<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Endpoint Security: Active Directory scanner LDAPS in Endpoint</title>
    <link>https://community.checkpoint.com/t5/Endpoint/Endpoint-Security-Active-Directory-scanner-LDAPS/m-p/75281#M2038</link>
    <description>&lt;P&gt;Hi all&lt;/P&gt;&lt;P&gt;I ran in problems while setting up Active Directory scanner with LDAPS enabled on a fresh installed R80.40 server.&lt;/P&gt;&lt;P&gt;The only error message i got is: unable to establish a connection to the domain controller&lt;/P&gt;&lt;P&gt;I've imported the certificates to keystore and restarted the needed services.&lt;/P&gt;&lt;P&gt;With '&lt;FONT face="courier new,courier"&gt;bin/keytool -list -keystore lib/security/cacerts certificate.cer -storepass password&lt;/FONT&gt;' I can see the certificate listed. I also installed the intermediate cert.&lt;BR /&gt;Because I wasn't sure where to install the certs, I've put them in both stores:&lt;BR /&gt;- $CPDIR/jre_32&lt;BR /&gt;- $CPDIR/jre_64&lt;/P&gt;&lt;P&gt;From the CLI on the CP management server a '&lt;FONT face="courier new,courier"&gt;telnet ip.add.re.ss 636&lt;/FONT&gt;' to the Active Directory domain controller is successfull.&lt;/P&gt;&lt;P&gt;Another thing I've tried is to change the settings in file&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;$UEPMDIR/engine/conf/ldap.utils.properties&lt;/FONT&gt;&lt;BR /&gt;from &lt;FONT face="courier new,courier"&gt;use.ssl=false&lt;/FONT&gt; to &lt;FONT face="courier new,courier"&gt;use.ssl=true&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;This didn't help either.&lt;/P&gt;&lt;P&gt;I tried then the AD sync with LDAP. This was successfull.&lt;/P&gt;&lt;P&gt;So it must have something to do with LDAPS. How can I troubleshoot this further?&lt;/P&gt;&lt;P&gt;Thanks for a hint...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 14 Feb 2020 13:49:52 GMT</pubDate>
    <dc:creator>startoff</dc:creator>
    <dc:date>2020-02-14T13:49:52Z</dc:date>
    <item>
      <title>Endpoint Security: Active Directory scanner LDAPS</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Endpoint-Security-Active-Directory-scanner-LDAPS/m-p/75281#M2038</link>
      <description>&lt;P&gt;Hi all&lt;/P&gt;&lt;P&gt;I ran in problems while setting up Active Directory scanner with LDAPS enabled on a fresh installed R80.40 server.&lt;/P&gt;&lt;P&gt;The only error message i got is: unable to establish a connection to the domain controller&lt;/P&gt;&lt;P&gt;I've imported the certificates to keystore and restarted the needed services.&lt;/P&gt;&lt;P&gt;With '&lt;FONT face="courier new,courier"&gt;bin/keytool -list -keystore lib/security/cacerts certificate.cer -storepass password&lt;/FONT&gt;' I can see the certificate listed. I also installed the intermediate cert.&lt;BR /&gt;Because I wasn't sure where to install the certs, I've put them in both stores:&lt;BR /&gt;- $CPDIR/jre_32&lt;BR /&gt;- $CPDIR/jre_64&lt;/P&gt;&lt;P&gt;From the CLI on the CP management server a '&lt;FONT face="courier new,courier"&gt;telnet ip.add.re.ss 636&lt;/FONT&gt;' to the Active Directory domain controller is successfull.&lt;/P&gt;&lt;P&gt;Another thing I've tried is to change the settings in file&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;$UEPMDIR/engine/conf/ldap.utils.properties&lt;/FONT&gt;&lt;BR /&gt;from &lt;FONT face="courier new,courier"&gt;use.ssl=false&lt;/FONT&gt; to &lt;FONT face="courier new,courier"&gt;use.ssl=true&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;This didn't help either.&lt;/P&gt;&lt;P&gt;I tried then the AD sync with LDAP. This was successfull.&lt;/P&gt;&lt;P&gt;So it must have something to do with LDAPS. How can I troubleshoot this further?&lt;/P&gt;&lt;P&gt;Thanks for a hint...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Feb 2020 13:49:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Endpoint-Security-Active-Directory-scanner-LDAPS/m-p/75281#M2038</guid>
