mirror of
https://github.com/BookStackApp/BookStack.git
synced 2026-02-05 00:29:48 +03:00
LDAP over TLS: Unable to bind to server: Can't contact LDAP server #990
Closed
opened 2026-02-04 23:17:45 +03:00 by OVERLORD
·
16 comments
No Branch/Tag Specified
development
l10n_development
further_theme_development
release
llm_only
vectors
v25-11
docker_env
drawio_rendering
user_permissions
ldap_host_failover
svg_image
prosemirror
captcha_example
fix/video-export
v25.12.3
v25.12.2
v25.12.1
v25.12
v25.11.6
v25.11.5
v25.11.4
v24.11.4
v25.11.3
v25.11.2
v25.11.1
v25.11
v25.07.3
v25.07.2
v25.07.1
v25.07
v25.05.2
v25.05.1
v25.05
v25.02.5
v25.02.4
v25.02.3
v25.02.2
v25.02.1
v25.02
v24.12.1
v24.12
v24.10.3
v24.10.2
v24.10.1
v24.10
v24.05.4
v24.05.3
v24.05.2
v24.05.1
v24.05
v24.02.3
v24.02.2
v24.02.1
v24.02
v23.12.3
v23.12.2
v23.12.1
v23.12
v23.10.4
v23.10.3
v23.10.2
v23.10.1
v23.10
v23.08.3
v23.08.2
v23.08.1
v23.08
v23.06.2
v23.06.1
v23.06
v23.05.2
v23.05.1
v23.05
v23.02.3
v23.02.2
v23.02.1
v23.02
v23.01.1
v23.01
v22.11.1
v22.11
v22.10.2
v22.10.1
v22.10
v22.09.1
v22.09
v22.07.3
v22.07.2
v22.07.1
v22.07
v22.06.2
v22.06.1
v22.06
v22.04.2
v22.04.1
v22.04
v22.03.1
v22.03
v22.02.3
v22.02.2
v22.02.1
v22.02
v21.12.5
v21.12.4
v21.12.3
v21.12.2
v21.12.1
v21.12
v21.11.3
v21.11.2
v21.11.1
v21.11
v21.10.3
v21.10.2
v21.10.1
v21.10
v21.08.6
v21.08.5
v21.08.4
v21.08.3
v21.08.2
v21.08.1
v21.08
v21.05.4
v21.05.3
v21.05.2
v21.05.1
v21.05
v21.04.6
v21.04.5
v21.04.4
v21.04.3
v21.04.2
v21.04.1
v21.04
v0.31.8
v0.31.7
v0.31.6
v0.31.5
v0.31.4
v0.31.3
v0.31.2
v0.31.1
v0.31.0
v0.30.7
v0.30.6
v0.30.5
v0.30.4
v0.30.3
v0.30.2
v0.30.1
v0.30.0
v0.29.3
v0.29.2
v0.29.1
v0.29.0
v0.28.3
v0.28.2
v0.28.1
v0.28.0
v0.27.5
v0.27.4
v0.27.3
v0.27.2
v0.27.1
v0.27
v0.26.4
v0.26.3
v0.26.2
v0.26.1
v0.26.0
v0.25.5
v0.25.4
v0.25.3
v0.25.2
v0.25.1
v0.25.0
v0.24.3
v0.24.2
v0.24.1
v0.24.0
v0.23.2
v0.23.1
v0.23.0
v0.22.0
v0.21.0
v0.20.3
v0.20.2
v0.20.1
v0.20.0
v0.19.0
v0.18.5
v0.18.4
v0.18.3
v0.18.2
v0.18.1
v0.18.0
v0.17.4
v0.17.3
v0.17.2
v0.17.1
v0.17.0
v0.16.3
v0.16.2
v0.16.1
v0.16.0
v0.15.3
v0.15.2
v0.15.1
v0.15.0
v0.14.3
v0.14.2
v0.14.1
v0.14.0
v0.13.1
v0.13.0
v0.12.2
v0.12.1
v0.12.0
v0.11.2
v0.11.1
v0.11.0
v0.10.0
v0.9.3
v0.9.2
v0.9.1
v0.9.0
v0.8.2
v0.8.1
v0.8.0
v0.7.6
v0.7.5
v0.7.4
v0.7.3
0.7.2
v.0.7.1
v0.7.0
v0.6.3
v0.6.2
v0.6.1
v0.6.0
v0.5.0
Labels
Clear labels
🎨 Design
📖 Docs Update
🐛 Bug
🐛 Bug
:cat2:🐈 Possible duplicate
💿 Database
☕ Open to discussion
💻 Front-End
🐕 Support
🚪 Authentication
🌍 Translations
🔌 API Task
🏭 Back-End
⛲ Upstream
🔨 Feature Request
🛠️ Enhancement
🛠️ Enhancement
🛠️ Enhancement
❤️ Happy feedback
🔒 Security
🔍 Pending Validation
💆 UX
📝 WYSIWYG Editor
🌔 Out of scope
🔩 API Request
:octocat: Admin/Meta
🖌️ View Customization
❓ Question
🚀 Priority
🛡️ Blocked
🚚 Export System
♿ A11y
🔧 Maintenance
> Markdown Editor
No Label
🐕 Support
Milestone
No items
No Milestone
Projects
Clear projects
No project
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: starred/BookStack#990
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Originally created by @Mant1kor on GitHub (Jan 15, 2019).
Describe the bug
Login via Active Directory account.
Sometimes I've got error:
ldap_bind(): Unable to bind to server: Can't contact LDAP serverScreenshots


