The VMware Knowledge Base provides support solutions, error messages and troubleshooting guides
Adding a vCenter Single Sign On Active Directory Identity Source fails with the LDAP error: The server requires binds to turn on integrity checking (2035934)
- Cannot add a vCenter Single Sign On (SSO) Active Directory Identity Source
- Adding an Active Directory Single Sign On Identity Source with a Primary Server URL starting with
- Test Connection fails with one of these errors:
[LDAP: error code 8 - 00002028: LdapErr: DSID-0C0901FC, comment: The server requires binds to turn on integrity checking if SSL\TLS are not already active on the connection, data 0, v1db1]
simple bind failed
A certificate that establishes trust for the LDAPS endpoint of the Active Directory server is required when you use
ldaps://in the primary or secondary LDAP URL.
- Log in to the vSphere Web Client using the
- Browse to Administration > Sign-On and Discovery > Configuration in the vSphere Web Client.
- Open the Edit Identity Source by right-clicking on the dialog of the Identity Source you want to edit.
- Change the URL from
A Choose Certificate button appears below the settings.
- Click Choose Certificate.
- Select the correct
.cerRoot CA certificate of your AD/OpenLdap Identity Source.
- Click Test Connection.
- Click OK.
To obtain the trust certificate for use with SSO, see the Exporting the LDAPS Certificate and Importing for use with AD DS section of LDAP over SSL (LDAPS) Certificate.
Note: The preceding links were correct as of November 21, 2012. If you find a link is broken, provide feedback and a VMware employee will update the link.
Request a Product Feature
To request a new product feature or to provide feedback on a VMware product, please visit the Request a Product Feature page.