Cannot integrate PAM with AWS Active Directory
search cancel

Cannot integrate PAM with AWS Active Directory

book

Article ID: 265329

calendar_today

Updated On:

Products

CA Privileged Access Manager (PAM)

Issue/Introduction

PAM Admin cannot integrate PAM with AWS Active Directory over LDAPS.

They get the error:

"PAM-CM-0270: LDAP Bind fail: Cannot contact LDAP server xxxxxxxx.yyy.zzz"

Environment

Release : 4.0.x and 4.1.x

Component: PRIVILEGED ACCESS MANAGEMENT

Cause

No certificate binded to their AWS LDAP Server

Resolution

SSH'd into PAM Appliance and executed the following command:

openssl s_client -showcerts -connect <ldapserver>:636

and no certificates came back. 

PAM Admin worked with this AWS Team and binded a certificate to their AWS LDAP Server and then the issue was resolved.