      <dc:creator>startoff</dc:creator>
      <dc:date>2020-02-14T13:49:52Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint Security: Active Directory scanner LDAPS</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Endpoint-Security-Active-Directory-scanner-LDAPS/m-p/77735#M2109</link>
      <description>&lt;P&gt;I'm actually having this same problem with an even older version of Endpoint Security. Did you ever find a solution? I've performed all the same steps you mentioned and get the same generic error.&lt;/P&gt;
&lt;P&gt;I also haven't figured out whether there is another log file besides&amp;nbsp;&lt;SPAN&gt;$UEPMDIR/logs/Authentication.log that may contain a hint as to the cause of the&amp;nbsp;&lt;/SPAN&gt;problem. There isn't anything relevant in that file for me.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Mar 2020 13:59:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Endpoint-Security-Active-Directory-scanner-LDAPS/m-p/77735#M2109</guid>
      <dc:creator>Daniel_Taney</dc:creator>
      <dc:date>2020-03-09T13:59:42Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint Security: Active Directory scanner LDAPS</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Endpoint-Security-Active-Directory-scanner-LDAPS/m-p/77740#M2110</link>
      <description>&lt;P&gt;It looks like there is more information logged in&amp;nbsp;&lt;EM&gt;&lt;STRONG&gt;/opt/CPuepm-R77/logsserver_messages.log&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;I also made sure intermediate certs were imported to the keychain. Unfortunately, this doesn't do a whole lot to help me because I know my information is correct in terms of the LDAP path, server name, ports, etc.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Telnet also works for me.&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;[2020-03-09 10:19:56,390] ERROR Dispatcher-Thread-10 - An error has occurred while trying to connect to LDAP server on [LDAPS://myDC.ad.myDomain.net:636]. Check the URL and verify that an LDAP server is running on this machine. (AbstractLdapContext)
[2020-03-09 10:19:56,390] ERROR Dispatcher-Thread-10 - An error has occurred while trying to connect to LDAP server on [LDAPS://myDC.ad.myDomain.net:636]. (FilteredDirectorySearch)
[2020-03-09 10:19:56,390] ERROR Dispatcher-Thread-10 - Check the URL and verify that an LDAP server is running on this machine. Exception:  (FilteredDirectorySearch)
javax.naming.CommunicationException: myDC.ad.myDomain.net:636 [Root exception is java.net.SocketException: Connection reset]
	at com.sun.jndi.ldap.Connection.&amp;lt;init&amp;gt;(Connection.java:224)
	at com.sun.jndi.ldap.LdapClient.&amp;lt;init&amp;gt;(LdapClient.java:136)
	at com.sun.jndi.ldap.LdapClient.getInstance(LdapClient.java:1600)
	at com.sun.jndi.ldap.LdapCtx.connect(LdapCtx.java:2698)
	at com.sun.jndi.ldap.LdapCtx.&amp;lt;init&amp;gt;(LdapCtx.java:316)
	at com.sun.jndi.ldap.LdapCtxFactory.getUsingURL(LdapCtxFactory.java:193)
	at com.sun.jndi.ldap.LdapCtxFactory.getUsingURLs(LdapCtxFactory.java:211)
	at com.sun.jndi.ldap.LdapCtxFactory.getLdapCtxInstance(LdapCtxFactory.java:154)
	at com.sun.jndi.ldap.LdapCtxFactory.getInitialContext(LdapCtxFactory.java:84)
	at javax.naming.spi.NamingManager.getInitialContext(NamingManager.java:684)
	at javax.naming.InitialContext.getDefaultInitCtx(InitialContext.java:307)
	at javax.naming.InitialContext.init(InitialContext.java:242)
