Impact of Removing Client Authentication (id-kp-clientAuth) Identifier from LDAP Certificates on ONTAP LDAPS Connectivity
Applies to
- ONTAP 9 (all versions)
- LDAP integration using Active Directory as LDAP server
- LDAPS (LDAP over SSL/TLS) configurations
Answer
The removal of the Client Authentication (id‑kp‑clientAuth) identifier from SSL/TLS certificates will not affect ONTAP LDAP connectivity or configuration when Active Directory is used as the LDAP server.
- ONTAP LDAP/LDAPS configurations do not rely on client certificates or mutual authentication.
- Active Directory Domain Controllers only require a server certificate to authenticate themselves to clients during LDAPS communication.
Because ONTAP does not use client certificates for LDAP/LDAPS and no component in the LDAP workflow depends on the id‑kp‑clientAuth identifier, this change will not impact existing LDAP connectivity or configuration.
