Acutis Gate logo Acutis Gate Health check help

Health check › Active Directory

Directory lookups (LDAP)

Check id ad.ldap

What it checks

Looks up the directory over an encrypted, Kerberos-signed LDAP connection, the way Gate reads people and groups.

What you might see

OKEncrypted LDAP (LDAPS, Kerberos) to dc1.corp.example:636 works.Fine.
ProblemCan't contact LDAP server / certificate verify failed / Strong(er) authentication requiredA port is blocked, the DC's certificate is not trusted, or the bind was refused.

How to fix it

Gate needs to reach a DC on 636 (LDAPS, Windows edition) or 389 (LDAP, Linux appliance; Gate always signs), plus 88 (Kerberos).

  1. On the domain controller: certlm.msc → Personal → Certificates should hold a Domain Controller or Kerberos Authentication certificate from your company CA (an AD CS enterprise CA issues these automatically).
  2. On the Gate server: the company CA must be in Trusted Root Certification Authorities (domain members get it by Group Policy).
  3. Check the firewall between Gate and the DCs.

Command line

Test-NetConnection dc1.corp.example -Port 636     # Windows
Test-NetConnection dc1.corp.example -Port 88
nc -vz dc1.corp.example 389; nc -vz dc1.corp.example 88   # Linux

Related checks

Gate's service account

Still stuck? Click Copy report on the Health check and send it to support@acutisgo.com. · Acutis Gate · Guides