I am having issues using LDAPS with Microsoft Active Directory. My configuration works using LDAP, but when i switch to LDAPS I get the following error:
Test basic connection : Succeeded
Test retrieve user : Failedorg.springframework.ldap.PartialResultException:
nested exception is javax.naming.PartialResultException
[Root exception is javax.naming.CommunicationException: ForestDnsZones.ad.uc.edu:636
[Root exception is javax.net.ssl.SSLHandshakeException: java.security.cert.CertificateException:
No subject alternative DNS name matching ForestDnsZones.ad.uc.edu found.]]
This is with the "Follow Referrals" option enabled. If I disable that option for LDAPS, the connection times out. LDAP connections work with "Follow Referrals" disabled.
The AD is set up in a forest with ad.uc.edu as the forest root. I am accessing one of the 6 domain controllers directly at ucdceiw2.ad.uc.edu, and the connection works with "Follow Referrals" disabled on LDAP connections
My read timeout is 120 seconds
My search timeout is 120 seconds
My connection timeout is 30 seconds
My IT department will be shutting off LDAP access soon and forcing LDAPS so it is important to resolve this soon.