> Source: [sk161112](https://support.checkpoint.com/results/sk/sk161112)

# sk161112 - "Failed to connect to Active Directory using SSL"  certificate error when trying to add organization directory scanner in SmartEndpoint

| Property | Value |
|----------|-------|
| Solution ID | sk161112 |
| Date Created | 2019-08-22 |
| Last Modified | 2022-01-25 |
| Technical Level | Advanced |
| OS | Gaia |

## Symptoms

- * "Failed to connect to Active Directory using SSL. The SSL certificate is not installed on the Endpoint Security Management server" certificate error when trying to add organization directory scanner in SmartEndpoint when "SSL enabled" option is unchecked. ![](https://sc1.checkpoint.com/sc//SolutionsStatics/NEW_SK_NOID1566460883756/keniv21908220106.JPG)

* The *$UEPMDIR/logs/server_messages.log* shows this exception:   
  `INFO Dispatcher-Thread-9 - Cannot connect to current search base LDAP:someserver.local:389 on get top level hierarchy. `  
  `Authentication failed. Possible reasons: `  
  `(1) The LDAP server is configured to accept only strong authentication such as SSL. `  
  `(2) The DS requested an operation that requires strong authentication. (FilteredDirectorySearch)`

## Cause

Active Directory is configured to disable insecure connections.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
