In a LDAP Server, I see a warning log in Event Views regarding LDAP Interface. 
In this case, the warning is related to "binding performed without requesting 
signing". Our CAS is supposed to run on LDAPS with FastBinding. Would anyone 
explain what the warning message implies in term of binding CAS to LDAPS? For 
security, the message suggests to reject such binding.

----------------- warning message ---------------
During the previous 24 hour period, some clients attempted to perform LDAP 
binds that were either: 
(1) A SASL (Negotiate, Kerberos, NTLM, or Digest) LDAP bind that did not 
request signing (integrity validation), or 
(2) A LDAP simple bind that was performed on a cleartext 
(non-SSL/TLS-encrypted) connection 
 
This directory server is not currently configured to reject such binds.  The 
security of this directory server can be significantly enhanced by configuring 
the server to reject such binds.  For more details and information on how to 
make this configuration change to the server, please see 
http://go.microsoft.com/fwlink/?LinkID=87923. 
 
Summary information on the number of these binds received within the past 24 
hours is below. 
 
You can enable additional logging to log an event each time a client makes such 
a bind, including information on which client made the bind.  To do so, please 
raise the setting for the "LDAP Interface Events" event logging category to 
level 2 or higher. 
 
Number of simple binds performed without SSL/TLS: 0 
Number of Negotiate/Kerberos/NTLM/Digest binds performed without signing: 5
-- 
You are currently subscribed to [email protected] as: 
[email protected]
To unsubscribe, change settings or access archives, see 
http://www.ja-sig.org/wiki/display/JSG/cas-user

Reply via email to