The LDAP connection status is in Failed state after upgrade to 4.2.2.1. LDAP functionality does not appear to be impacted.
book
Article ID: 416122
calendar_today
Updated On:
Products
VMware NSX
Issue/Introduction
After upgrade of NSX to 4.2.x, LDAP probe is in failed state in the NSX UI with "An undetermined error occurred."
LDAP services are working as expected
Running the API call to check the LDAP probe returns an "GENERAL_ERROR"
Environment
VMware NSX 4.2 and above
Cause
There are two processes involved: 1.Proton - the primary service responsible for hosting the majority of APIs. 2.Reverse-proxy - responsible for the actual authentication processing (authN)
Proton is responsible for maintaining the LDAP configuration in the database. It then passes those values to reverse-proxy on disk.
There was a change made to the allowed ciphersuites for proton services specifically. This change significantly lowered the number of cipher suites that are permitted. Many of the less secure cipher suites are no longer supported. See below for a comparison of cipher suites allowed in 4.2.2.1 vs. 3.2.1.2: