Dell Security Management Server Virtual 11.0以降ではLDAPをバインドできない

Resumen: この記事では、リモート管理コンソールでLDAPをバインドするときに、Dell Security Management Server Virtual v11.0以降で「サーバーに接続できません」というエラーが表示される状況について説明します。

Este artículo se aplica a Este artículo no se aplica a Este artículo no está vinculado a ningún producto específico. No se identifican todas las versiones del producto en este artículo.

Síntomas

対象製品:

  • Dell Security Management Server Virtual

影響を受けるバージョン:

  • v11.0以降

対象オペレーティング システム:

  • Linux

通常、古いバージョンからDell Security Management Server Virtual v11.0以降にアップグレードし、アップデート前に正常に機能していたのと同じLDAP設定を使用しようとすると、ドメインのステータスが無効と表示され、LDAP設定を保存しようとしたときにエラーが発生します。

リモート管理コンソールでLDAPをバインドしようとすると、サーバーに接続できないというエラーが表示されます。ログにSSLハンドシェイク エラーが表示されます。

org.springframework.ldap.CommunicationException: simple bind failed: ADSERVER.DOMAIN.COM:636; nested exception is javax.naming.CommunicationException: simple bind failed: ADSERVER.DOMAIN.COM:636 [Root exception is javax.net.ssl.SSLHandshakeException: No subject alternative DNS name matching ADSERVER.DOMAIN.COM found.]

サーバーに接続できません

Causa

v11.0での自己作成証明書とJavaアップデート。LDAPS(Secure LDAP over TLS)接続の堅牢性を向上させるために、エンドポイント識別アルゴリズムがデフォルトで有効になっています。変更ログから: https://www.oracle.com/technetwork/java/javase/8u181-relnotes-4479407.html このハイパーリンクをクリックすると、デル・テクノロジーズ以外のWebサイトにアクセスします。

Resolución

以下の手順に従って、「wrapper.conf」を修正して、エンドポイントの識別を無効にします。

注:この操作は、必要に応じてSSHセッションを介して実行できます。SSHを有効にする方法: Dell Security Management Server VirtualでSSHを有効にする方法
  1. サービスを停止する 方法については、「Dell Security Management Server Virtualのサービスを停止および開始する方法」を参照してください。
  2. メイン メニューから、[ Launch Shell]を選択します。
    [Launch Shell]の選択
  3. su dellsupport Enterキーを押します。
    「su dellsupport」と入力します。
  4. のパスワードを入力します dellsupport アカウントを選択し、 Enterを押します。
    パスワードを入力します
  5. sudo nano /opt/dell/server/security-server/conf/wrapper.confの詳細を確認してください。
    「sudo nano /opt/dell/server/security-server/conf/wrapper.conf」と入力します。
  6. [# Additional java parameters to the VM]で、次の行を追加します。 wrapper.java.additional.XX=-Dcom.sun.jndi.ldap.object.disableEndpointIdentification=true ここで、 XX はリストの増分です(この例では12です)。
    行wrapper.java.additional.XX=-Dcom.sun.jndi.ldap.object.disableEndpointIdentification=trueを追加します。
  7. CTRL + Oを押して変更を保存します。
  8. CTRL + Xを押して終了します。
  9. exit Enterを押してログアウトします dellsupportの詳細を確認してください。
    「exit」と入力します
  10. exit 次に Enter を押してシェルからログアウトし、メインメニューに戻ります。
    「exit」と入力します
  11. サービスの開始 については、「Dell Security Management Server Virtualでサービスを停止および開始する方法」を参照してください

これで、LDAPポートを使用してドメインをバインドできます。

Productos afectados

Dell Encryption
Propiedades del artículo
Número del artículo: 000205453
Tipo de artículo: Solution
Última modificación: 05 jun 2026
Versión:  3
Encuentre respuestas a sus preguntas de otros usuarios de Dell
Servicios de soporte
Compruebe si el dispositivo está cubierto por los servicios de soporte.