Oracle error
ORA-28030
ORA-28030: Server encountered problems accessing LDAP directory service
What usually causes it
The database couldn't reach or log in to the directory: a domain controller is down or unreachable on port 636, the wallet or dsi.ora is missing or in the wrong folder (check where CMU_WALLET points), the wallet doesn't trust the DC's certificate, or the service account's password changed.
What to check first
Check the wallet with orapki wallet display and the LDAPS connection with the openssl line in the wallet step. After fixing the wallet or dsi.ora, re-run ALTER SYSTEM SET LDAP_DIRECTORY_ACCESS = 'PASSWORD'.
Scripts that help
- CMU step 3: create the walletBuilds the auto-login wallet the database reads at login: the service account's user name, DN and password, plus the AD root certificate. With PDBs,…
- CMU step 4: create dsi.oraTells the database which domain controllers to use. Put it in the same folder as the wallet from step 3. Use fully qualified host names, and list at…
- CMU step 5: point each PDB at its wallet (CMU_WALLET)Creates a directory object for the wallet folder from step 3 and sets the CMU_WALLET database property in the PDB, so CMU reads that PDB's wallet and…
- CMU step 6: turn on directory accessSwitches the database to Active Directory for global users. In a CDB, run it in each PDB that uses CMU, not in the root: setting it in the root only…
- CMU step 8: check the setup and a loginShows the LDAP parameters, the CMU_WALLET location, the users and roles mapped to AD, and who the current session really is. Run it once as a DBA,…