Troubleshooting LDAP integration via MID Server
Summarize
Summary of Troubleshooting LDAP integration via MID Server
This guide assists ServiceNow customers in diagnosing and resolving common issues encountered during LDAP integration via the MID Server. It focuses on using the External Communication Channel (ECC) Queue to monitor and validate LDAP connection tests, directory browsing, data import, and specific LDAP configuration settings.
Show less
Test Connection Issues
When testing LDAP connections within Organizational Units (OUs), the Test connection feature generates ECC Queue messages with the topic LDAPConnectionTesterProbe. A successful test is indicated by an input message with a Name value of true. Customers should drill down into the ECC Queue records to verify the payload for any error messages.
Browse Issues
The Browse feature in OU definitions shows LDAP directory records and produces ECC Queue messages with the topic LDAPBrowseProbe. A successful browse operation is confirmed by an input message showing true in the Name column. Reviewing the payload helps identify any underlying errors.
Load Import Issues
During data import (e.g., using the Test Load 20 Records function), the ECC Queue outputs messages named LDAPProbe and LDAPProbeCompleted. The Name field on the input messages indicates the number of records returned, with batch processing handled via multiple LDAPProbe messages if the record count exceeds the batch size (default 200). Customers should inspect these records for errors and monitor for any LDAPProbeError output messages to troubleshoot import failures.
LDAP Paging Configuration
LDAP paging requires alignment between the MID Server and LDAP server settings. If the LDAP server’s paging size is less than 1000, the MID Server property glide.ldap.maxresults must be set to a value less than or equal to the LDAP server’s paging size to ensure paging functions correctly.
Importing Binary Data via LDAP
To successfully import binary attributes such as user photos, the corresponding binary attribute (e.g., jpegphoto) must be included in the MID Server property glide.ldap.binaryattributes. This configuration enables the MID Server to handle binary data during LDAP imports.
You may encounter issues in the following areas while integrating LDAP via MID Server.
You can troubleshoot these issues by viewing the outputs found in the External Communication Channel (ECC) Queue ().
Test Connection Issues
Browse Issues
When defining OUs within the server, there is a Browse related list that is used to view the LDAP directory records that the OU definition returns. When you click this link, the ECC Queue should show a single output message with a topic name of LDAPBrowseProbe. After data has been returned from the MID Server, the ECC Queue should show an input message with the same topic name. If the Name column for the input message shows true, the test was successful. Drill down into the record to view the payload and ensure it does not contain error messages.
Load Import Issues
When uploading data (for example, using the Test Load 20 Records feature), the ECC Queue should show a single output message with a topic name of LDAPProbe.
After data has been returned from the MID Server, the ECC Queue should show another input message called LDAPProbeCompleted. The Name column for this input message shows the total number of records returned.
An additional input messages, also named LDAPProbe, is displayed. The Name column for this input message displays the highest record number in the batch. If the total number of records returned is 258 and the batch size is 200 (the default), two LDAPProbe (200, 258) incoming messages will be received, and one LDAPProbeCompleted (258) incoming message will be received.
Click the link in the Name column to view the details of the error.
LDAP paging
LDAP paging does not work if the paging size on the LDAP server is less than 1000. Set the MID Server property glide.ldap.max_results to a value less than or equal to the LDAP server paging size.
LDAP fails to import binary data
To import binary data via LDAP, such as a user photo, you must include the binary attribute in the MID Server property glide.ldap.binary_attributes. For the user photo example, the attribute may be jpegphoto.