size: 10.0pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; "isPasswordEncrypted": "true"&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-bottom: .0001pt;"&gt;&lt;SPAN style="font-size: 10.0pt;"&gt;&amp;nbsp; }&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10.0pt;"&gt;}&lt;/SPAN&gt;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;SPAN style="font-size: 10.0pt;"&gt;In LDAP, I can trace my user name by following this path : "&lt;SPAN style="background-color: #ffffff;"&gt;CN=MY Name,OU=XX,&lt;/SPAN&gt;&lt;SPAN style="background-color: #ffffff; border: 0px; font-weight: bold; font-size: 15px;"&gt;&lt;STRONG&gt;OU&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN style="background-color: #ffffff;"&gt;=User Accounts,&lt;/SPAN&gt;&lt;SPAN style="background-color: #ffffff; border: 0px; font-weight: bold; font-size: 15px;"&gt;&lt;STRONG&gt;OU&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN style="background-color: #ffffff;"&gt;=X,&lt;/SPAN&gt;&lt;SPAN style="background-color: #ffffff; border: 0px; font-weight: bold; font-size: 15px;"&gt;&lt;STRONG&gt;OU&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN style="background-color: #ffffff;"&gt;=Y,DC=Z,DC=com". This is, probably 95% sure, is the path that you should type on to the "&lt;STRONG&gt;user&lt;/STRONG&gt;" parameter part. I remove some parameters as well, like : "&lt;SPAN style="font-size: 9.0pt; color: #4c4c4c;"&gt;caseSensitive" and "userSearchAttribute".&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #ffffff; color: #4c4c4c; font-size: 9.0pt;"&gt;The configuration above is quite different to the one that esri suggested in their Help :&lt;/SPAN&gt;&lt;/P&gt;&lt;BLOCKQUOTE class="jive_macro_quote jive-quote jive_text_macro"&gt;&lt;PRE style="background-color: #ffffff; font-size: 15.9375px; margin-bottom: 1.55rem;"&gt;{   "type": "LDAP",   "properties": {     "userPassword": "secret",     "isPasswordEncrypted": "false",     "user": "uid=admin,ou=system",     "userFullnameAttribute": "cn",     "ldapURLForUsers": "ldaps://myLdapServer:10636/ou=users,ou=ags,dc=example,dc=com",     "userEmailAttribute": "mail",     "usernameAttribute": "uid",     "caseSensitive": "false",     "userSearchAttribute": "uid"   } }&lt;/PRE&gt;&lt;/BLOCKQUOTE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Sep 2019 03:07:26 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-online-questions/arcgis-ldap-configuration-errors/m-p/707209#M35061</guid>
      <dc:creator>yockee</dc:creator>
      <dc:date>2019-09-03T03:07:26Z</dc:date>
    </item>
    <item>
      <title>Re: ArcGIS LDAP Configuration Errors</title>
      <link>https://community.esri.com/t5/arcgis-online-questions/arcgis-ldap-configuration-errors/m-p/707210#M35062</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Addendum... so, I had to do it for ArcGIS 10.3.1... and encountered issue after issue, and could not decipher the problem, until I tried a java app&amp;nbsp;called sslpoke which makes sure your root certificates are set up right and you can get to the target host given... and I learned that ArcGIS 10.3.1 runs on java 1.7.0_76, found in &amp;lt;install folder&amp;gt;\ArcGIS\server\framework\runtime\jre, which does not support TLSv1.1 or TLSv1.2.&amp;nbsp; It only supports TLSv1.&amp;nbsp; This is obsolete, and not allowed to connect to newer ldap versions, or other server types, so it causes a big problem if your it department decides to upgrade the LDAP servers to disallow TLSv1, which honestly, they should really do.&amp;nbsp; So, what's the fix?&amp;nbsp; You need to go find at LEAST java se 1.7.0_131, which is the first one to include TLS1.1 / 1.2 support, which requires an oracle support contract to download.&amp;nbsp; Trust me that this is the first one that works, I tested connecting to LDAP with every 1.7.0_X version out there that is lower than 1.7.0_131.&amp;nbsp; Anything higher than 1.7.0_131 should work also, I tested for TLS1.2 sslpoke success up to the current developer-only build 1.7.0_241 from the oracle patching support site, but I didn't try placing them into the ArcGIS folder yet, so&amp;nbsp;back up&amp;nbsp;your config_store.&amp;nbsp;Once you have that, you can save your cacerts file, or just reimport your root certs to it, then stop arcgis server, and replace the server's&amp;nbsp;jre folder under &amp;lt;install root&amp;gt;\ArcGIS\server\framework\runtime\jre folder with the 1.7.0_131 (or higher)&amp;nbsp;jre folder you obtained.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Make sure you add your root certificates back into the new jre\lib\security\cacerts file as detailed above in original post.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One thing I haven't checked, but might be a nice side effect, tls1.2 ArcGIS online connectivity.&amp;nbsp; Maybe someone can advise if this resolves that.&lt;/P&gt;&lt;P&gt;This may also work for ArcGIS Portal 10.3.1, but I haven't tried it yet.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Oct 2019 04:53:32 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-online-questions/arcgis-ldap-configuration-errors/m-p/707210#M35062</guid>
      <dc:creator>JoshuaDalton</dc:creator>
      <dc:date>2019-10-17T04:53:32Z</dc:date>
    </item>
  </channel>
</rss>

