IBM Support

IBM Resilient users cannot login due to an expired Active Directory SSL certificate

Troubleshooting


Problem

Users cannot log in to IBM Resilient because IBM Resilient cannot connect to Active Directory as the SSL certificate that IBM Resilient is using to ensure a TLS connection with Active Directory is expired.

Symptom

Users cannot log to IBM Resilient via LDAP authentication. The client.log shows the following error:
07:53:11.117 [http-nio-443-exec-18] ERROR [ldap] com.co3.ldap.LdapConnectionSet - Failed to connect to xx:636: An error occurred while attempting to connect to server xx:636: IOException(LDAPException(resultCode=123 (authorization denied), errorMessage='authorization denied', ldapSDKVersion=4.0.9, revision=29290))......
Caused by: java.io.IOException: LDAPException(resultCode=123 (authorization denied), errorMessage='authorization denied', ldapSDKVersion=4.0.9, revision=29290)
at com.unboundid.ldap.sdk.LDAPConnectionInternals.<init>(LDAPConnectionInternals.java:178)
at com.unboundid.ldap.sdk.LDAPConnection.connect(LDAPConnection.java:860)
... 59 common frames omitted
Caused by: com.unboundid.ldap.sdk.LDAPException: authorization denied
at com.co3.ldap.LdapConnectionSet$2.verifySSLSocket(LdapConnectionSet.java:413)
at com.unboundid.ldap.sdk.LDAPConnectionInternals.<init>(LDAPConnectionInternals.java:166)
... 60 common frames omitted
Caused by: javax.net.ssl.SSLPeerUnverifiedException: peer not authenticated
at com.ibm.jsse2.ag.getPeerCertificates(ag.java:130)
at org.apache.http.conn.ssl.AbstractVerifier.verify(AbstractVerifier.java:113)
at com.co3.net.ResilientHostnameVerifier.verify(rgResilientHostnameVerifier.java:34)
at com.co3.ldap.LdapConnectionSet$2.verifySSLSocket(LdapConnectionSet.java:411)
... 61 common frames omitted

Document Location

Worldwide

[{"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSIP9Q","label":"IBM Security SOAR"},"ARM Category":[{"code":"a8m0z0000001gqlAAA","label":"Authentication-\u003ELDAP"}],"ARM Case Number":"","Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"All Version(s)","Line of Business":{"code":"LOB77","label":"Automation Platform"}},{"Type":"MASTER","Line of Business":{"code":"LOB77","label":"Automation Platform"},"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSEGM63","label":"IBM Security QRadar SOAR on Cloud"},"ARM Category":[{"code":"a8m0z0000001gqlAAA","label":"Authentication-\u003ELDAP"}],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"All Versions"}]

Log InLog in to view more of this document

This document has the abstract of a technical article that is available to authorized users once you have logged on. Please use Log in button above to access the full document. After log in, if you do not have the right authorization for this document, there will be instructions on what to do next.

Document Information

Modified date:
15 August 2022

UID

ibm16250815