Security settings blocking LDAP responses??

From: Paul Greene (techlists_at_comcast.net)
Date: 09/01/05

  • Next message: Derick Anderson: "RE: Group Policy: multiple password policies in the same domain?"
    Date: Thu, 01 Sep 2005 16:17:54 -0400
    To: focus-ms@securityfocus.com
    
    

    We have a VDS server running on a Solaris box that sends LDAP queries to
    a Win2k domain controller on port 389. The domain controller is
    responding to the LDAP request with the following error message:

    "The server requires binds to turn on integrity checking if SSL\TLS are
    not already active on the connection, data 0, v893"

    I have disabled, or set to "not defined", the following security
    settings, and run the command "secedit /refreshpolicy machine_policy
    /enforce" after making the changes:

    Synchronize directory service data
    Network security: LDAP client signing requirements
    Domain controller: LDAP server signing requirements

    Any idea what other possible security setting could be causing a hangup
    here? Or maybe something besides a security setting?

    PG

    ---------------------------------------------------------------------------
    ---------------------------------------------------------------------------


  • Next message: Derick Anderson: "RE: Group Policy: multiple password policies in the same domain?"

    Relevant Pages

    • Re: Authenticating Windows 2003 users to a central LDAP
      ... The Domain Controller itself contains a LDAP ... We are running a Windows 2003 R2 server whose domain ... and workstation authentication for a portion of the ...
      (comp.protocols.kerberos)
    • Multiple NICs in DNS server causes invalid IP in DomainDNSZones
      ... We have 3 sites, with one domain controller ... Each DC also serves as a DNS server. ... Weblogic performs a lookup on DomainDNSZones.domain.com to find an LDAP ...
      (microsoft.public.windows.server.dns)
    • Re: LDAP query
      ... > If not you won't be able to perform any LDAp search against this server - ... > try pointing the Canon copier to a domain controller. ...
      (microsoft.public.exchange2000.active.directory.integration)
    • DC not responding
      ... When ever I reboot my FSMO DC my Exchange 2003 server gives LDAP ... All Domain Controller Servers in use are not responding: ...
      (microsoft.public.win2000.general)
    • Re: Does samba 3.0.14Aa on OS 5.0.6 work with ldapsam backend on another LDAP server?
      ... used 3.0.9 on SCO 5.0.6 for quite some time after suffering problems I ... a RedHat4 box running samba 3.0.10 and OpenLDAP 2.2.13. ... and no LDAP server (although there were the ... share on the SCO server without any smbpasswd on that server! ...
      (comp.unix.sco.misc)