VPLEX: After Password Change of Active Directory Bind User for LDAPS the reconfiguration fails
Summary: After Password Change of Active Directory Bind User for LDAPS on the active directory server the reconfiguration on VPlex clusters fails. AD user cannot authenticated on VPlex anymore.
Symptoms
Impacted Hardware:
Dell EMC Hardware: VPLEX VS2
Dell EMC Hardware: VPLEX-Local
Dell EMC Hardware: VPLEX-Metro
Impacted VPLEX GeoSynchrony software:
Dell EMC Software: GeoSynchrony 5.5.x
Dell EMC Software: GeoSynchrony 6.0.x
Dell EMC Software: GeoSynchrony 6.1.x
Dell EMC Software: GeoSynchrony 6.2.0.03
Dell EMC Software: GeoSynchrony 6.2.0.04
Symptoms:
-
VPLEX user authenticated by AD Server cannot login to VPLEX.
-
VPLEX LDAPS configuration removed and cannot reconfigured, because the "authentication directory-service configure"-command failed with " ldap_sasl_bind(SIMPLE): Can't contact LDAP server (-1) "
Cause
User keeps Active Directory Server up to date and current versions require TLS versions 1.1 or 1.2 (in this case Windows 2016 server). On VPLEX management server or MMCS is SLES 11.4 in use this include the OpenSSL version 0.9.8. This version does not support TLS version 1.1 and 1.2.
OpenSSL version 0.9.8 is end-of-support since 1st January 2016 and no longer receiving updates.
Minimum openSSL version supporting TLS 1.1 and 1.2 is version 1.0.1.
Resolution
The VPLEX Engineering development team team is working on a solution to fix the issue. Currently, VPLEX using SLES11 SP4, the plan is to upgrade to SLES15 and do the changes, the complexity involved in tweaking the code, hence a lot of testing is going on.