Welcome to the LimeSurvey Community Forum

Ask the community, share ideas, and connect with other LimeSurvey users!

How to enable LDAPS

  • helpdeskortec
  • helpdeskortec's Avatar Topic Author
  • Offline
  • New Member
  • New Member
More
3 years 10 months ago #200563 by helpdeskortec
How to enable LDAPS was created by helpdeskortec
I have Version 2.72.3+171020 + LDAP enabled. (Windows Server 2012 + IIS + PHP 7.0)

Settings for plugin: AuthLDAP:
-FQDN of the ldap server: ldap://server.domain.com
-LDAP port 636
-LDAP Version 2
-Simple Bind authentication

When I use these settings for plugin: AuthLDAP:
-FQDN of the ldap server: ldaps://server.domain.com
-LDAP port 636
-LDAP Version 2
-Simple Bind authentication
I get the warning: Can't contact LDAP server
How do I enable ldaps on Limesurvey?
The Windows server runs IIS and the SSL certificate Limesurvey uses is bound to the website in IIS.
The topic has been locked.
  • DenisChenu
  • DenisChenu's Avatar
  • Away
  • LimeSurvey Community Team
  • LimeSurvey Community Team
More
3 years 10 months ago #200566 by DenisChenu
Replied by DenisChenu on topic How to enable LDAPS
Are you sure certificate is valid ?

Assistance on LimeSurvey forum and LimeSurvey core development are on my free time.
I'm not a LimeSurvey GmbH member, professional service on demand , plugin development .
I don't answer to private message.
The topic has been locked.
  • helpdeskortec
  • helpdeskortec's Avatar Topic Author
  • Offline
  • New Member
  • New Member
More
3 years 10 months ago #200569 by helpdeskortec
Replied by helpdeskortec on topic How to enable LDAPS
Hi DenisChenu,

First of all, thanks for taking the time to read my post and better yet, to answer my question. So to be sure we are on the same page here....I am running Limesurvey Windows Server 2012 and IIS. The SSL certificate is bound in IIS.

I am sure that is not what you mean! By certificate you must mean the certificate that is necessary for Limesurvey to connect with secure LDAP. The Root certificate has been installed on the Windows server. Windows uses its own key store.
How do I use the Root certificate in Limesurvey? Where do I keep the Root certificate for Limesurvey?

Thanks in advance.
The topic has been locked.
  • DenisChenu
  • DenisChenu's Avatar
  • Away
  • LimeSurvey Community Team
  • LimeSurvey Community Team
More
3 years 10 months ago #200573 by DenisChenu
Replied by DenisChenu on topic How to enable LDAPS
It's not relalted to LimeSurvey but with PHP

If PHP don't know the certificate : you can not connect

Maybe try : qadrio.wordpress.com/2012/03/14/ldap-ssl...amppwamp-on-windows/ or stackoverflow.com/a/8447706/2239406

Assistance on LimeSurvey forum and LimeSurvey core development are on my free time.
I'm not a LimeSurvey GmbH member, professional service on demand , plugin development .
I don't answer to private message.
The following user(s) said Thank You: helpdeskortec
The topic has been locked.
  • helpdeskortec
  • helpdeskortec's Avatar Topic Author
  • Offline
  • New Member
  • New Member
More
3 years 10 months ago #200575 by helpdeskortec
Replied by helpdeskortec on topic How to enable LDAPS
Hi DenisChenu,

You are worth your weight in gold. The link: qadrio.wordpress.com/2012/03/14/ldap-ssl...amppwamp-on-windows/ or stackoverflow.com/a/8447706/2239406 had all the correct information.

So the solution was to create C:\Openldap\sysconf\ldap.conf. The content of ldap.conf is "TLS_REQCERT never".
After creating the folders and the file and adding the content to the ldap.conf file I restarted IIS.... and voila...

DenisChenu, thanks for helping me out. You saved me from a major headache.
The topic has been locked.
  • DenisChenu
  • DenisChenu's Avatar
  • Away
  • LimeSurvey Community Team
  • LimeSurvey Community Team
More
3 years 10 months ago #200583 by DenisChenu
Replied by DenisChenu on topic How to enable LDAPS
I think www.php.net/manual/fr/function.ldap-set-option.php can be included in plugin to allow self certificate.

Assistance on LimeSurvey forum and LimeSurvey core development are on my free time.
I'm not a LimeSurvey GmbH member, professional service on demand , plugin development .
I don't answer to private message.
The topic has been locked.

Lime-years ahead

Online-surveys for every purse and purpose