Interested in a ServiceNow event built for developers? Registration for now[dev]26 is officially open!

LDAPS Connection Failing in ServiceNow After Certificate Renewal - Unable to Get Local Issuer Cert

Akshay42
Tera Contributor

Hello Experts,

We are configuring LDAPS integration between ServiceNow and an on-premises Active Directory environment.

 

Verify return code: 20 (unable to get local issuer certificate)
Show more lines

Actions Already Performed

  • Downloaded the latest certificate from the LDAP server.
  • Deactivated the old certificate record in ServiceNow.
  • Uploaded the newly issued server certificate.
  • Retested the connection.
  • The issue persists.

Observations

  • LDAPS is using TLS 1.2.
  • SSL handshake completes successfully.
  • Certificate validation continues to fail.
  • LDAP connectivity remains unsuccessful after replacing the certificate.

Questions

  1. If replacing the server certificate does not resolve the issue, could this indicate that the Root CA or Intermediate CA certificates are missing from the trust chain?
  2. Does ServiceNow require the complete certificate chain (Server, Intermediate, and Root certificates) to be imported and trusted?
  3. What is the best way to verify whether the LDAP server is presenting the full certificate chain?
  4. Has anyone experienced a similar issue where uploading a renewed server certificate was not sufficient and the Root/Intermediate certificates also needed to be imported?
  5. Are there any additional trust-store or certificate validation steps within ServiceNow that should be reviewed?

Additional Context

ServiceNow Support suggested importing the complete certificate chain. However, even after replacing the server certificate, the connection still fails.

We are trying to determine whether the root cause is:

  • Missing Root CA certificate
  • Missing Intermediate CA certificate
  • Incomplete certificate chain presented by the LDAP server
  • Another ServiceNow trust configuration issue

Any guidance from ServiceNow LDAP, PKI, or Active Directory experts would be greatly appreciated.

Thank you.

0 REPLIES 0