	at javax.naming.ldap.InitialLdapContext.&amp;lt;init&amp;gt;(InitialLdapContext.java:153)
	at com.checkpoint.uepm.blm.directoryscanner.directoryservice.ldap.AbstractLdapContext.init(AbstractLdapContext.java:76)
	at com.checkpoint.uepm.blm.directoryscanner.directoryservice.ldap.AbstractLdapContext.init(AbstractLdapContext.java:35)
	at com.checkpoint.directoryServiceUtils.FilteredDirectorySearch.initContext(FilteredDirectorySearch.java:86)
	at com.checkpoint.directoryServiceUtils.FilteredDirectorySearch.getDirectOUsAndContainers(FilteredDirectorySearch.java:295)
	at com.checkpoint.uepm.ws.directoryscannerservice.v1.DirectoryScannerServiceImpl.getDirectChilds(DirectoryScannerServiceImpl.java:291)
	at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)
	at sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:76)
	at sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)
	at java.lang.reflect.Method.invoke(Method.java:602)
	at org.apache.cxf.service.invoker.AbstractInvoker.performInvocation(AbstractInvoker.java:166)
	at org.apache.cxf.service.invoker.AbstractInvoker.invoke(AbstractInvoker.java:82)
	at org.apache.cxf.jaxws.JAXWSMethodInvoker.invoke(JAXWSMethodInvoker.java:55)
	at org.apache.cxf.service.invoker.AbstractInvoker.invoke(AbstractInvoker.java:68)
	at org.apache.cxf.interceptor.ServiceInvokerInterceptor$1.run(ServiceInvokerInterceptor.java:58)
	at java.util.concurrent.Executors$RunnableAdapter.call(Executors.java:471)
	at java.util.concurrent.FutureTask$Sync.innerRun(FutureTask.java:334)
	at java.util.concurrent.FutureTask.run(FutureTask.java:166)
	at org.apache.cxf.workqueue.SynchronousExecutor.execute(SynchronousExecutor.java:37)
	at org.apache.cxf.interceptor.ServiceInvokerInterceptor.handleMessage(ServiceInvokerInterceptor.java:98)
	at org.apache.cxf.phase.PhaseInterceptorChain.doIntercept(PhaseInterceptorChain.java:236)
	at org.apache.cxf.transport.ChainInitiationObserver.onMessage(ChainInitiationObserver.java:104)
	at org.apache.cxf.transport.servlet.ServletDestination.invoke(ServletDestination.java:98)
	at org.apache.cxf.transport.servlet.ServletController.invokeDestination(ServletController.java:392)
	at org.apache.cxf.transport.servlet.ServletController.invoke(ServletController.java:170)
	at org.apache.cxf.transport.servlet.AbstractCXFServlet.invoke(AbstractCXFServlet.java:142)
	at org.apache.cxf.transport.servlet.AbstractHTTPServlet.doPost(AbstractHTTPServlet.java:45)
	at javax.servlet.http.HttpServlet.service(HttpServlet.java:637)
	at org.apache.cxf.transport.servlet.AbstractHTTPServlet.service(AbstractHTTPServlet.java:101)
	at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:290)
	at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:206)
	at org.apache.catalina.core.StandardWrapperValve.invoke(StandardWrapperValve.java:233)
	at org.apache.catalina.core.StandardContextValve.invoke(StandardContextValve.java:191)
	at org.apache.catalina.core.StandardHostValve.invoke(StandardHostValve.java:127)
	at org.apache.catalina.valves.ErrorReportValve.invoke(ErrorReportValve.java:102)
	at org.apache.catalina.core.StandardEngineValve.invoke(StandardEngineValve.java:109)
	at org.apache.catalina.connector.CoyoteAdapter.service(CoyoteAdapter.java:293)
	at org.apache.coyote.http11.Http11Processor.process(Http11Processor.java:859)
	at org.apache.coyote.http11.Http11Protocol$Http11ConnectionHandler.process(Http11Protocol.java:602)
	at org.apache.tomcat.util.net.JIoEndpoint$Worker.run(JIoEndpoint.java:489)
	at java.lang.Thread.run(Thread.java:780)
Caused by: java.net.SocketException: Connection reset
	at java.net.SocketInputStream.read(SocketInputStream.java:189)
	at java.net.SocketInputStream.read(SocketInputStream.java:121)
