


In addition, the resolved LDAP server address must match the CN (common name) contained within the certificate presented by the LDAP server.

the LDAP server’s certificate must be signed by an authority within the Pexip Infinity trusted CA certificates store. To establish a TLS connection, the Pexip Infinity platform must trust the certificate presented by the LDAP server i.e. If that fails it may fall back to a TCP connection if allowed. The system always tries in the first instance to set up a TLS connection with the LDAP server. When resolving the LDAP server address, the system supports DNS SRV and DNS A/AAAA lookups. Note that all LDAP distinguished names must be entered as per the LDAP standard ( RFC 4514). This section explains how Pexip Infinity connects to the LDAP server, and provides guidance on how to troubleshoot connection problems.
