Sign In with your
Trend Micro Account
Need Help?
Need More Help?

Create a technical support case if you need further support.

Unable to connect to two Microsoft 2008 Active Directory LDAP servers

    • Updated:
    • 21 Sep 2016
    • Product/Version:
    • InterScan Messaging Security Virtual Appliance 8.2
    • Platform:
    • N/A N/A
Summary
You cannot enable two Microsoft 2008 Active Directory servers using the Kerberos authentication method on InterScan Messaging Security Virtual Appliance (IMSVA).
Details
Public
This occurs because the Service Principal Name (SPN) of the second LDAP server cannot be retrieved.
To resolve this issue, apply Hot Fix Build 1438:
  1. Obtain a copy of this hot fix from Trend Micro Technical Support or from your Technical Account Manager (TAM).
  2. Install the hot fix.
  3. Log in to shell of IMSVA will root privileges.
  4. Open and edit the /opt/trend/imss/config/imss.ini file by adding the following parameters within the LDAP-SPN section:
    [LDAP-SPN]
    ldap1.example.com=ldap1@EXAMPLE.COM
    ldap2.example.com=ldap2@EXAMPLE.COM
    Notes:
    • "ldap1.example.com" and "ldap2.example.com" are hostnames or IP addresses of the LDAP servers and must be the same as the ones configured in the IMSVA web admin console within the LDAP section from Administration > IMSVA Configuration > Connections.
    • "ldap1@EXAMPLE.COM" and "ldap2@EXAMPLE.COM" are SPNs. By default, the format of an SPN is "hostname@DOMAIN_NAME_IN_UPPERCASE".
  5. Save the changes and close the file.
  6. Restart the IMSVA web admin console service by executing the following command from the IMSVA shell:
    # /opt/trend/imss/script/S99ADMINUI start
Premium
Internal
Rating:
Category:
Configure; Troubleshoot; Install
Solution Id:
1059782
Feedback
Did this article help you?

Thank you for your feedback!

To help us improve the quality of this article, please leave your email here so we can clarify further your feedback, if neccessary:
We will not send you spam or share your email address.

*This form is automated system. General questions, technical, sales, and product-related issues submitted through this form will not be answered.

If you need additional help, you may try to contact the support team. Contact Support


To help us improve the quality of this article, please leave your email here so we can clarify further your feedback, if neccessary:
We will not send you spam or share your email address.

*This form is automated system. General questions, technical, sales, and product-related issues submitted through this form will not be answered.


Need More Help?

Create a technical support case if you need further support.