Unified Manager Active Directory authentication fails if the SSL Certificate does not contain the common name or the subject alternative name
Applies to
- OnCommand Unified Manager 9.5
- OnCommand Unified Manager 9.4
Issue
After upgrading the OnCommand UM OVA installation to 9.5, or upgrading Java when running on Windows or RedHat, Active Directory (AD) authentication in UM stops working. The following error appears when testing AD authentication on the Setup / Authentication page:
Unable to communicate with the authentication server due to the following reasons: No subject alternative names present. Verify your authentication server configuration.
The ocum-error.log has errors similar to the following:
2019-03-12 13:07:27,935 ERROR [umadmin] [default task-3] [service.logging.SimpleRemoteLoggingService|logOnServer] [c.n.d.w.c.s.l.LdapServersPagePresenter] Unable to communicate with the authentication server due to the following reasons: No subject alternative names present. Verify your authentication server configuration.