synaesthesia Posted January 28, 2020 Posted January 28, 2020 Hi, Just auditing any remaining systems we have using unsecure LDAP, and one stickler is Solus 3. Documentation all says it "may need the port open for LDAP" but it all also says "We can't be bothered to write proper documentation for all scenarios because we're too lazy" (or something to that exact effect) so doesn't specify whether it only works on unsecure LDAP or if it's using something else. Can't see anything in settings. Can anyone shed any light?
jthompson Posted January 28, 2020 Posted January 28, 2020 Do you happen to know which specific functionality of SOLUS3 is flagging up as using insecure LDAP?
synaesthesia Posted January 28, 2020 Author Posted January 28, 2020 Nothing is flagging up, I just need to confirm if it is or isn't even using LDAP at all. I vaguely recall setting something when it was originally installed but that was years ago and there's nothing in settings to suggest how it gets it's info from AD. The only hint is the documentation clearly stating it needs firewall port 389 open.
jthompson Posted January 28, 2020 Posted January 28, 2020 Have a look at this link... http://www.edugeek.net/forums/security/209848-2020-ldap-channel-binding-ldap-signing-requirement-windows.html#post1814621 That details turning on logging for this on your DCs. Once the logging is set up, you'll see '2889' events on your DC whenever insecure LDAP connections are made.
synaesthesia Posted January 28, 2020 Author Posted January 28, 2020 (edited) Aware of that, and couldn't get it to work so have just been going through services manually (We have all services inventoried and how they connect anyway, just some uncertainties like this where it isn't specifically stated). Might just firewall off that port and if it breaks Capita can ruddy fix it Edited January 28, 2020 by synaesthesia
mavhc Posted January 30, 2020 Posted January 30, 2020 I've left a query with our county support. Did anyone get any more info about what it's doing?
synaesthesia Posted January 30, 2020 Author Posted January 30, 2020 Not yet, still awaiting an answer from Capita. May just phone them
jthompson Posted January 30, 2020 Posted January 30, 2020 I'm not seeing any 2889 events for it here.
ass17 Posted January 30, 2020 Posted January 30, 2020 If all else fails have wireshark capture port tcp and udp on 389. Then go through the capture for the whole day [emoji6]
mavhc Posted February 28, 2020 Posted February 28, 2020 Phone call from County Support, who talked to Capita. Capita still have no clue whether their code actually uses LDAP, and had never heard of this upcoming change. Time to install a trampoline on this sinking ship
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now