Notice: This website is an unofficial Microsoft Knowledge Base (hereinafter KB) archive and is intended to provide a reliable access to deleted content from Microsoft KB. All KB articles are owned by Microsoft Corporation. Read full disclaimer for more details.

Frequently asked questions about changes to Lightweight Directory Access Protocol


View products that this article applies to.

Frequently asked questions

What resources should I read to prepare to successfully deploy LDAP Channel Binding and LDAP signing?

What issues do you foresee with enforcing LDAP signing?

LDAP Clients that do not enable or support signing will not connect.

LDAP Simple Binds over non-TLS connections will not work if LDAP signing is required.

What issues do you foresee with enforcing LDAP channel binding?

LDAP clients that connect over SSL/TLS, but do not provide CBT, will fail if the server requires CBT.

SSL/TLS connections that are terminated by an intermediate server that in turn issues a new connection to an Active Directory Domain Controller, will fail.

Support for channel binding maybe less common on third-party operating systems and applications than it is for LDAP signing.

Do new certificates have to be issued to use CBT over SSL/TLS?

No.

How do clients use SSL/TLS CBT, do I have to change the applications?

Windows applications that are built on .NET Framework, Active Directory Service Interfaces (ADSI), or make LDAP calls into WLDAP32 which handles LDAP signing and channel binding for you. Please contact your SDK equivalent for non- windows device O/S, service, and applications.

Does this mean we have to move all LDAP applications to port 636 and switch to SSL/TLS?

No. When SASL with signing is used, LDAP is more secure over port 389.

Does Channel Binding and Signing have to be configured on just the domain controller (DC), or both the DCs and clients?

The policies are enabled only on DCs.

↑ Back to the top


References

Third-party information disclaimer

The third-party products that this article discusses are manufactured by companies that are independent of Microsoft. We make no warranty, implied or otherwise, about the performance or reliability of these products.

We provide third-party contact information to help you find technical support. This contact information may change without notice. We do not guarantee the accuracy of this third-party contact information.

↑ Back to the top


Keywords: standalone informational, kbinfo, kbfaq

↑ Back to the top

Article Info
Article ID : 4546509
Revision : 28
Created on : 6/3/2020
Published on : 6/3/2020
Exists online : False
Views : 372