<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic LDAP Open in Administration and Deployment</title>
    <link>https://communities.sas.com/t5/Administration-and-Deployment/LDAP-Open/m-p/133532#M1458</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Trying to connect from SAS server to LDAP server using TCP port 636 is the common communications port for SSL, getting error as "ERROR: Unable to contact the LDAP server.".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am able to connect LDAP server with TCP port 389 port from Solaris where SAS 9.1.3 has installed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt; font-family: Courier New;"&gt; %let ADServer = "xxxxxxxxxx";&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt; font-family: Courier New;"&gt; %let ADPort = 389;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt; font-family: Courier New;"&gt; %let ADPerBaseDN ="ou=users,ou=internal,o=xxxxxx";&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt; font-family: Courier New;"&gt; %let &lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Courier New;"&gt;ADBindUser = "uid=xxxxxx,ou=users,ou=internal,o=xxxxx";&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt; font-family: Courier New;"&gt; %let &lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Courier New;"&gt;ADBindPW = "xxxx";&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;call ldaps_open( handle, &amp;amp;ADServer, &amp;amp;ADPort, &amp;amp;ADPerBaseDN, &amp;amp;ADBindUser, &amp;amp;ADBindPW, rc, option );&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Installed Verisign certificate in "/etc/certs/ldapCert/cert8.db" path on source system to use 636 port, Any environment variable to pass this certificate path while connecing from sas to ldap.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;your help would be much appreciated&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 06 Nov 2013 17:37:59 GMT</pubDate>
    <dc:creator>sunilreddy</dc:creator>
    <dc:date>2013-11-06T17:37:59Z</dc:date>
    <item>
      <title>LDAP Open</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/LDAP-Open/m-p/133532#M1458</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Trying to connect from SAS server to LDAP server using TCP port 636 is the common communications port for SSL, getting error as "ERROR: Unable to contact the LDAP server.".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am able to connect LDAP server with TCP port 389 port from Solaris where SAS 9.1.3 has installed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt; font-family: Courier New;"&gt; %let ADServer = "xxxxxxxxxx";&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt; font-family: Courier New;"&gt; %let ADPort = 389;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt; font-family: Courier New;"&gt; %let ADPerBaseDN ="ou=users,ou=internal,o=xxxxxx";&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt; font-family: Courier New;"&gt; %let &lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Courier New;"&gt;ADBindUser = "uid=xxxxxx,ou=users,ou=internal,o=xxxxx";&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt; font-family: Courier New;"&gt; %let &lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Courier New;"&gt;ADBindPW = "xxxx";&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;call ldaps_open( handle, &amp;amp;ADServer, &amp;amp;ADPort, &amp;amp;ADPerBaseDN, &amp;amp;ADBindUser, &amp;amp;ADBindPW, rc, option );&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Installed Verisign certificate in "/etc/certs/ldapCert/cert8.db" path on source system to use 636 port, Any environment variable to pass this certificate path while connecing from sas to ldap.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;your help would be much appreciated&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Nov 2013 17:37:59 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/LDAP-Open/m-p/133532#M1458</guid>
      <dc:creator>sunilreddy</dc:creator>
      <dc:date>2013-11-06T17:37:59Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP Open</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/LDAP-Open/m-p/133533#M1459</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Check with your network specialist regarding port 636. It is common practice these days to protect servers with firewalls, and then open ports in the firewalls only as required plus restrict traffic to only specified servers. In my organisation everytime we want to add a new server we need to change the firewall rules for our SAS server. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Nov 2013 19:06:10 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/LDAP-Open/m-p/133533#M1459</guid>
      <dc:creator>SASKiwi</dc:creator>
