Troubleshooting Tip: LDAPS connection failing with 'Cert error 66, EE certificate key too weak'
| Description | This article describes an issue that occurs where the connection status shows 'Can't contact LDAP server' when 'Secure Connection' (LDAPS) is enabled under LDAP Server settings. |
| Scope | FortiGate v7.4 and above. |
| Solution | In the packet captures, the client (FortiGate) sent 'Alert (Level: Fatal, Description: Bad Certificate)' to the server. This alert message is sent when FortiGate fails to validate the Server certificate sent by the LDAP server.
fnbamd debug output:
[1407] __ldap_tcps_connect-Start ldap conn timer.
To resolve this issue, regenerate the server certificate with a minimum of a 2048-bit RSA key.
Related articles: Technical Tip: LDAPS/STARTTLS certificate issuer enforcement Troubleshooting Tip: Alert (Level: Fatal, Description: Bad Certificate) when configuring LDAPS |

