pki-tomcat service failed to start up in IPA Replica with the error : "netscape.ldap.LDAPException: Authentication failed (48)"
Issue
-
ipactl restart command fails as pki-tomcat service is unable to start due to authentication errors.
- Debug log shows below error,
[06/Jun/2017:12:46:18][localhost-startStop-1]: SSLClientCertificateSelectionCB: Setting desired cert nickname to: subsystemCert cert-pki-ca
[06/Jun/2017:12:46:18][localhost-startStop-1]: LdapJssSSLSocket: set client auth cert nickname subsystemCert cert-pki-ca
[06/Jun/2017:12:46:18][localhost-startStop-1]: SSLClientCertificatSelectionCB: Entering!
[06/Jun/2017:12:46:18][localhost-startStop-1]: SSLClientCertificateSelectionCB: returning: null
[06/Jun/2017:12:46:18][localhost-startStop-1]: SSL handshake happened
Could not connect to LDAP server host server.exampale.com port 636 Error netscape.ldap.LDAPException: Authentication failed (48)
at com.netscape.cmscore.ldapconn.LdapBoundConnFactory.makeConnection(LdapBoundConnFactory.java:205)
Environment
- Red Hat Enterprise Linux Server release 7 (rhel 7)
- ipa-server-4.X
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.