Welcome to Port3101.org : Your BES Connection Mark forums read | View Forum Leaders
Port3101.org : Your BES Connection



Reply
LinkBack Thread Tools Display Modes
BAS and LDAP / AD Auth
 
  #1 (permalink)  
Old 07-10-2009, 06:56 AM
BES Activated
 
Join Date: Jul 2009
Posts: 6
Default BAS and LDAP / AD Auth

Hola everyone

I've done a fresh install of BES 5.0 and applied MR1. Everything works nicely except..you guessed it...AD authentication when logging in to the BAS. I just get this error:

"The username, password, or domain is not correct. Please correct the entry."

I've tried resolving this myself for the past couple of days by doing the following:

1) The workaround where the password is stored in the database in plain text (fixed in MR1, supposedly!)
2) Tried multiple accounts, each of which can successfully perform LDAP lookups according to the server when you press the Verify button.
3) Reinstalled BES 5.0 4 times, and recreated the database twice.

ALso, in the BAS AS logs, I have seen this (names and IPs obscured):

(07/09 14:42:59:463):{http-<BESServerName>%2F<BESServerIP>-443-3} [com.rim.bes.basplugin.activedirectory.LdapSearch] [INFO] [ADAU-1001] {u=SystemUser, t=2140} LOGIN ERROR: getActiveDirectoryRootDseInformation could not get rootDSE attributes for URL ldap://RootDomain:389 error=javax.naming.CommunicationException: RootDomain:389 [Root exception is java.net.ConnectException: Connection refused: connect]

I am concerned that the name of the ldap server isn't showing up there, only the root domain i.e. ldap://mycompany.com:389. Is that normal?

BAS authentication is fine.

My BES is running on Windows Server 2003 SP2 and fully patched.

What do I do from here? Any suggestions appreciated!

Cheers

Richard
Reply With Quote
Sponsored Links
  #2 (permalink)  
Old 07-10-2009, 11:20 AM
hdawg's Avatar
Proprietor
 
Join Date: Nov 2008
Posts: 2,036
Blog Entries: 116
Default

If a reboot doesn't fix it; try manually adding a hosts entry into the BES for company.com of a functioning / close domain controller to the BES.

After adding it do an ipconfig /flushdns and then relaunch the console and try to logon ... I don't think you need to reboot.

showing only mycompany.com:389 is normal ... in fact it is what you want; having it point to the domain will pick a DC on round-robin in the event that one is unresponsive the others will eventually pick up.
__________________
http://blog.port3101.org/hdawg/

The views expressed by me on Port3101 and its affiliated sites are my own and do not necessarily reflect the views of my employer.
Reply With Quote
  #3 (permalink)  
Old 07-10-2009, 04:21 PM
BES Activated
 
Join Date: Jul 2009
Posts: 6
Default

Thanks hdawg. I think I'd already done that by adding the following:

ldapserver.domain.com x.x.x.x
ldapserver x.x.x.x

Which is right, or neither?
Reply With Quote
  #4 (permalink)  
Old 07-10-2009, 11:23 PM
hdawg's Avatar
Proprietor
 
Join Date: Nov 2008
Posts: 2,036
Blog Entries: 116
Default

neither actually:

it should be the other way around; and be sure to include domain.com in the list.
__________________
http://blog.port3101.org/hdawg/

The views expressed by me on Port3101 and its affiliated sites are my own and do not necessarily reflect the views of my employer.
Reply With Quote
  #5 (permalink)  
Old 07-11-2009, 07:35 AM
BES Activated
 
Join Date: Jul 2009
Posts: 6
Default

Thanks hdawg. I had the format of the hosts file right, just couldn't remember it when I posted last night I'll be sure to add domain.com as well.
Reply With Quote
  #6 (permalink)  
Old 07-17-2009, 05:02 AM
BES Activated
 
Join Date: Jul 2009
Posts: 6
Default

Quick update, this is weird. It still wouldn't work after correcting the host file, so I had one of my AD guys come to take a look. We changed the LDAP path to a dfferent AD server and the port to 3268. Rebooted, and it worked! Wow, that felt good. After that I decided I wanted to install the collaboration components, so I went through setup again, verified the information and...ldad/domain auth to BAS stopped working.

Seriously buggy software imo.
Reply With Quote
  #7 (permalink)  
Old 07-17-2009, 11:26 AM
hdawg's Avatar
Proprietor
 
Join Date: Nov 2008
Posts: 2,036
Blog Entries: 116
Default

You're pointed at the Global catalog port ... I'm pretty sure if you ever have to call RIM they're going to ask you to change this.
__________________
http://blog.port3101.org/hdawg/

The views expressed by me on Port3101 and its affiliated sites are my own and do not necessarily reflect the views of my employer.
Reply With Quote
  #8 (permalink)  
Old 07-18-2009, 01:14 PM
Otto's Avatar
Proprietor
 
Join Date: Nov 2008
Location: Atlanta, GA
Posts: 1,778
Blog Entries: 13
Default

For what it's worth, their implementation into LDAP is either quite unstable or it adds a tad more complexity above and beyond what many of them are used to seeing. This doesn't even get into the resource hog the BAS services are. I can't say I'm impressed, but we work with what we have, I suppose.
__________________
BCSA (4.1, 5.0) | BCSD (4.1)

The views expressed by me on Port3101.org are my own and do not necessarily reflect the views of my employer.
Reply With Quote
  #9 (permalink)  
Old 08-07-2009, 01:21 PM
BES Activated
 
Join Date: Apr 2009
Posts: 4
Default

You didn't by any chance update JAVA did you? I had problems after I did that and had to reinstall my BAS and JAVA from scratch.
Reply With Quote
Reply

Bookmarks

Tags
bas ad ldap

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -4. The time now is 08:56 AM.
Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.3.2