Uploaded image for project: 'Jenkins'
  1. Jenkins
  2. JENKINS-16243

Active Directory SSL/TLS authentication does not work with Active Directory Plugin

    • Icon: Bug Bug
    • Resolution: Unresolved
    • Icon: Major Major
    • Windows (7/2008 R2) x64; Active Directory at 2003 Forest Level; Global Catalog

      When <host>:636 or <host>:3269 is specified, authentication fails with a 'socket closed' error. I've confirmed that these ports on the domain controller are working and available by setting up the LDAP plugin using them. I've attached the logs generated by the authentication attempt. A network capture indicates that a handshake is occurring.

          [JENKINS-16243] Active Directory SSL/TLS authentication does not work with Active Directory Plugin

          ray terrill added a comment -

          Is this still a problem? Running into the exact same issue - socket closed on both 636 and 3269, validated that I can connect outside of Jenkins.

          ray terrill added a comment - Is this still a problem? Running into the exact same issue - socket closed on both 636 and 3269, validated that I can connect outside of Jenkins.

          It's still a problem. The only option you have is to switch to the LDAP and use ldaps://<domain>:636 or use the StartTLS option.

          From the code it seems that the plugin is not even trying to connect via TLS, as there is no switch or implementation to do this. So a resolution for this issue would be to add a field "use ssl only" and then pass this option to the LDAP context class.

          Fabian Grutschus added a comment - It's still a problem. The only option you have is to switch to the LDAP and use ldaps://<domain>:636 or use the StartTLS option. From the code it seems that the plugin is not even trying to connect via TLS, as there is no switch or implementation to do this. So a resolution for this issue would be to add a field "use ssl only" and then pass this option to the LDAP context class.

            Unassigned Unassigned
            khoury Khoury Brazil
            Votes:
            6 Vote for this issue
            Watchers:
            8 Start watching this issue

              Created:
              Updated: