TLS 1.0 versus 1.1/2 in SLDAP
my company wants stop using all encryption protocols except tls1.2. have 2008r2 dcs ssl 2/3 disabled, with tls1.0, 1.1 , 1.2 enabled. have windows 2008r2 , 2012 standard member servers ssl disabled , 3 tls versions enabled. i now testing performing sldap connections (using ldp.exe) clients dcs. in testing, @ point disabling/enabling the encryption protocols on client servers, not dcs. connections successful long as tls1.0 enabled. if disable tls1.0, leave tls 1.1 and/or tls 1.2 enabled, connection fails.
all ciphers/hashes have been left @ default install state, , have valid dc certificate on dc.
can me understand why, , achieve goal of tls 1.2 enabled on dcs , client/member servers?
tony auby
Windows Server > Directory Services
Comments
Post a Comment