Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Issue: LDAP error 32 LDAP_NO_SUCH_OBJECT #1108

Open
2 tasks done
cjohnston1158 opened this issue Sep 26, 2024 · 3 comments
Open
2 tasks done

Issue: LDAP error 32 LDAP_NO_SUCH_OBJECT #1108

cjohnston1158 opened this issue Sep 26, 2024 · 3 comments
Labels
bug Something isn't working jira Import to Jira

Comments

@cjohnston1158
Copy link
Contributor

Is there an existing issue for this?

  • I have searched the existing issues and found none that matched mine

Describe the issue

After configuring certificate auto-enrollment on Ubuntu 22.04 per the docs I am seeing LDAP error 32 LDAP_NO_SUCH_OBJECT. When trying to register with a Windows client, the Windows client was also not receiving the certificates.

There is another OU which was known to be working with a Windows client, so the GPO was compared. The new OU did not have the "Automatic Certificate Request Settings" configured, where the working OU did have this configured. The policy on the new OU was updated to match the working OU. Afterwards the Windows client was able to successfully download the certificates, however the Ubuntu client still is not.

Error message

Steps to reproduce it

https://documentation.ubuntu.com/adsys/en/stable/tutorial/certificates-autoenrolment/

Ubuntu users: System information

No response

Non Ubuntu users: System information

No response

Additional information

No response

Double check your logs

  • I have redacted any sensitive information from the logs
@cjohnston1158 cjohnston1158 added the bug Something isn't working label Sep 26, 2024
@didrocks
Copy link
Member

didrocks commented Sep 26, 2024

FTR: requested information about Windows AD server and OS level. Also, can you run ubuntu-bug adsys and report the content there (see the bug template), so that we get all linux OS info, including its dependencies?

Some of the idea could be a stuck GPT.ini and no refresh for it.
Can you try to check for the cached policy on the windows client? You will have them under /var/cache/adsys. Please look at the GPOs directories, try to find the matching GPO with the object ID and check GPT.ini file content. The version (if the policy was correctly updated) should match the one on the AD server.

Thanks!

@cjohnston1158
Copy link
Contributor Author

DCs are running Windows Server 2019 or 2022.
2016 AD domain/forest Functional level.

@cjohnston1158
Copy link
Contributor Author

report.txt
policies

@denisonbarbosa denisonbarbosa added the jira Import to Jira label Oct 2, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working jira Import to Jira
Projects
None yet
Development

No branches or pull requests

3 participants