Networking Forums

Networking Forums > Computer Networking > Windows Networking > Rejecting SASL LDAP

Reply
Thread Tools Display Modes

Rejecting SASL LDAP

 
 
Lee Jefferies
Guest
Posts: n/a

 
      07-05-2008, 11:37 PM
I am getting this warning in the event manager of Server 2008. I have
no idea where to go to fix the problem and the url given is not
functional. Can anyone help? I'm trying to learn Server 2008, so I'm
new at it...

The security of this directory server can be significantly enhanced by
configuring the server to reject SASL (Negotiate, Kerberos, NTLM, or
Digest) LDAP binds that do not request signing (integrity
verification) and LDAP simple binds that are performed on a cleartext
(non-SSL/TLS-encrypted) connection. Even if no clients are using such
binds, configuring the server to reject them will improve the security
of this server.

Some clients may currently be relying on unsigned SASL binds or LDAP
simple binds over a non-SSL/TLS connection, and will stop working if
this configuration change is made. To assist in identifying these
clients, if such binds occur this directory server will log a summary
event once every 24 hours indicating how many such binds occurred.
You are encouraged to configure those clients to not use such binds.
Once no such events are observed for an extended period, it is
recommended that you configure the server to reject such binds.

For more details and information on how to make this configuration
change to the server, please see
http://go.microsoft.com/fwlink/?LinkID=87923.

You can enable additional logging to log an event each time a client
makes such a bind, including information on which client made the
bind. To do so, please raise the setting for the "LDAP Interface
Events" event logging category to level 2 or higher.
 
Reply With Quote
 
 
 
 
Hellen K
Guest
Posts: n/a

 
      09-25-2008, 03:42 AM
I got the same error message too. Could anyone help us to give the solutions?

Thanks.

Hellen

------------------

"Lee Jefferies" wrote:

> I am getting this warning in the event manager of Server 2008. I have
> no idea where to go to fix the problem and the url given is not
> functional. Can anyone help? I'm trying to learn Server 2008, so I'm
> new at it...
>
> The security of this directory server can be significantly enhanced by
> configuring the server to reject SASL (Negotiate, Kerberos, NTLM, or
> Digest) LDAP binds that do not request signing (integrity
> verification) and LDAP simple binds that are performed on a cleartext
> (non-SSL/TLS-encrypted) connection. Even if no clients are using such
> binds, configuring the server to reject them will improve the security
> of this server.
>
> Some clients may currently be relying on unsigned SASL binds or LDAP
> simple binds over a non-SSL/TLS connection, and will stop working if
> this configuration change is made. To assist in identifying these
> clients, if such binds occur this directory server will log a summary
> event once every 24 hours indicating how many such binds occurred.
> You are encouraged to configure those clients to not use such binds.
> Once no such events are observed for an extended period, it is
> recommended that you configure the server to reject such binds.
>
> For more details and information on how to make this configuration
> change to the server, please see
> http://go.microsoft.com/fwlink/?LinkID=87923.
>
> You can enable additional logging to log an event each time a client
> makes such a bind, including information on which client made the
> bind. To do so, please raise the setting for the "LDAP Interface
> Events" event logging category to level 2 or higher.
>

 
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Rejecting packets from a given domain H.K. Kingston-Smith Linux Networking 7 04-16-2008 01:51 PM
failed to bind to LDAP server ldap://127.0.0.1: Confidentiality required Bjørn A. Linux Networking 0 02-05-2007 06:37 PM
Postfix + SASL [repost] Piotr Strycharz Linux Networking 2 05-24-2005 04:46 PM
Postfix + Sasl. Anyone succesful? Piotr Strycharz Linux Networking 0 05-20-2005 07:38 AM
Okay, I've got Postfix, SASL, Mysql and Courier-imap all installed Mark Adams Linux Networking 0 03-04-2004 12:57 AM



1 2 3 4 5 6 7 8 9 10 11