# Ldaps Configuration Error

**URL:** <https://forum.keycloak.org/t/ldaps-configuration-error/6680>\
**Category:** Configuring the server\
**Tags:** authentication, ldap\
**Created:** [January 6, 2021, 10:45am UTC](https://forum.keycloak.org/t/ldaps-configuration-error/6680 "2021-01-06T10:45:53Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![cresphontess](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/cresphontess/32/2046_2.png) [@cresphontess](https://forum.keycloak.org/u/cresphontess)\
**Post date:** [January 6, 2021, 10:45am UTC](https://forum.keycloak.org/t/ldaps-configuration-error/6680/1 "2021-01-06T10:45:53Z")

</div>

Hi,

I tried numerous method to configure ldaps but I couldn’t reach to any result that I want.

(My keycloak service running in a docker container)

First, I imported my root.cer to keystores as a below,

" keytool -import -alias myAlias -keystore /opt/jboss/keycloak/standalone/configuration/keystores/truststore.jks -file /etc/x509/https/root.cer -storepass changeit "

Then, I changed standalone-ha.xml file (I tried both WILDCARD and ANY options for hostname-verification-policy)

 ![Untitledwe](https://global.discourse-cdn.com/free1/uploads/keycloak/original/2X/0/0a2d48bebe82cf106b21b9fcdeda274b8f5e3f68.png)

But I encountered this error permanently when I pushed “Test Authentication” button

" **Error!** LDAP authentication failed. See server.log for details "

And these are the logs

10:45:40,061 ERROR [org.keycloak.services] (default task-17) KC-SERVICES0055: Error when authenticating to LDAP: simple bind failed: IP:636: javax.naming.CommunicationException: simple bind failed: IP:636 [Root exception is javax.net.ssl.SSLHandshakeException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target]

Caused by: javax.net.ssl.SSLHandshakeException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target

So, I am stuck in there, is there anyone who can help me?

Thank you so much.

---

<div class="post-metadata">

**Author:** ![johnsonj](https://avatars.discourse-cdn.com/v4/letter/j/41988e/32.png) [@johnsonj](https://forum.keycloak.org/u/johnsonj)\
**Post date:** [February 9, 2022, 6:55pm UTC](https://forum.keycloak.org/t/ldaps-configuration-error/6680/2 "2022-02-09T18:55:03Z")

</div>

Hey,

Did you ever find a solution to this issue? I am dealing with the same thing.
