"Cannot configure identity source due to Failed to probe provider connectivity... Caused by: Can't contact LDAP server" when attempting to edit an existing LDAP with SSL (LDAPS) configuration
search cancel

"Cannot configure identity source due to Failed to probe provider connectivity... Caused by: Can't contact LDAP server" when attempting to edit an existing LDAP with SSL (LDAPS) configuration

book

Article ID: 401134

calendar_today

Updated On:

Products

VMware vCenter Server

Issue/Introduction

  • When attempting to edit an existing LDAP with SSL (LDAPS) identity source configuration on the vCenter Server using the vSphere Client in order to update or replace the existing certificates, the following error occurs:

    Cannot configure identity source due to Failed to probe provider connectivity [URI: ldaps://XXXXX:636 ]; tenantName [XXXXX.XXXX], userName [cn=XXXX,dc=ad,dc=XXXX,dc=XX] Caused by: Can't contact LDAP server.

Environment

vCenter Server 8.x
vCenter Server 7.x

Cause

This is an expected behaviour. A per KB article 316596 - Configuring a vCenter Single Sign-On Identity Source using LDAP with SSL (LDAPS):

"If updating or replacing the SSL certificate, the identity source must be removed and re-added." 

Resolution

In order to update or replace the existing LDAPS Certificates remove the existing Identity Source and re-add it using the new certificates.