	at com.ibm.jsse2.a.a(a.java:204)
	at com.ibm.jsse2.a.a(a.java:110)
	at com.ibm.jsse2.qc.a(qc.java:619)
	at com.ibm.jsse2.qc.h(qc.java:809)
	at com.ibm.jsse2.qc.a(qc.java:106)
	at com.ibm.jsse2.qc.startHandshake(qc.java:586)
	at com.sun.jndi.ldap.Connection.createSocket(Connection.java:379)
	at com.sun.jndi.ldap.Connection.&amp;lt;init&amp;gt;(Connection.java:201)
	... 52 more
[2020-03-09 10:19:56,390] ERROR Dispatcher-Thread-10 - Throwing exception with error code : NO_CONNECTION_TO_DOMAIN_CONTROLLER (DirectoryScannerServiceImpl)
[2020-03-09 10:19:56,390] ERROR Dispatcher-Thread-10 -  (DirectoryScannerServiceImpl)
com.checkpoint.uepm.api.epsbackend.is.EpsBackendException: 
TICKET_NUMBER = 1172162787. 

	at com.checkpoint.uepm.ws.directoryscannerservice.v1.DirectoryScannerServiceImpl.handleDirectoryScannerException(DirectoryScannerServiceImpl.java:515)
	at com.checkpoint.uepm.ws.directoryscannerservice.v1.DirectoryScannerServiceImpl.getDirectChilds(DirectoryScannerServiceImpl.java:313)
	at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)
	at sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:76)
	at sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)
	at java.lang.reflect.Method.invoke(Method.java:602)
	at org.apache.cxf.service.invoker.AbstractInvoker.performInvocation(AbstractInvoker.java:166)
	at org.apache.cxf.service.invoker.AbstractInvoker.invoke(AbstractInvoker.java:82)
	at org.apache.cxf.jaxws.JAXWSMethodInvoker.invoke(JAXWSMethodInvoker.java:55)
	at org.apache.cxf.service.invoker.AbstractInvoker.invoke(AbstractInvoker.java:68)
	at org.apache.cxf.interceptor.ServiceInvokerInterceptor$1.run(ServiceInvokerInterceptor.java:58)
	at java.util.concurrent.Executors$RunnableAdapter.call(Executors.java:471)
	at java.util.concurrent.FutureTask$Sync.innerRun(FutureTask.java:334)
	at java.util.concurrent.FutureTask.run(FutureTask.java:166)
	at org.apache.cxf.workqueue.SynchronousExecutor.execute(SynchronousExecutor.java:37)
	at org.apache.cxf.interceptor.ServiceInvokerInterceptor.handleMessage(ServiceInvokerInterceptor.java:98)
	at org.apache.cxf.phase.PhaseInterceptorChain.doIntercept(PhaseInterceptorChain.java:236)
	at org.apache.cxf.transport.ChainInitiationObserver.onMessage(ChainInitiationObserver.java:104)
	at org.apache.cxf.transport.servlet.ServletDestination.invoke(ServletDestination.java:98)
	at org.apache.cxf.transport.servlet.ServletController.invokeDestination(ServletController.java:392)
	at org.apache.cxf.transport.servlet.ServletController.invoke(ServletController.java:170)
	at org.apache.cxf.transport.servlet.AbstractCXFServlet.invoke(AbstractCXFServlet.java:142)
	at org.apache.cxf.transport.servlet.AbstractHTTPServlet.doPost(AbstractHTTPServlet.java:45)
	at javax.servlet.http.HttpServlet.service(HttpServlet.java:637)
	at org.apache.cxf.transport.servlet.AbstractHTTPServlet.service(AbstractHTTPServlet.java:101)
	at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:290)
	at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:206)
	at org.apache.catalina.core.StandardWrapperValve.invoke(StandardWrapperValve.java:233)
	at org.apache.catalina.core.StandardContextValve.invoke(StandardContextValve.java:191)
	at org.apache.catalina.core.StandardHostValve.invoke(StandardHostValve.java:127)
	at org.apache.catalina.valves.ErrorReportValve.invoke(ErrorReportValve.java:102)
	at org.apache.catalina.core.StandardEngineValve.invoke(StandardEngineValve.java:109)
	at org.apache.catalina.connector.CoyoteAdapter.service(CoyoteAdapter.java:293)
	at org.apache.coyote.http11.Http11Processor.process(Http11Processor.java:859)
	at org.apache.coyote.http11.Http11Protocol$Http11ConnectionHandler.process(Http11Protocol.java:602)
