You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

新服务器LDAPS证书无法为第三方服务正常工作的排查求助

新服务器LDAPS证书无法为第三方服务正常工作的排查求助

大概5-6年前我在主域控上配置了LDAPS,当时是在同一台服务器上部署了Active Directory Certificate Services,防火墙转发了636端口,第三方服务(比如Barracuda Essentials)都能正常认证。

上周我退役了那台旧服务器,移除了所有角色,搭建了新的主域控和副域控(都是Server 2016)。这次我决定让副域控(FQDN是dc02.domain.com)作为ADCS服务器来处理LDAPS,外网连接地址还是ds.domain.com:636——这个地址之前用了好几年都没问题。

第一次配置的时候我是跟着教程来的(这次也完全照搬了同样的步骤),看起来一切正常:用ldp.exe测试能成功,也能看到LDAPS的证书。我更新了防火墙的端口转发指向新服务器,但第三方服务却报错:

Could not bind privileged user: Ldap Error Code=-1 - Can't contact LDAP server.

我测试了端口转发是通的,然后运行openssl s_client -connect dc02.domain.com:636命令排查,发现证书居然还在引用旧的CA!我清理了旧的CA根证书和个人证书,重新颁发了新证书,但再次运行openssl命令还是有错误,第三方服务依然连不上。命令输出里最显眼的问题是:

CONNECTED(000001BC)

depth=0 CN = DC02.domain.com
verify error:num=20:unable to get local issuer certificate
verify return:1
depth=0 CN = DC02.domain.com
verify error:num=21:unable to verify the first certificate
verify return:1
depth=0 CN = DC02.domain.com
verify return:1
---
Certificate chain
0 s:CN = DC02.domain.com
i:DC = com, DC = domain, CN = domain-DC01-CA
a:PKEY: rsaEncryption, 2048 (bit); sigalg: RSA-SHA256
v:NotBefore: Aug 14 23:52:24 2023 GMT; NotAfter: Aug 13 23:52:24 2024 GMT
---
Server certificate
-----BEGIN CERTIFICATE-----
xxxxxx
-----END CERTIFICATE-----
subject=
issuer=DC = com, DC = domain, CN = domain-DC01-CA  <--这是我的旧CA!-->
---
No client certificate CA names sent
Client Certificate Types: RSA sign, DSA sign, ECDSA sign
Requested Signature Algorithms: RSA+SHA256:RSA+SHA384:RSA+SHA1:ECDSA+SHA256:ECDSA+SHA384:ECDSA+SHA1:DSA+SHA1:RSA+SHA512:ECDSA+SHA512
Shared Requested Signature Algorithms: RSA+SHA256:RSA+SHA384:ECDSA+SHA256:ECDSA+SHA384:RSA+SHA512:ECDSA+SHA512
Peer signing digest: SHA256
Peer signature type: RSA
Server Temp Key: X25519, 253 bits
---
SSL handshake has read 2069 bytes and written 438 bytes
Verification error: unable to verify the first certificate

注意看,证书颁发者还是旧的CA,可旧CA服务器早就关机了啊!我已经在旧服务器上移除了ADCS和NPS角色,现在整个AD环境在新的两台域控上运行正常,复制也没问题。我发现DC02上还留着旧CA的根证书和旧证书,但不确定能不能删。我也试过用基于Kerberos模板创建的LDAP证书模板重新申请证书,还手动通过注册表把证书分配给LDAPS服务,不过后来又把注册表改回去了。

我完全不是CA或LDAP方面的专家,这问题快把我搞疯了。现在我已经把DC02上的CA角色移除了,打算重新安装,但不确定这是不是正确的方向。我到底漏掉了什么?有没有其他办法解决?


补充:ldp.exe测试输出(在CA服务器上运行)

-----------
0x51 = ldap_unbind(ld);

ld = ldap_sslinit("dc02.domain.com", 636, 1);

Error 81 = ldap_set_option(hLdap, LDAP_OPT_PROTOCOL_VERSION, 3);

Error 0 = ldap_connect(hLdap, NULL);

Error 0 = ldap_get_option(hLdap,LDAP_OPT_SSL,(void*)&lv);

Host supports SSL, SSL cipher strength = 256 bits

Established connection to dc02.domain.com.

Retrieving base DSA information...

Getting 1 entries:

