Solved

Google Apps Directory Sync LDAP port 389

Posted on 2010-08-20
6
1,498 Views
Last Modified: 2012-08-13
I'm configuring Google Apps Directory Sync and forward port 389 to my Active Directory server.

It works. But is this a security risk?

If yes, what are the steps/requirements for using LDAP+SSL for the connection?

0
Comment
Question by:TANGLAD
  • 3
  • 3
6 Comments
 
LVL 7

Accepted Solution

by:
Paul Tozer earned 500 total points
ID: 33483371
The issue would be that the password is sent as plain text so a packet sniffer could potentially get the password. Depending on how much priviliges you give the account used to read the LDAP, could be a security risk.

See http://support.microsoft.com/kb/321051 if you want to change your LDAP to use SSL, plus change your connection on Directory Sync to use port 636 instead of 389

Personally mine is set to use 389, and as our domain controller has outbound internet access I run the directory sync from it, negating the issue.
0
 
LVL 1

Author Comment

by:TANGLAD
ID: 33483386
I run the directory sync on the domain controller as well and I have forwarded port 389 to the dc.
Is that a risk?
0
 
LVL 7

Expert Comment

by:Paul Tozer
ID: 33483434
how do you mean you have forwarded port 389 on the dc.

all you need to do is set it as attached image, changing your base DN and authorised user

I can't see any security risk as it is done locally (so no network sniffing), and port 389 is open anyhow
Untitled.png
0
Want to promote your upcoming event?

Attending an event? Speaking at a conference? Or exhibiting at a tradeshow? Easily inform your contacts by using a promotional banner in your email signature. This will ensure your organization’s most important contacts are in the know.

 
LVL 1

Author Comment

by:TANGLAD
ID: 33483491
I did the forward in the firewall
0
 
LVL 7

Expert Comment

by:Paul Tozer
ID: 33483791
Don't do that, there is no need. That is a security risk

The directory sync reads the LDAP details locally and then uploads the information to Google/Postini through HTTP/S
0
 
LVL 1

Author Closing Comment

by:TANGLAD
ID: 33487284
Great. Thanks
0

Featured Post

Better Security Awareness With Threat Intelligence

See how one of the leading financial services organizations uses Recorded Future as part of a holistic threat intelligence program to promote security awareness and proactively and efficiently identify threats.

Join & Write a Comment

Resolve Outlook connectivity issues after moving mailbox to new Exchange 2016 server
Find out how to use Active Directory data for email signature management in Microsoft Exchange and Office 365.
In this video we show how to create a Shared Mailbox in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Recipients >> Sha…
To add imagery to an HTML email signature, you have two options available to you. You can either add a logo/image by embedding it directly into the signature or hosting it externally and linking to it. The vast majority of email clients display l…

760 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

20 Experts available now in Live!

Get 1:1 Help Now