Unity: LDAPS Config in Unisphere Fails with 0x6000193 Error when LDAP Cert SAN lacks FQDN

Summary: After upgrading to Unity OE 5.5.x or later, configuring or verifying LDAPS for Unisphere Management may fail with error 0x6000193. This occurs even though the LDAP server certificate appears valid and LDAP queries succeed using ldapsearch. ...

This article applies to This article does not apply to This article is not tied to any specific product. Not all product versions are identified in this article.

Symptoms

Attempts to verify the LDAP configuration fail with:

Operation failed. Error code: 0x6000193

Could not connect to the LDAP server.
Please recheck your LDAP configuration under Directory Services.
(Error Code: 0x6000193)

Example:

uemcli /net/ldap -id <domain> verify

Returns:

Operation failed. Error code: 0x6000193
Could not connect to the LDAP server.

The LDAP configuration appears correct:

Protocol = ldaps
Port = 636
Server name = ldapserver.company.com

LDAP connectivity tests from the Unity service shell succeed:

spX:/EMC/CEM/log# LDAPTLS_CACERT=/EMC/backend/CEM/LDAPCer/serverCertificate.cer ldapsearch -x -v -H ldaps://peeps-dc.peeps.lab -D "CN=Administrator,CN=Users,DC=peeps,DC=lab" -b "DC=peeps,DC=lab" samaccountname=administrator cn -w Password123#

Cause

The BSAFE library which is responsible for the certificate validation was upgraded in version 5.5.0. This library is using the more strict validation rules in that version. This is the reason the certificate without Subject Alternate Name (SAN) fails on 5.5.1.

RFC 6125 recommends and prefers using the SAN extension. It provides the flexibility and modern browser support. Further, our Dell certificate service has the mandatory requirement of using SAN in the Certificate Signing Requests (CSR).

Resolution

Regenerate the LDAP server certificate so that the LDAP server FQDN is present in the SAN extension.

Example:

X509v3 Subject Alternative Name:
DNS:ldapserver.company.com

Verify that:

  • The LDAP server certificate contains a SAN extension.
  • The SAN contains the exact FQDN configured in Unity.
  • After replacing the LDAP server certificate:
    • Import the required CA certificates chain to Unity.
    • Reconfigure or verify LDAP for successful verification.

Affected Products

Dell EMC Unity
Article Properties
Article Number: 000473894
Article Type: Solution
Last Modified: 10 Jun 2026
Version:  1
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.