LDAP Server Signing requirements


dear all,

until have been running 2 windows server 2008 r2 active directory domain controllers "domain controller: ldap server signing requirements" not defined (which same none) due fact allowed authentication our web server's content management system (squiz matrix if need know). i followed instructions in

http://technet.microsoft.com/en-us/library/dd941856(v=ws.10).aspx

to enable logging of 2889 events (where server allowed client ldap bind without requiring signing , sending passwords in cleartext!). showed our cms servers were indeed doing of unsigned binding expected.

it seems the preferred solution enable ldap on ssl, which implies getting certificate each of domain controllers, setting "domain controller: ldap server signing requirements" required, , configure cms use ldap on ssl. prompts me ask couple of questions:

1) if cms servers appear in 2889 events, mean ones binding without signing; far i have not got ldap on ssl enabled, , if none of member servers , desktops in domain appear there, how signing, because not doing against certificate have not created far?

2) using self-signed certificate in domain controllers cause problems?

thank help.

yours,

fd

hi,

based on research, using self-signed certificate ldap signing work, though not secure enough. it’s better install formatted certificate either microsoft certification authority (ca) or non-microsoft ca.

here related links below suggest refer to:

how enable ldap on ssl third-party certification authority

http://support.microsoft.com/kb/321051

windows server 2008 - enable ldap on ssl

http://social.technet.microsoft.com/forums/windowsserver/en-us/be63bfb5-6578-4590-8369-4488e9952750/windows-server-2008-enable-ldap-over-ssl?forum=winserverds

ldap server signing requirement

http://social.technet.microsoft.com/forums/en-us/e242fc9b-ed7e-4f78-b0b2-a1d9745e869e/ldap-server-signing-requirement

ldap on ssl (ldaps) certificate

http://social.technet.microsoft.com/wiki/contents/articles/2980.ldap-over-ssl-ldaps-certificate.aspx

i hope helps.

amy wang



Windows Server  >  Directory Services



Comments

Popular posts from this blog

CRL Revocation always failed

Failed to query the results of bpa xpath

0x300000d errors in Microsoft Remote Desktop client