LDAP Server Signing requirements
dear all,
until have been running 2 windows server 2008 r2 active directory domain controllers "domain controller: ldap server signing requirements" not defined (which same none) due fact allowed authentication our web server's content management system (squiz matrix if need know). i followed instructions in
http://technet.microsoft.com/en-us/library/dd941856(v=ws.10).aspx
to enable logging of 2889 events (where server allowed client ldap bind without requiring signing , sending passwords in cleartext!). showed our cms servers were indeed doing of unsigned binding expected.
it seems the preferred solution enable ldap on ssl, which implies getting certificate each of domain controllers, setting "domain controller: ldap server signing requirements" required, , configure cms use ldap on ssl. prompts me ask couple of questions:
1) if cms servers appear in 2889 events, mean ones binding without signing; far i have not got ldap on ssl enabled, , if none of member servers , desktops in domain appear there, how signing, because not doing against certificate have not created far?
2) using self-signed certificate in domain controllers cause problems?
thank help.
yours,
fd
hi,
based on research, using self-signed certificate ldap signing work, though not secure enough. it’s better install formatted certificate either microsoft certification authority (ca) or non-microsoft ca.
here related links below suggest refer to:
how enable ldap on ssl third-party certification authority
http://support.microsoft.com/kb/321051
windows server 2008 - enable ldap on ssl
ldap server signing requirement
ldap on ssl (ldaps) certificate
http://social.technet.microsoft.com/wiki/contents/articles/2980.ldap-over-ssl-ldaps-certificate.aspx
i hope helps.
amy wang
                                                                          Windows Server                                                     >                                                                 Directory Services                                                                           
 
 
  
 
Comments
Post a Comment