How do I create an outbound SSL connection for my LDAPS provider?
Or
my outbound SSL connection for LDAPS fails with the following error:
Cannot connect to this directory 'Could not establish context on any of the ldap urls'.
Release: Any
Component: Gateway
The secure connection (SSL) failed to establish between the LDAP and the policy manager
If an LDAP server is configured to use secure communications via LDAPS, it is imperative to ensure that the LDAPS server is trusted for Outbound SSL. If it is not trusted, the connection will not attempt to use SSL encryption and the connection to the LDAPS enabled identity provider may fail.
Enabling trust for outbound SSL involves importing the public certificate of the LDAPS server into the API Gateway via the Policy Manager. To import the public certificate of an LDAPS enabled identity provider:
** If outbound SSL does not allow the LDAPS connection please add these additional options, Signing Certificates for Outbound SSL Connections, Signing Client Certificates, also on the validation tab select "certificate is a trust anchor".
Once the certificate is imported successfully, you will need to add the identity provider if it was not done prior: