Secure LDAP question


hi, have off-site application authenticating via secure ldap our ad domain controllers.  i have no clue how set up.  i did read through kb321051, raises more questions answers.  some of question are:

1) have other apps use ldap (unsecure).  will these break when install cert?

2) cert need installed on domain controllers, or one?  the configuration of external app allows point @ 1 ip address.

3) our domain mycompany.int.  it turns out .int domain protected.  usually it's not problem because never reference domain internet.  but i'm wondering if problem cert, dc's fqdns dc1.mycompany.int.  we of course have public domain - mycompany.com.  can make public dns records (dc1.mycompany.com) , use generating csrs?

4) finally, i'm wondering of hidden gotchas might be.  will else in ad break?  exchange?

thanks!

hi,

> 1) have other apps use ldap (unsecure). these break when install cert?

no. after enable ldap on ssl, dc still support normal ldap connection request.

> 2) cert need installed on domain controllers, or one? configuration of the
> external app allows point @ 1 ip address.

you can enable ldap on ssl on 1 of dcs. why not enable ldap on ssl on dcs, encrypt dcs’ ldap communications.

> 3) our domain mycompany.int. turns out .int domain protected. it's not problem
> because never reference domain internet. i'm wondering if problem with
> cert, dc's fqdns dc1.mycompany.int. of course have public domain -
> mycompany.com. can make public dns records (dc1.mycompany.com) , use generating
> csrs?

this not question, since can request certificate custom subject alternative name (san). use of sans in server authentication certificates enables single certificate bound multiple names on single computer.

> 4) finally, i'm wondering of hidden gotchas might be. else in ad break?
> exchange?

no, enable ldap on ssl (port 636), ldap service still listen port 389 , support normal ldap connection request.

for more information please refer following ms articles:

ldap on ssl (ldaps) certificate
http://social.technet.microsoft.com/wiki/contents/articles/2980.ldap-over-ssl-ldaps-certificate.aspx
how enable ldap on ssl third-party certification authority
http://support.microsoft.com/kb/321051


lawrence

technet community support



Windows Server  >  Security



Comments

Popular posts from this blog

some help on Event 540

WMI Repository 4GB limit - Win 2003 Ent Question

Event ID 1302 (error 1307) DFS replication service encountered an error while writing to the debug log file