The exception is [LDAP: error code 49 - 80090308: LdapErr: DSID-0C090334, comment: AcceptSecurityContext error, data 775, vece ].

Indicates that the results of a compare operation are true. 7 LDAP_AUTH_METHOD_NOT_SUPPORTED Indicates that during a bind operation the client requested an authentication method not supported by the LDAP server. 8 This generally indicates that a referral loop was encountered, in which attempting to follow a referral ends eventually causes the client to encounter the same referral multiple times. 97: Referral Limit This result code is set when the client parsing a server response for controls and not finding the requested controls 0x5e 94 LDAP_NO_RESULTS_RETURNED: Indicates no results were returned from the server. For example, it may be used if a client sends a non-bind request in the middle of a multi-stage bind operation.

constraintViolation (19) Indicates that the client supplied an attribute value that does not conform to the constraints placed upon it by the data model. For example, this code is returned when multiple values are supplied to an attribute that has a SINGLE-VALUE constraint.

saslBindInProgress (14) Indicates the server requires the client to send a new bind request, with the same SASL mechanism, to continue the authentication process (see RFC4511 Section 4.2). The client returns a DN and a password for a simple bind when the entry does not have a password defined. 0x31 49 LDAP_INVALID_CREDENTIALS: Indicates during a bind operation one of

This is not the intended use for this result code (the "other" result is a better choice for this), but clients may need to be aware of this possibility. 2: Protocol

Data 775 The user account is locked Unlock the user account from the user's "Account" tab in Active Directory PKIX Path Building Failed while connecting to Secure LDAP (LDAPS) This error For example, this may be used if the attribute type does not have an appropriate matching rule for the type of matching requested for that attribute. 19: Constraint Violation This indicates

H.27. More about the author Check that you can log in as that user in another system that is connected to the same LDAP engine. H.19. H.41. Ldap Error Code 32

Reset the computer password on the primary domain controller (PDC) emulator by using the following command:

Netdom resetpwd /server:PDCE /userd:ms\admin /passwordd:* 
Synchronize Domain NC (from PDC emulator), Schema NC, and Configuration

Symptom Generally, error references SECJ0369E and SECJ0055E will be generated in the SystemOut.log. entryAlreadyExists (68) Indicates that the request cannot be fulfilled (added, moved, or renamed) as the target entry already exists.

This is an issue with the specific LDAP user object/account which should be investigated by the LDAP administrator. 49 / 701 ACCOUNT_EXPIRED Indicates an Active Directory (AD) AcceptSecurityContext data error that From SystemOut.log: [date/time] 0000000a LdapRegistryI A SECJ0419I: The user registry is currently connected to the LDAP server ldap://:389. [date/time] 0000000a LTPAServerObj E SECJ0369E: Authentication failed when using LTPA.

unavailableCriticalExtension (12) Indicates a critical control is unrecognized (see RFC4511 Section 4.1.11). In the example above all we would need to do to fix the issue is use dc=com instead of dc=con). Will prevent most other errors from being displayed as noted. 80090308: LdapErr: DSID-0C09030B, comment: AcceptSecurityContext error, data 530, v893 HEX: 0x530 - not permitted to logon at this time DEC: 1328

If the operation is a search, the results will be incomplete. This error is returned for the following reasons: The add entry request violates the server's structure rules...OR...The modify attribute request specifies attributes that users cannot modify...OR...Password restrictions prevent the action...OR...Connection restrictions This may also indicate that the client attempted to perform anonymous authentication when that is not allowed. 49: Invalid Credentials This indicates that the client attempted to bind as a user

These client-side result codes include those listed below: 81: Server Down This generally indicates that a previously-established connection is no longer valid. This often means that the server had already completed processing for the operation by the time it received and attempted to process the cancel request. 120: Too Late This indicates that

17 One of the attributes specified in the configuration Note that this result code can only be used if the server is able to at least partially decode the request in order to determine the message ID and operation type,

NoSuchAttributeException 17 An undefined attribute type. Verify DNS for local, problem, or replica domain controllers.Stop or disable KDC.