Inedo Community Forums Forums
    • Recent
    • Tags
    • Popular
    • Login

    Welcome to the Inedo Forums! Check out the Forums Guide for help getting started.

    If you are experiencing any issues with the forum software, please visit the Contact Form on our website and let us know!

    The remote certificate was rejected by the provided RemoteCertificateValidationCallback

    Scheduled Pinned Locked Moved Support
    7 Posts 2 Posters 22 Views 1 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • C Offline
      carl.westman_8110
      last edited by carl.westman_8110

      Hi there!

      We're trying to setup LDAPS configuration towards Azure AD so that we can put the right permission on people when they login with SAML to Proget :) but we get some wierd error messages right now which we cannot figure out, anyone here have any idea? See the picture below.

      9668483a-45b1-4a35-93b7-fdb491009d8f-MicrosoftTeams-image (2).png

      Fyi, we are hosting our Proget as a web app in Azure with the Docker container and a functioning certificate.

      12152ce0-5844-4e1c-972b-e090efccffc6-image.png

      Kind regards
      Carl

      https://github.com/Wesztman

      1 Reply Last reply Reply Quote 0
      • Dan_WoolfD Offline
        Dan_Woolf inedo-engineer
        last edited by

        Hi @carl-westman_8110,

        The rejected certificate was from your Active Directory provider, not the Azure Web App itself. This is normally due to Active Directory generating its own certificates. I'm not exactly sure how to trust them in Azure, but it looks like you can register CA certificates on an Azure Web App using Microsoft's documentation: https://learn.microsoft.com/en-us/azure/app-service/configure-ssl-certificate-in-code

        As an alternative, you can edit your User Directory in ProGet and on the Connection tab, you can change to "Use LDAPS and bypass the certificate errors". That will allow ProGet to bypass the certificate validation process.

        Thanks,
        Dan

        1 Reply Last reply Reply Quote 0
        • C Offline
          carl.westman_8110
          last edited by

          Thanks @Dan_Woolf!

          Will try to add the certificate according to the guide :) do I need to follow this guide after I have the certificate available in the web app env?

          https://docs.inedo.com/docs/installation-linux-https-support#configuring-https-without-a-reverse-proxy

          https://github.com/Wesztman

          1 Reply Last reply Reply Quote 0
          • Dan_WoolfD Offline
            Dan_Woolf inedo-engineer
            last edited by

            Hi @carl-westman_8110,

            I didn't realize how you were running ProGet. Are you currently running the ProGet Docker Image using an Azure App Service?

            Thanks,
            Dan

            1 Reply Last reply Reply Quote 0
            • C Offline
              carl.westman_8110
              last edited by

              Ahh sorry, should have mentioned that, I'm running Proget as an Azure App Service yes :)

              416a0f8f-11a1-44fb-92ce-f7b95e1c0d17-Screenshot from 2023-10-11 10-14-19.png

              1496fb6e-1cf0-4dca-9319-3d0f99d5ddcc-Screenshot from 2023-10-11 10-18-29.png

              https://github.com/Wesztman

              1 Reply Last reply Reply Quote 0
              • Dan_WoolfD Offline
                Dan_Woolf inedo-engineer
                last edited by

                Hi @carl-westman_8110,

                Thanks for clarifying that for me. So that changes things a bit. When it comes to the LDAPS issue, the original suggestion for adding the certificate will not work. The LDAPS certificate needs to be added directly to the trusted certificates in the Container, not the app service. We don't have much advice on this as of yet, but let me talk internally on this and see what my colleagues say.

                As for the actual SSL certificate in ProGet, you will need to follow the Configuring HTTPS without a Reverse Proxy guide in the Linux HTTPS Support. That will show you how to configure the SSL certificate within the container itself and not the app service. We also have more guidance on converting certificate files to different formats at the bottom of our HTTPS support on Windows documentation.

                Thanks,
                Dan

                1 Reply Last reply Reply Quote 0
                • C Offline
                  carl.westman_8110
                  last edited by carl.westman_8110

                  Hi Dan!

                  My IT department solved the issue for now by ignoring certificate errors for LDAPS as per your suggestion above 😊 while it would be nice to get it to work "correctly" i'll wait until there is a guide available on how to set it up to not have to ignore the errors 😊 Many thanks for all your help!

                  For future reference and people 😊

                  8858e4fd-80d1-491f-8c65-c559c7276ddd-image.png
                  f2ffb7da-c5f6-40b7-b246-a5efe8fcaaec-image.png

                  https://github.com/Wesztman

                  1 Reply Last reply Reply Quote 0

                  Hello! It looks like you're interested in this conversation, but you don't have an account yet.

                  Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.

                  With your input, this post could be even better 💗

                  Register Login
                  • 1 / 1
                  • First post
                    Last post
                  Inedo Website Home • Support Home • Code of Conduct • Forums Guide • Documentation