ActiveDirectory


hello togehter,

is possible disable bloody warning?:

event id: 2887
event source: activedirectory_domainservice
event type: warning
event description:
during previous 24 hour period clients attempted perform ldap binds either:
(1) sasl (negotiate kerberos ntlm or digest) ldap bind did not request signing (integrity validation) or
(2) ldap simple bind performed on cleartext (non-ssl/tls-encrypted) connection

directory server not configured reject such binds.  the security of directory server can enhanced configuring server reject such binds.  for more details , information on how make configuration change server please see http://go.microsoft.com/fwlink/linkid=87923.

summary information on number of these binds received within past 24 hours below.

can enable additional logging log event each time client makes such bind including information on client made bind.  to please raise setting "ldap interface events" event logging category level 2 or higher.

 

thanks helps

 

subash

the warning due client not using ldap on ssl, due credentials transmitted in clear text, might imlement ldap on ssl or ignore warning.

event id 2887 — ldap signing

http://technet.microsoft.com/en-us/library/dd941856%28ws.10%29.aspx

previous discussion

http://social.technet.microsoft.com/forums/en/winservergen/thread/c8885b99-6f2b-4877-a8ea-624b19e42b5e

 

regards


awinish vishwakarma

mvp-directory services

my blog:  http://awinish.wordpress.com

this posting provided as-is no warranties/guarantees , confers no rights.



Windows Server  >  Directory Services



Comments

Popular posts from this blog

more indexes

Page indexing