      <dc:date>2013-11-06T19:06:10Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP Open</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/LDAP-Open/m-p/133534#M1460</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;But i am able to connect with 636 by using verisign installed path (&lt;STRONG&gt;Z -P "/etc/certs/ldapCert/cert8.db") in&lt;/STRONG&gt; below shell script&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;&lt;SPAN lang="SV"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt; font-family: Courier New;"&gt;ldapsearch -h ecd.ldap.se -p 636 -D "uid=EXXXXXX,ou=Users,ou=Internal,o=XXXXXX" -T -w&amp;nbsp; 8HrS7iQ2 -&lt;STRONG&gt;Z -P "/etc/certs/ldapCert/cert8.db"&lt;/STRONG&gt; -1 -b "ou=users,ou=internal,o=XXXXXX" "(&amp;amp;(objectclass=ldap)(idmaccess=XXXXXX*))" &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt; font-family: Courier New;"&gt;I want to use "/etc/certs/ldapCert/cert8.db" certification path to run it from SAS Code. Is there any way to pass this path thru variable or any alternative&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt; font-family: Courier New;"&gt;sas code:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;data useraccess (keep=entryname attrName value filter displayName);&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; length entryname $600 attrName $100 value $600 filter $500&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; displayName $600 ;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; handle = 0;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; rc&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; = 0;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; option = "OPT_REFERRALS_ON";&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; /* open connection to LDAP server */&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; call ldaps_open( handle, &amp;amp;ADServer, &amp;amp;ADPort, &amp;amp;ADPerBaseDN, &amp;amp;ADBindUser, &amp;amp;ADBindPW, rc, option );&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; timeLimit=0;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; sizeLimit=0;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; base='';&amp;nbsp; /* use default set at _open time */&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; referral = "OPT_REFERRALS_ON";&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; restart = ""; /* use default set at _open time */&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; call ldaps_setOptions(handle, timeLimit, sizeLimit, base, referral, restart, rc);&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; %include groups;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; /* close connection to LDAP server */&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; call ldaps_close(handle,rc);&lt;BR /&gt;&amp;nbsp; &lt;BR /&gt;run;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Nov 2013 20:21:34 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/LDAP-Open/m-p/133534#M1460</guid>
      <dc:creator>sunilreddy</dc:creator>
      <dc:date>2013-11-06T20:21:34Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP Open</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/LDAP-Open/m-p/133535#M1461</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In that case I suggest you open a track with Tech Support.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Nov 2013 20:32:11 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/LDAP-Open/m-p/133535#M1461</guid>
      <dc:creator>SASKiwi</dc:creator>
      <dc:date>2013-11-06T20:32:11Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP Open</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/LDAP-Open/m-p/133536#M1462</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi sunilreddy,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have a track still opened for months on a similar issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; - a SAS 9.3 (TS1/M1) Metadata Server on Linux x64&amp;nbsp; is unable to authenticate against an LDAP server through SSL (LDAPS) using a &lt;EM&gt;chained&lt;/EM&gt; Verisign Certificate.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;it works fine using a self-signed certificate but fails with a &lt;EM&gt;chained&lt;/EM&gt; Verisign. SAS tech support has tried to replicate our issue but we disagree on the minimal requirements&lt;/P&gt;&lt;P&gt;and, unfortunately, this is still unresolved despite upgrading the ssl SAS code up to 9.4.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In our case, the LDAPS certificate should be declared with &lt;STRONG&gt;SSLCALISTLOC&lt;/STRONG&gt; SAS sytem option. Be aware that SAS awaits the SSL certificate to be read as a plain text file (ASCII);&lt;/P&gt;&lt;P&gt;I am note sure it can retrieve the certificate from a *.dlb key store. Since I'm not familiar with SAS 9.1 on Solaris, check the documentation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'll be curious to know if you can open the LDAPS call at all. Please, keep us informed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ronan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Nov 2013 12:05:02 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/LDAP-Open/m-p/133536#M1462</guid>
      <dc:creator>ronan</dc:creator>
      <dc:date>2013-11-07T12:05:02Z</dc:date>
    </item>
  </channel>
</rss>

