Lexmark X782e PKI-Enabled MFP Installation and Configuration Guide - Page 55

Use SSL/TLS checkbox; change the LDAP

Page 55 highlights

LDAP lookups (searching address book, getting user's email address, getting user's home directory) fail almost immediately blocked by a firewall. Resolution: These ports are used by the MFP to communicate with the LDAP Server and must be open in order for LDAP lookups to work. Cause: Reverse DNS lookup are disabled on the network. Resolution: The MFP uses reverse DNS lookups to verify IP addresses. If these lookups are disabled on the network, check the Disable Reverse DNS Lookups option in the PKI/AD Authentication solution settings. Cause: The LDAP search base is too broad in scope Resolution: Narrow the LDAP search base to the lowest possible scope that will include all necessary users. Cause: The user's credentials are being used to connect to the LDAP server but IP address for the LDAP server was used. Resolution: When the user's credentials are used to connect to the LDAP server, the hostname of the LDAP server must be used instead of the IP address. Cause: Port 389 is being used but the LDAP Server requires SSL to be used. Resolution: Change the LDAP Port to 636; check the Use SSL/TLS checkbox; change the LDAP Certificate Verification to "Never". Cause: The LDAP search base is incorrect. Resolution: Correct the LDAP search base to be the lowest possible scope that will include all necessary users. Cause: The LDAP attribute being searched for is not correct. Resolution: Verify the LDAP attributes for email addresses and/or the user's home directory is correct. Version 2.0.0 Page 49

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60

Version 2.0.0
Page 49
blocked by a firewall.
Resolution:
These ports are used by the MFP to
communicate with the LDAP Server and must be
open in order for LDAP lookups to work.
Cause:
Reverse DNS lookup are disabled on the
network.
Resolution:
The MFP uses reverse DNS lookups to
verify IP addresses.
If these lookups are disabled
on the network, check the Disable Reverse DNS
Lookups option in the PKI/AD Authentication
solution settings.
Cause:
The LDAP search base is too broad in scope
Resolution:
Narrow the LDAP search base to the
lowest possible scope that will include all
necessary users.
LDAP lookups (searching address
book, getting user’s email address,
getting user’s home directory) fail
almost immediately
Cause:
The user’s credentials are being used to
connect to the LDAP server but IP address for the
LDAP server was used.
Resolution:
When the user’s credentials are used to
connect to the LDAP server, the hostname of the
LDAP server must be used instead of the IP
address.
Cause:
Port 389 is being used but the LDAP Server
requires SSL to be used.
Resolution:
Change the LDAP Port to 636; check the
Use SSL/TLS checkbox; change the LDAP
Certificate Verification to “Never”.
Cause:
The LDAP search base is incorrect.
Resolution:
Correct the LDAP search base to be the
lowest possible scope that will include all
necessary users.
Cause:
The LDAP attribute being searched for is not
correct.
Resolution:
Verify the LDAP attributes for email
addresses and/or the user’s home directory is
correct.