Your Configuration (please complete the following information):
Additional context
.envoptionsAD level: 2008 R2
@Mant1kor commented on GitHub (Jan 15, 2019):
Update: the issue reproduce only when connected to LDAP_SERVER over TLS
LDAP_SERVER=ldaps://dc.domain.com:636
@ssddanbrown commented on GitHub (Jan 15, 2019):
Sorry to hear you're having issues @Mant1kor,
Just to confirm is this a new BookStack/Ldap setup you're experiencing this on or are you just experiencing this after performing an update?
Does this mean it sometimes does work as expected, without error?
@Mant1kor commented on GitHub (Jan 15, 2019):
It's a new BookStack/Ldap setup.
Yep, error occurs in ~50% of attempts. I'll try to record video proof.
@Mant1kor commented on GitHub (Jan 15, 2019):
Looks like that's solve my problem:
LDAP_USER_FILTER=(&(objectCategory=Person)(sAMAccountName=${user}))Give me a ~day to check in detail.
@Mant1kor commented on GitHub (Jan 16, 2019):
@ssddanbrown still something wrong with ldap auth

@ssddanbrown commented on GitHub (Jan 16, 2019):
This sounds very similar to #1069 and perhaps #247.
If I'm honest, I'm not really sure how to diagnose such an issue.
@Mant1kor commented on GitHub (Jan 16, 2019):
I'm not a specialist, but some people(googled) recommends to use ldap_start_tls() instead of ldap_bind()
It's not critical, I'll use ldap:// to avoid the problem.
And I remind you again: the issue reproduce only with ldaps://
@FreeTheTech101 commented on GitHub (Jan 17, 2019):
I personally believe there is something going wrong with verified LDAPS. Despite enabling trust my personal CA, I still encountered this issue. The "temporary" work around which I ended up using (which I cannot solely recommend) is changing the following lines:
to
@cenix102 commented on GitHub (Jan 21, 2019):
Hello to everyone!
I have the same problem. Maybe my configuration is wrong or something else. (PS: I tried the configuration from this issue).
Config:
AUTH_METHOD=ldap
@Mant1kor commented on GitHub (Jan 21, 2019):
@cenix102 use ldap:// to avoid the problem. And waiting for the fix...
LDAP_SERVER=ldap://172.25.60.10:389And one more thing:
Using admin credentials is not necessary and secure. Use a normal user account.
@cenix102 commented on GitHub (Jan 21, 2019):
@Mant1kor thanks for your answer. Now I have some credential errors...
PS: ldap.admin is just a the name. The user have not admin access. :-)
@christophert commented on GitHub (Feb 6, 2019):
Setting
LDAP_TLS_INSECUREis the equivalentTLS REQCERT neverin/etc/ldap/ldap.conffor the session so this might be unrelated.I personally haven't run in to this issue with our AD infrastructure (2012R2/2016). Are there any log entries in the DC's auth log that indicate authentication failure? What OS is BookStack running on?
@Mant1kor commented on GitHub (Feb 7, 2019):
It's strange, but I can't reproduce the problem any more.
The difference is:
OS: CentOS 7
@Duan-fei commented on GitHub (Mar 12, 2019):
@Mant1kor

I also met this kind of problem, have you solved this problem,Can you help me?
This is my ldap configuration:
@Mant1kor commented on GitHub (Mar 14, 2019):
@Duan-fei
You don't use encryption. Did you get the same error "Can't contact LDAP server"?
@ssddanbrown commented on GitHub (May 18, 2019):
An issue was found in how BookStack handles LDAP URI's. A fix was applied for release v0.26:
c24764018aIf anyone is still experiencing issues it's work updating to the latest release as you may find your issue has been fixed.