	at org.apache.tomcat.util.net.JIoEndpoint$Worker.run(JIoEndpoint.java:489)
	at java.lang.Thread.run(Thread.java:780)
Caused by: com.checkpoint.directoryServiceUtils.DirectoryScannerServiceException
	at com.checkpoint.directoryServiceUtils.FilteredDirectorySearch.initContext(FilteredDirectorySearch.java:137)
	at com.checkpoint.directoryServiceUtils.FilteredDirectorySearch.getDirectOUsAndContainers(FilteredDirectorySearch.java:295)
	at com.checkpoint.uepm.ws.directoryscannerservice.v1.DirectoryScannerServiceImpl.getDirectChilds(DirectoryScannerServiceImpl.java:291)&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Mar 2020 14:27:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Endpoint-Security-Active-Directory-scanner-LDAPS/m-p/77740#M2110</guid>
      <dc:creator>Daniel_Taney</dc:creator>
      <dc:date>2020-03-09T14:27:12Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint Security: Active Directory scanner LDAPS</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Endpoint-Security-Active-Directory-scanner-LDAPS/m-p/77741#M2111</link>
      <description>&lt;P&gt;I'm actually working with Checkpoint on this case.&lt;/P&gt;&lt;P&gt;Will have a session with CP tomorrow.&lt;/P&gt;&lt;P&gt;As soon as I have a working solution I'll update this thread.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Mar 2020 14:30:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Endpoint-Security-Active-Directory-scanner-LDAPS/m-p/77741#M2111</guid>
      <dc:creator>startoff</dc:creator>
      <dc:date>2020-03-09T14:30:38Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint Security: Active Directory scanner LDAPS</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Endpoint-Security-Active-Directory-scanner-LDAPS/m-p/77742#M2112</link>
      <description>&lt;P&gt;Excellent! Thanks for replying! Anxious to hear what you find. This one has me pretty stumped!&lt;/P&gt;</description>
      <pubDate>Mon, 09 Mar 2020 14:33:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Endpoint-Security-Active-Directory-scanner-LDAPS/m-p/77742#M2112</guid>
      <dc:creator>Daniel_Taney</dc:creator>
      <dc:date>2020-03-09T14:33:27Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint Security: Active Directory scanner LDAPS</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Endpoint-Security-Active-Directory-scanner-LDAPS/m-p/77856#M2116</link>
      <description>&lt;P&gt;We had something similar when our DC server certificates auto renewed.&amp;nbsp;&lt;/P&gt;&lt;P&gt;We followed&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk106970&amp;amp;partition=Basic&amp;amp;product=Endpoint" target="_self"&gt;sk84620&lt;/A&gt;&amp;nbsp;and that sorted the problem for us.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Mar 2020 10:52:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Endpoint-Security-Active-Directory-scanner-LDAPS/m-p/77856#M2116</guid>
      <dc:creator>J_B</dc:creator>
      <dc:date>2020-03-10T10:52:45Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint Security: Active Directory scanner LDAPS</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Endpoint-Security-Active-Directory-scanner-LDAPS/m-p/77863#M2117</link>
