<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: WARNING: Portal for ArcGIS cannot connect to Active Directory LDAP server at ldaps in ArcGIS Enterprise Portal Questions</title>
    <link>https://community.esri.com/t5/arcgis-enterprise-portal-questions/warning-portal-for-arcgis-cannot-connect-to-active/m-p/1029525#M10594</link>
    <description>&lt;P&gt;Have you tried connecting to the LDAPS port for global catalogs (3269) using another method such as ldp.exe?&lt;/P&gt;&lt;P&gt;Ldp | Microsoft Docs&lt;BR /&gt;&lt;A href="https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/cc771022(v=ws.11)" target="_blank" rel="noopener"&gt;https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/cc771022(v=ws.11)&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That may give you some more information about why the connection is failing. With a connection reset error, it is possible the connection is being blocked by or timing-out on a firewall (either internal or external to the domain controller in question). The Active Directory connection does use LDAP to query the AD structure for users/groups, and connections will be made on 3269, 3268, 636, and 389, depending on whether LDAPS is configured with a proper certificate and the binding options set within group policy.&lt;/P&gt;</description>
    <pubDate>Tue, 23 Feb 2021 13:37:54 GMT</pubDate>
    <dc:creator>ChristopherPawlyszyn</dc:creator>
    <dc:date>2021-02-23T13:37:54Z</dc:date>
    <item>
      <title>WARNING: Portal for ArcGIS cannot connect to Active Directory LDAP server at ldaps</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-portal-questions/warning-portal-for-arcgis-cannot-connect-to-active/m-p/1028057#M10582</link>
      <description>&lt;P&gt;&amp;nbsp;We use Active Directory authentication (not using LDAP). There are two errors in sequence; see below.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ZacharyHart_0-1613659834956.png" style="width: 749px;"&gt;&lt;img src="https://community.esri.com/t5/image/serverpage/image-id/6313i9B4BC5C041876352/image-dimensions/749x111?v=v2" width="749" height="111" role="button" title="ZacharyHart_0-1613659834956.png" alt="ZacharyHart_0-1613659834956.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;The &lt;A href="https://community.esri.com/t5/arcgis-enterprise-questions/portal-for-arcgis-cannot-connect-to-active-directory/m-p/208889#M8275" target="_self"&gt;only other post&lt;/A&gt; I've found related to this involves IWA.&lt;/LI&gt;&lt;LI&gt;I have been assured by our IT provider that all Domain Controllers are Global Catalog Servers.&lt;/LI&gt;&lt;LI&gt;We don't have any authentication issues as a result of this, but it is a curious and troubling warning.&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Thu, 18 Feb 2021 14:54:56 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-portal-questions/warning-portal-for-arcgis-cannot-connect-to-active/m-p/1028057#M10582</guid>
      <dc:creator>ZacharyHart</dc:creator>
      <dc:date>2021-02-18T14:54:56Z</dc:date>
    </item>
    <item>
      <title>Re: WARNING: Portal for ArcGIS cannot connect to Active Directory LDAP server at ldaps</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-portal-questions/warning-portal-for-arcgis-cannot-connect-to-active/m-p/1029525#M10594</link>
      <description>&lt;P&gt;Have you tried connecting to the LDAPS port for global catalogs (3269) using another method such as ldp.exe?&lt;/P&gt;&lt;P&gt;Ldp | Microsoft Docs&lt;BR /&gt;&lt;A href="https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/cc771022(v=ws.11)" target="_blank" rel="noopener"&gt;https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/cc771022(v=ws.11)&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That may give you some more information about why the connection is failing. With a connection reset error, it is possible the connection is being blocked by or timing-out on a firewall (either internal or external to the domain controller in question). The Active Directory connection does use LDAP to query the AD structure for users/groups, and connections will be made on 3269, 3268, 636, and 389, depending on whether LDAPS is configured with a proper certificate and the binding options set within group policy.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Feb 2021 13:37:54 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-portal-questions/warning-portal-for-arcgis-cannot-connect-to-active/m-p/1029525#M10594</guid>
      <dc:creator>ChristopherPawlyszyn</dc:creator>
      <dc:date>2021-02-23T13:37:54Z</dc:date>
    </item>
    <item>
      <title>Re: WARNING: Portal for ArcGIS cannot connect to Active Directory LDAP server at ldaps</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-portal-questions/warning-portal-for-arcgis-cannot-connect-to-active/m-p/1328761#M14011</link>
      <description>&lt;P&gt;I am having this same error and the one new user to the organization (City) is unable to log into Portal. All other users have access as expected.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Did you ever find a resolution?&lt;/P&gt;&lt;P&gt;Jared&lt;/P&gt;</description>
      <pubDate>Thu, 14 Sep 2023 16:24:06 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-portal-questions/warning-portal-for-arcgis-cannot-connect-to-active/m-p/1328761#M14011</guid>
      <dc:creator>jschuckert</dc:creator>
      <dc:date>2023-09-14T16:24:06Z</dc:date>
    </item>
    <item>
      <title>Re: WARNING: Portal for ArcGIS cannot connect to Active Directory LDAP server at ldaps</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-portal-questions/warning-portal-for-arcgis-cannot-connect-to-active/m-p/1604155#M16435</link>
      <description>&lt;P&gt;We recently came across this in a customers environment. It was actually preventing an upgrade of ArcGIS Portal from 10.8.1 to 11.1 because the ArcGIS Portal post installation configuration steps attempt to test the connection to the configured user store. In this case the Portal had numerous error messages about Portal not being able to connect to Active Directory. The errors tell you exactly what the issue is. ESRI uses the ldaps protocol to communicate with Active Directory. In our case the clients environment was not configured properly to support the ldaps protocol communication with their domain controllers. To get the errors to disappear in Portal this needed to be fixed. They had to do the following...&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Build out an internal Certificate Authority for the internal domain so they could issue trusted certificates to machine on the network.&lt;/LI&gt;&lt;LI&gt;Issued a certificate to the two domain controllers. The issued SSL should match each DCs FQDN.&lt;/LI&gt;&lt;LI&gt;Installed certificate to the Local Computer Personal Certificates store (certlm.msc) on the respective domain controllers.&lt;/LI&gt;&lt;LI&gt;Restarted domain controllers.&lt;/LI&gt;&lt;LI&gt;Once the certificates were put in place the errors in Portals log disappeared.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Apr 2025 13:05:36 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-portal-questions/warning-portal-for-arcgis-cannot-connect-to-active/m-p/1604155#M16435</guid>
      <dc:creator>MattMoore</dc:creator>
      <dc:date>2025-04-09T13:05:36Z</dc:date>
    </item>
  </channel>
</rss>

