Support for secure LDAP in Active Directory
Overview
Cayosoft Administrator uses Lightweight Directory Access Protocol (LDAP) to read data and write data to and from Active Directory. You can enable support for secure LDAP (LDAPS) to establish secure communication in your AD environment and prevent exposure of data sent via LDAP. This article covers prerequisites to enable LDAPS, steps to enable the protocol, and additional information to troubleshoot related issues in your environment.
NOTE: LDAPS applies only to direct LDAP and global catalog connections that Cayosoft Administrator uses. It does not change the transport used by Active Directory cmdlet operations, which continue to use Active Directory Web Services (ADWS) on port 9389 regardless of the setting.
Prerequisites
IMPORTANT: Cayosoft Administrator does not provide an LDAP fallback option when you enable LDAPS. If your environment is not ready for LDAPS, connection will fail with a corresponding error.
A valid certificate installed on each domain controller, including the global catalog server.
A certificate chain that the server running Cayosoft Administrator trusts, so it can validate the certificate presented by each domain controller and the global catalog server.
Reachable TCP ports 636 and 3269 on both DC and GC servers.
For additional information on enabling LDAPS in your environment, refer to the following article: Enable LDAP over SSL with a third-party certification authority.
Enable LDAPS in Cayosoft Administrator
Start the Cayosoft Administrator console.
In the left pane, navigate to Configuration > Connected System Extensions > Active Directory.
In the Advanced settings section, locate the Enable LDAPS setting (labeled Use secure LDAP (LDAPS) for direct LDAP connections) and set the value to Yes. The default value is No, which preserves existing connection behavior for both new and upgraded installations. This setting is not available in the initial Configuration Wizard and must be configured here after setup.
Click Save changes. Cayosoft Administrator rebuilds its PowerShell sessions, as it does for other advanced settings changes, and will prompt you to verify the connection by running a setting check.
IMPORTANT: Do not enter port numbers (such as :636 or :3269) in managed domains for DC, Alt DC, GC, or Alt GC fields. These fields must contain host names only, for example dc1.contoso.com. When Enable LDAPS is set to Yes, Cayosoft Administrator automatically uses port 636 for covered direct LDAP connections and port 3269 for covered direct global catalog connections. If you enter an explicit port in one of these fields, that port is used instead of the default for direct LDAP connections; this will affect Active Directory cmdlet (ADWS) calls that use the same field.
Troubleshooting
When you enable the feature in the environment with misconfigured secure LDAP, one of the following errors may be prompted:
Error: Unable to contact the server %FQDN% on port 636/3269 over secure LDAP (LDAPS).
LDAPS may not be configured correctly on the domain controller.
Verify that LDAPS is enabled and that a valid trusted server certificate is installed.
Credentials may also be invalid.
Unable to contact the Global Catalog server %FQDN% on port 636/3269 over secure LDAP (LDAPS).
LDAPS may not be configured correctly on the domain controller.
Verify that LDAPS is enabled and that a valid trusted server certificate is installed.
Credentials may also be invalid.Review possible causes:
No valid certificate is present on the affected domain controller (including the global catalog server).
The certificate authority is not trusted by the Cayosoft Administrator server.
The LDAPS ports cannot be reached from the Cayosoft Administrator server.
LDAPS ports are indicated in the Managed domains table.
The connection account credentials for the Active Directory extensions are invalid.
Comments
0 comments
Please sign in to leave a comment.