Security Compliance

Unable to login with AD credentials to SEM web console

This article shows steps on how to troubleshoot when you cannot login with AD credentials to SEM web console.

First published date

11/28/2019 2:28 PM

Last published date

11/28/2019 2:28 PM

Overview

You are trying to login to SEM web console with AD credentials but getting Authentication failed and you see the following error in manager.log
javax.naming.CommunicationException: simple bind failed: YourPrimaryDC:636 [Root exception is javax.net.ssl.SSLHandshakeException: java.security.cert.CertificateException: Certificate not trusted!]

Product section

Security Event Manager

Cause

  • The LDAP cert was expired on AD and it has been renewed but SEM need to get the new cert
  • The AD account used by SEM to access the LDAP is invalid or the account is locked out

Resolution

Re-configure the LDAP connection via SEM HTML5
1. Go to https://yourlem/mvc/configuration/ldap
2. Click Edit
3. If LDAP details have not changed then simply enter the LDAP Service account password and hit Save
4. You will be prompted to accept the new cert, click Trust
5. Logout and login back with AD credentials to verify