Dn: (RootDSE)
configurationNamingContext: CN=Configuration,DC=domain,DC=com;
currentTime: 8/15/2023 5:01:50 PM Central Daylight Time;
defaultNamingContext: DC=domain,DC=com;
dnsHostName: DC02.domain.com;
domainControllerFunctionality: 7 = ( WIN2016 );
domainFunctionality: 7 = ( WIN2016 );
dsServiceName: CN=NTDS Settings,CN=DC02,CN=Servers,CN=Domain,CN=Sites,CN=Configuration,DC=domain,DC=com;
forestFunctionality: 7 = ( WIN2016 );
highestCommittedUSN: 86626;
isGlobalCatalogReady: TRUE;
isSynchronized: TRUE;
ldapServiceName: domain.com:dc02$@domain.COM;
namingContexts (5): DC=domain,DC=com; CN=Configuration,DC=domain,DC=com; CN=Schema,CN=Configuration,DC=domain,DC=com; DC=DomainDnsZones,DC=domain,DC=com; DC=ForestDnsZones,DC=domain,DC=com;
rootDomainNamingContext: DC=domain,DC=com;
schemaNamingContext: CN=Schema,CN=Configuration,DC=domain,DC=com;
serverName: CN=DC02,CN=Servers,CN=Domain,CN=Sites,CN=Configuration,DC=domain,DC=com;
subschemaSubentry: CN=Aggregate,CN=Schema,CN=Configuration,DC=domain,DC=com;
supportedCapabilities (6): 1.2.840.113556.1.4.800 = ( ACTIVE_DIRECTORY ); 1.2.840.113556.1.4.1670 = ( ACTIVE_DIRECTORY_V51 ); 1.2.840.113556.1.4.1791 = ( ACTIVE_DIRECTORY_LDAP_INTEG ); 1.2.840.113556.1.4.1935 = ( ACTIVE_DIRECTORY_V61 ); 1.2.840.113556.1.4.2080 = ( ACTIVE_DIRECTORY_V61_R2 ); 1.2.840.113556.1.4.2237 = ( ACTIVE_DIRECTORY_W8 );
supportedControl (38): 1.2.840.113556.1.4.319 = ( PAGED_RESULT ); 1.2.840.113556.1.4.801 = ( SD_FLAGS ); 1.2.840.113556.1.4.473 = ( SORT ); 1.2.840.113556.1.4.528 = ( NOTIFICATION ); 1.2.840.113556.1.4.417 = ( SHOW_DELETED ); 1.2.840.113556.1.4.619 = ( LAZY_COMMIT ); 1.2.840.113556.1.4.841 = ( DIRSYNC ); 1.2.840.113556.1.4.529 = ( EXTENDED_DN ); 1.2.840.113556.1.4.805 = ( TREE_DELETE ); 1.2.840.113556.1.4.521 = ( CROSSDOM_MOVE_TARGET ); 1.2.840.113556.1.4.970 = ( GET_STATS ); 1.2.840.113556.1.4.1338 = ( VERIFY_NAME ); 1.2.840.113556.1.4.474 = ( RESP_SORT ); 1.2.840.113556.1.4.1339 = ( DOMAIN_SCOPE ); 1.2.840.113556.1.4.1340 = ( SEARCH_OPTIONS ); 1.2.840.113556.1.4.1413 = ( PERMISSIVE_MODIFY ); 2.16.840.1.113730.3.4.9 = ( VLVREQUEST ); 2.16.840.1.113730.3.4.10 = ( VLVRESPONSE ); 1.2.840.113556.1.4.1504 = ( ASQ ); 1.2.840.113556.1.4.1852 = ( QUOTA_CONTROL ); 1.2.840.113556.1.4.802 = ( RANGE_OPTION ); 1.2.840.113556.1.4.1907 = ( SHUTDOWN_NOTIFY ); 1.2.840.113556.1.4.1948 = ( RANGE_RETRIEVAL_NOERR ); 1.2.840.113556.1.4.1974 = ( FORCE_UPDATE ); 1.2.840.113556.1.4.1341 = ( RODC_DCPROMO ); 1.2.840.113556.1.4.2026 = ( DN_INPUT ); 1.2.840.113556.1.4.2064 = ( SHOW_RECYCLED ); 1.2.840.113556.1.4.2065 = ( SHOW_DEACTIVATED_LINK ); 1.2.840.113556.1.4.2066 = ( POLICY_HINTS_DEPRECATED ); 1.2.840.113556.1.4.2090 = ( DIRSYNC_EX ); 1.2.840.113556.1.4.2205 = ( UPDATE_STATS ); 1.2.840.113556.1.4.2204 = ( TREE_DELETE_EX ); 1.2.840.113556.1.4.2206 = ( SEARCH_HINTS ); 1.2.840.113556.1.4.2211 = ( EXPECTED_ENTRY_COUNT ); 1.2.840.113556.1.4.2239 = ( POLICY_HINTS ); 1.2.840.113556.1.4.2255; 1.2.840.113556.1.4.2256; 1.2.840.113556.1.4.2309;
supportedLDAPPolicies (20): MaxPoolThreads; MaxPercentDirSyncRequests; MaxDatagramRecv; MaxReceiveBuffer; InitRecvTimeout; MaxConnections; MaxConnIdleTime; MaxPageSize; MaxBatchReturnMessages; MaxQueryDuration; MaxDirSyncDuration; MaxTempTableSize; MaxResultSetSize; MinResultSets; MaxResultSetsPerConn; MaxNotificationPerConn; MaxValRange; MaxValRangeTransitive; ThreadMemoryLimit; SystemMemoryLimitPercent;
supportedLDAPVersion (2): 3; 2;
supportedSASLMechanisms (4): GSSAPI; GSS-SPNEGO; EXTERNAL; DIGEST-MD5;

这是不是说明本地连接是成功的?


备注:内容来源于stack exchange,提问作者Kenny

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.21 15:58:18