Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

Recommended Posts

Posted

Hi Everyone,

 

We are having issues with Ruckus AD authentication after upgrading our DCs to Windows Server 2025. The error we receive is admin invalid, I've had a look through various google search results and knowledge base articles and I can't find anything which says what this error actually means. Has anyone else encountered this? All admin details and AD details are exactly the same as before.

Posted
7 minutes ago, AdamD_Net-Ctrl said:

Hello,

 

I think LDAP gets disabled with server 2025 and you can only bind using LDAPs.

 

Is this to login to the controller or for auth to an SSID?

 

Adam

Just auth to an SSID. We use a local login for the unleashed controller.

Posted
Just now, Badaz52 said:

Just auth to an SSID. We use a local login for the unleashed controller.

Ok, I am guessing its a web auth ssid, I think its how sever 2025 works with LDAP

 

Edit this on your domain controller policy:

Domain Controller Policy
===Computer Configuration
======Policies
=========Windows Settings
============Security Settings
===============Local Policies
==================Security Options
=====================Domain controller: LDAP server channel binding token requirements: "When Supported"
=====================Domain controller: LDAP server signing requirements: "None"
=====================Domain controller: LDAP server Enforce signing requirements: "Disabled"
=====================Network security: LDAP client encryption requirements: "Negotiate Sealing"
=====================Network security: LDAP client signing requirements: "Negotiate Signing"

 

 

 

Posted (edited)

Should not need a admin account for LDAP/LDAPS auth, a bog standard Domain User account should be enough (certainly with the many services I have setup that use LDAP/S), I'd create a specific AD service account for it too and name appropriately so you know if you change password it will only be one thing effected.

 

Some devices can also be a bit of a mare to setup LDAPS, one of our devices we have to add an intermediate cert that is used on our LDAPS otherwise auth does not work

Edited by Davit2005

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...