5017 - Directory Unavailable

727 views
Skip to first unread message

LTA IT

unread,
Aug 17, 2021, 6:15:07 AM8/17/21
to pwm-general
Hello,
could someone help me to resolve this error? 
I checked the pwm configuration and got a ldpa test profile. On annex the result
The main ldaps url is the smclatmi01.

On the screenshot the error I got when I use the "AD_sspr" user enabled only to password reset.

Thank you,
Alessandro
Error_5017_Directory_unavailable.JPG
LDAP_test.docx

Jason Rivard

unread,
Aug 17, 2021, 7:52:30 PM8/17/21
to pwm-general
The Java version your using has deprecated TLSv10, and your directory doesn't support anything newer.  It should.  Ideally update your direcory server.  Otherwise you can google for how to allow Java to use older TLS versions.

LTA IT

unread,
Aug 18, 2021, 3:38:31 AM8/18/21
to pwm-general
Hello Jason,
thanks.
How can do that on Debian server?update the directory server...

LTA IT

unread,
Aug 20, 2021, 3:15:05 AM8/20/21
to pwm-general
Hello Jason,
could you help with some advices? 

Thank so much

Jason Rivard

unread,
Aug 20, 2021, 10:40:54 AM8/20/21
to pwm-general
This issue is not PWM specific and has been covered here and many other places on the internet.  Try googling the error.

Marco Neves

unread,
Sep 9, 2021, 5:01:21 AM9/9/21
to pwm-general
Enable TLS1.2 on your Ldap Servers.

Soh Meng Kuan

unread,
Feb 20, 2024, 1:16:08 AMFeb 20
to pwm-general
hi all, 

i can confirm my AD server(win 2016 standard) is support tls1.2 by default, and the sslscan do confirm my confirm too.

But still it showing 

5015 ERROR_INTERNAL (unexpected error during ldap search (profile=default), error: 5015 ERROR_INTERNAL (ldap error during searchID=0, context=DC=irafflesia,DC=edu,DC=my, error=javax.naming.PartialResultException, cause:javax.naming.CommunicationException: irafflesia.edu.my:636, cause:javax.net.ssl.SSLHandshakeException: The server selected protocol version TLS10 is not accepted by client preferences [TLS13, TLS12]))

i dont want to waste a topic as this is the same issue as mine.

Jason Rivard

unread,
Feb 21, 2024, 3:19:28 AMFeb 21
to pwm-general
Did you check all of the LDAP servers in the domain.   
Reply all
Reply to author
Forward
0 new messages