# LDAPS Docker Container

**URL:** <https://forum.keycloak.org/t/ldaps-docker-container/3186>\
**Category:** Configuring the server\
**Tags:** ldap\
**Created:** [June 8, 2020, 7:11am UTC](https://forum.keycloak.org/t/ldaps-docker-container/3186 "2020-06-08T07:11:33Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![jominga](https://avatars.discourse-cdn.com/v4/letter/j/e56c9b/32.png) [@jominga](https://forum.keycloak.org/u/jominga)\
**Post date:** [June 8, 2020, 7:11am UTC](https://forum.keycloak.org/t/ldaps-docker-container/3186/1 "2020-06-08T07:11:33Z")

</div>

Hello,

I am trying to configure a User Federation using LDAPS with my Active Directory provider. I am using Keycloak in a Docker Container. When I try to authenticate I get the following error:

> ERROR [org.keycloak.services] (default task-2) KC-SERVICES0055: Error when authenticating to LDAP: simple bind failed: MY\_SERVER:636: javax.naming.CommunicationException: simple bind failed: MY\_SERVER:636 [Root exception is javax.net.ssl.SSLHandshakeException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: **unable to find valid certification path to requested target**]

I spoke to my Active Directory Provider and got 3 .cer files as certificates. They told me all 3 are necessary. But now I am unsure on how I should use them.

In the Keycloak Forum ([here](https://www.keycloak.org/docs/latest/server_admin/#openshift-4)) I found that I should configure the `X509_CA_BUNDLE` enviroment variable to be `/var/run/secrets/kubernetes.io/serviceaccount/ca.crt `. I could convert my .cer files to .crt files and copy them in that directory when creating the container, but this solution only works for one certificate if I am not mistaken.

How should I approach this?

---

<div class="post-metadata">

**Author:** ![jominga](https://avatars.discourse-cdn.com/v4/letter/j/e56c9b/32.png) [@jominga](https://forum.keycloak.org/u/jominga)\
**Post date:** [June 8, 2020, 8:55am UTC](https://forum.keycloak.org/t/ldaps-docker-container/3186/2 "2020-06-08T08:55:09Z")

</div>

Solved it by combining all the certificates into a .crt like shown [here](https://support.vidyocloud.com/hc/en-us/articles/115000460374-Combining-Root-and-Intermediate-Certificates#:~:text=To%20combine%20them%2C%20simply%20copy,end%20of%20the%20new%20filename.) and then importing it like stated in the Keycloak Documentation.

---

<div class="post-metadata">

**Author:** ![klepptor](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/klepptor/32/3470_2.png) [@klepptor](https://forum.keycloak.org/u/klepptor)\
**Post date:** [July 5, 2021, 7:48am UTC](https://forum.keycloak.org/t/ldaps-docker-container/3186/3 "2021-07-05T07:48:17Z")

</div>

Hi @jominga

I’m facing the same problem right now and I can’t figure out what to do using the official Keycloak documentation.

Using Docker-Compose I assume I have to simple mount the new Cert file into the container at the right place. The path you mentioned (/var/run/secrets/kubernetes.io/serviceaccount/ca.crt) doesn’t exist in my running container!?!?

Do you have any hint?

Thx

---

<div class="post-metadata">

**Author:** ![jominga](https://avatars.discourse-cdn.com/v4/letter/j/e56c9b/32.png) [@jominga](https://forum.keycloak.org/u/jominga)\
**Post date:** [July 5, 2021, 11:15am UTC](https://forum.keycloak.org/t/ldaps-docker-container/3186/4 "2021-07-05T11:15:49Z")

</div>

Hello,

Even if the path does not exist you can create it when specifying your volume in the docker-compose file.

Example:

```auto
version: "2.4"
services:
  web:
    image: nginx:alpine
    ports:
      - "80:80"
    volumes:
      - type: bind
        source: ./pathToCert
        target: /var/run/secrets/kubernetes.io/serviceaccount

networks:
  webnet:

volumes:
  mydata:

```

See [Compose file version 2 reference | Docker Documentation](https://docs.docker.com/compose/compose-file/compose-file-v2/#volumes)

---

<div class="post-metadata">

**Author:** ![klepptor](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/klepptor/32/3470_2.png) [@klepptor](https://forum.keycloak.org/u/klepptor)\
**Post date:** [July 7, 2021, 11:52am UTC](https://forum.keycloak.org/t/ldaps-docker-container/3186/5 "2021-07-07T11:52:04Z")

</div>

Thx.

Right now I just did:

keytool -import -trustcacerts -alias MYALAIS -file ./certs/myadcert.cer -keystore ./certs/cacerts

> mount self created Java Cert Store with own Root CA cert from Active Directory

```
volumes:
  - ./certs/cacerts:/etc/pki/java/cacerts

```

This works for me as I only need this single cert in the keystore.

---

<div class="post-metadata">

**Author:** ![nullr0ute](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/nullr0ute/32/4256_2.png) [@nullr0ute](https://forum.keycloak.org/u/nullr0ute)\
**Post date:** [October 28, 2021, 2:38pm UTC](https://forum.keycloak.org/t/ldaps-docker-container/3186/6 "2021-10-28T14:38:06Z")

</div>

I tried this approach, but I’m running into this error:

```auto
ERROR [org.keycloak.services] (default task-4) KC-SERVICES0055: 
Error when authenticating to LDAP: 
simple bind failed: <ldap-server-hostname>:636: 
javax.naming.CommunicationException: 
simple bind failed: <ldap-server-hostname>:636 [Root exception is 
javax.net.ssl.SSLException: Unexpected error: 
java.security.InvalidAlgorithmParameterException: 
the trustAnchors parameter must be non-empty]

```

Not sure on how to troubleshoot this. May be due to an incorrect password to the keystore? What should the password be?
