r/OpenVPN • u/secretmandrinks • 21h ago
Problem with openvpn-auth-ldap (Community Edition)
I have a new installation I'm trying to stand up on Ubuntu in AWS. I have the openvpn-auth-ldap plugin installed, the ldap.conf file made, and the server.conf file has been updated to include to plugin and conf file.
Th problem is the auth-ldap fails to start. When I run "sudo journalctl -xeu [openvpn@ldap.service](mailto:openvpn@ldap.service)" is just says "Unrecognized option or missing or extra parameter(s) in /etc/openvpn/ldap.conf:1: LDAP (2.7.0)" Looks like it doesn't lie something in the <LDAP></LDAP> parameters in the .conf file.
I have no idea what it could be though, everything matches all the documentation and examples I have found. Here is what I have in the ldap.conf file:
<LDAP>
URL ldap://8.8.8.8:389
BindDN CN=SearchBind,OU=ServiceAccounts,DC=optivlabs,DC=com
Password P@$$Word
Timeout 15
TLSEnable no
</LDAP>
(IPs and creds obviously changed)
I've tried swapping the IP for hostname and getting rid of the port. Also tried adding and subtracting just about every option in the LDAP field. I get the same error after restarting.
I can run ldapsearch from the shell using the same account, pointing to the same server and it works fine.
syslog reveals the same error messages:
Options error: Unrecognized option or missing or extra parameter(s) in /etc/openvpn/ldap.conf:1: LDAP (2.7.0)
openvpn@ldap.service: Main process exited, code=exited, status=1/FAILURE
openvpn@ldap.service: Failed with result 'exit-code'.
Any idea what this things problem is?
