Discussion:
AD LDS for single sign on for firewall
(too old to reply)
Brian Allen
2018-06-07 15:33:09 UTC
Permalink
Have gotten the single sign on working but getting an error on the DC server.
Error 2537
The directory server has failed to create the AD LDS serviceConnectionPoint object in Active Directory Lightweight Directory Services. This operation will be retried.

Error value:
5 Access is denied.
Server error:
00000005: SecErr: DSID-03152612, problem 4003 (INSUFF_ACCESS_RIGHTS), data 0

The account under this instance is a domain user. I do not want Active Directory to be updated, only read information. I have tried using this link

https://social.technet.microsoft.com/Forums/windowsserver/en-US/2ec4da2d-72ca-4c67-ae9d-5666c1f3c529/ad-lds-event-log-2536-question?forum=winserverDS

I have attempted to disable SCP publication but my AD configuration does not have CN=SCP Publication Service

I have CN= Services, CN=Windows NT, CN =Directory Service, but do not have the CN=SCP Publication Service in the right hand pane.

I changed the Instance from the network service to a AD user without admin rights. Now in addition to the warning message I'm getting an error message that states:

Internal error: An Active Directory Lightweight Directory Services error has occurred.

Additional Data
Error value (decimal):
-1073741790
Error value (hex):
c0000022
Internal ID:
3000812

This error occurs before the warning message.

Everything appears to be working with the exception of the warning and error message. Anyone have an idea?
Brian Allen
2018-06-08 14:17:39 UTC
Permalink
Correction, I found out that I do need Active Directory integration due to some people needing to change passwords when they log in.
Continue reading on narkive:
Search results for 'AD LDS for single sign on for firewall' (Questions and Answers)
14
replies
Creating a "Why we should switch to Mac" Speech. Help Please?
started 2007-10-26 15:44:14 UTC
desktops
Loading...