      <description>&lt;P&gt;So, had a call with Checkpoint this morning and we could resolve the issue!&lt;/P&gt;&lt;P&gt;To explain why the error happended a short info about our setup.&lt;/P&gt;&lt;P&gt;Our endpoint protection will reach the AD Domain Controller through a public IP on another FW and there we're doing a NAT to the DC.&lt;/P&gt;&lt;P&gt;On the endpoint protection server in the Organization scanner I entered the public IP, not a hostname. Therefore we saw an error in the log on the EP about the public IP not being a SAN inside the certificate we installed on the EP server.&lt;/P&gt;&lt;P&gt;I then added a host definition inside clish on the EP server:&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;add host name fqdn.from.domaincontroller ipv4-address pub.lic.ip.address&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The pub.lic.ip.address is the IP address on the firewall where we're doing the NAT.&lt;/P&gt;&lt;P&gt;After that, I had to enter the hostname instead of the public IP address in the Organization Scanner settings.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Mar 2020 11:58:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Endpoint-Security-Active-Directory-scanner-LDAPS/m-p/77863#M2117</guid>
      <dc:creator>startoff</dc:creator>
      <dc:date>2020-03-10T11:58:06Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint Security: Active Directory scanner LDAPS</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Endpoint-Security-Active-Directory-scanner-LDAPS/m-p/77906#M2118</link>
      <description>&lt;P&gt;Glad to hear this resolved your issue! Your circumstances are a little different than mine. So, unfortunately, I don't think this fix applies to me. Was there anywhere else you looked during the troubleshooting session to see additional or more specific errors?&lt;/P&gt;
&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 10 Mar 2020 18:37:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Endpoint-Security-Active-Directory-scanner-LDAPS/m-p/77906#M2118</guid>
      <dc:creator>Daniel_Taney</dc:creator>
      <dc:date>2020-03-10T18:37:13Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint Security: Active Directory scanner LDAPS</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Endpoint-Security-Active-Directory-scanner-LDAPS/m-p/77907#M2119</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/19118"&gt;@J_B&lt;/a&gt;&amp;nbsp;I have seen these SK's, but had asked our server guys to provide the certificates. Since this fixed your problem, maybe I need to double back with them and make sure they followed the procedure correctly to acquire them.&lt;/P&gt;
&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 10 Mar 2020 18:38:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Endpoint-Security-Active-Directory-scanner-LDAPS/m-p/77907#M2119</guid>
      <dc:creator>Daniel_Taney</dc:creator>
      <dc:date>2020-03-10T18:38:08Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint Security: Active Directory scanner LDAPS</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Endpoint-Security-Active-Directory-scanner-LDAPS/m-p/77934#M2123</link>
      <description>&lt;P&gt;I'm sorry to hear that didn't help in your case.&lt;/P&gt;&lt;P&gt;We looked at the same log as you:&lt;/P&gt;&lt;P&gt;$UEPMDIR/log/server_messages.log&lt;/P&gt;&lt;P&gt;There we saw these two error messages:&lt;/P&gt;&lt;P&gt;javax.net.ssl.SSLHandshakeException: java.security.cert.CertificateException: No subject alternative names matching IP address pub.lic.ip.address found&lt;/P&gt;&lt;P&gt;java.security.cert.CertificateException: No subject alternative names matching IP address pub.lic.ip.address found&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The pub.lic.ip.address is the one where we're doing the NAT to the ADC.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Mar 2020 06:49:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Endpoint-Security-Active-Directory-scanner-LDAPS/m-p/77934#M2123</guid>
      <dc:creator>startoff</dc:creator>
      <dc:date>2020-03-11T06:49:54Z</dc:date>
    </item>
  </channel>
</rss>

