> Source: [sk120669](https://support.checkpoint.com/results/sk/sk120669)

# sk120669 - Unable to add specific users during Access Role creation when using LDAP over SSL

| Property | Value |
|----------|-------|
| Solution ID | sk120669 |
| Date Created | 2017-09-26 |
| Last Modified | 2017-09-28 |
| Technical Level | Advanced |
| Products | Security Gateway, Security Management Server, SmartConsole, Multi-Domain Security Management Server |
| Versions | R82.10, R82, R81.20, R82.10, R82, R81.20, R82.10, R82.10, R82.20, R82.20, R82, R81.20, R81.20, R82, R82.20 |
| OS | Gaia |

## Symptoms

- * When creating or modifying an access role and trying to add specific users to the list, the list does not get populated
* There is a Red 'X' next to the domain name in the User Pick window, showing that we don't have connection to the DC

## Cause

**Environment:** The LDAP server used in the Account Unit's definition has been configured to use encryption on port **636** (LDAPs - LDAP over SSL) or **3269**(MS Global Catalog with LDAP SSL), and you are able to fetch the fingerprint successfully.

The 'User Pick' window tries to fetch the list of users directly from the LDAP server by establishing a connection between the SmartConsole machine where Dashboard is installed and the LDAP server on port **389**, even if the Account Unit's configuration has been set to use LDAP over SSL (ports 636 or 3269).

For some environments where LDAP over SSL is being used, it is still possible to add specific users when creating the Access Role, given that port 389 remains open on the LDAP server.

However, most of the time when LDAP over SSL has been enabled, access to port 389 on the LDAP server will be blocked, thus preventing Dashboard from obtaining the list of users when creating or modifying an access role.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
