> Source: [sk104785](https://support.checkpoint.com/results/sk/sk104785)

# sk104785 - "Binding to LDAP server: Failed to check ssl" error

| Property | Value |
|----------|-------|
| Solution ID | sk104785 |
| Date Created | 2015-03-06 |
| Last Modified | 2023-07-24 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R81.20, R81.10 (EOS), R81 (EOS) |

## Symptoms

- * Connection to port 636 fails with "Binding to LDAP server: Failed to connect to LDAP Server - the server might be down or the IP is wrong".  

* Adding an LDAP server to an Account Unit fails with "Binding to LDAP server: Failed to check ssl"  

* Fetching the fingerprint fails with "Error fetching fingerprints - Failed to connect to LDAP Server SSL connection failed to ckpSSL ssl lib error"  

* Output of test_ad_connectivity shows:  

  `:status (SUCCESS_WMI)`  
  `
  :err_msg (ADLOG_SUCCESS LDAP_STRONG_AUTH_REQUIRED)`  
  `
  :ldap_status (LDAP_STRONG_AUTH_REQUIRED)`  
  `
  :wmi_status (ADLOG_SUCCESS)`

## Cause

The "LDAP server signing requirements" security setting on the Domain Controller is set to "Require signature". For additional information on this setting refer to [Domain controller: LDAP server signing requirements](https://technet.microsoft.com/en-us/library/cc778124(v=ws.10).aspx) article:

"If signing is required, then *ldap_simple_bind* and*ldap_simple_bind_s requests* are rejected."

**Note:** This setting also applies on Windows Server 2008. Server 2012, and Server 2016.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
