Health check › Active Directory
Directory lookups (LDAP)
Check id ad.ldap
What it checks
Looks up the directory over an encrypted, Kerberos-signed LDAP connection, the way Gate reads people and groups.
What you might see
| OK | Encrypted LDAP (LDAPS, Kerberos) to dc1.corp.example:636 works. | Fine. |
| Problem | Can't contact LDAP server / certificate verify failed / Strong(er) authentication required | A port is blocked, the DC's certificate is not trusted, or the bind was refused. |
How to fix it
Gate needs to reach a DC on 636 (LDAPS, Windows edition) or 389 (LDAP, Linux appliance; Gate always signs), plus 88 (Kerberos).
- On the domain controller: certlm.msc → Personal → Certificates should hold a Domain Controller or Kerberos Authentication certificate from your company CA (an AD CS enterprise CA issues these automatically).
- On the Gate server: the company CA must be in Trusted Root Certification Authorities (domain members get it by Group Policy).
- Check the firewall between Gate and the DCs.
Command line
Test-NetConnection dc1.corp.example -Port 636 # Windows Test-NetConnection dc1.corp.example -Port 88 nc -vz dc1.corp.example 389; nc -vz dc1.corp.example 88 # Linux
Related checks
Still stuck? Click Copy report on the Health check and send it to support@acutisgo.com. · Acutis Gate · Guides
Acutis