Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

Google Apps Directory Sync LDAP port 389

Posted on 2010-08-20
6
Medium Priority
?
1,544 Views
Last Modified: 2012-08-13
I'm configuring Google Apps Directory Sync and forward port 389 to my Active Directory server.

It works. But is this a security risk?

If yes, what are the steps/requirements for using LDAP+SSL for the connection?

0
Comment
Question by:TANGLAD
  • 3
  • 3
6 Comments
 
LVL 7

Accepted Solution

by:
Paul Tozer earned 2000 total points
ID: 33483371
The issue would be that the password is sent as plain text so a packet sniffer could potentially get the password. Depending on how much priviliges you give the account used to read the LDAP, could be a security risk.

See http://support.microsoft.com/kb/321051 if you want to change your LDAP to use SSL, plus change your connection on Directory Sync to use port 636 instead of 389

Personally mine is set to use 389, and as our domain controller has outbound internet access I run the directory sync from it, negating the issue.
0
 
LVL 1

Author Comment

by:TANGLAD
ID: 33483386
I run the directory sync on the domain controller as well and I have forwarded port 389 to the dc.
Is that a risk?
0
 
LVL 7

Expert Comment

by:Paul Tozer
ID: 33483434
how do you mean you have forwarded port 389 on the dc.

all you need to do is set it as attached image, changing your base DN and authorised user

I can't see any security risk as it is done locally (so no network sniffing), and port 389 is open anyhow
Untitled.png
0
Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 
LVL 1

Author Comment

by:TANGLAD
ID: 33483491
I did the forward in the firewall
0
 
LVL 7

Expert Comment

by:Paul Tozer
ID: 33483791
Don't do that, there is no need. That is a security risk

The directory sync reads the LDAP details locally and then uploads the information to Google/Postini through HTTP/S
0
 
LVL 1

Author Closing Comment

by:TANGLAD
ID: 33487284
Great. Thanks
0

Featured Post

Get free NFR key for Veeam Availability Suite 9.5

Veeam is happy to provide a free NFR license (1 year, 2 sockets) to all certified IT Pros. The license allows for the non-production use of Veeam Availability Suite v9.5 in your home lab, without any feature limitations. It works for both VMware and Hyper-V environments

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Here in this article, you will get a step by step guidance on how to restore an Exchange database to a recovery database. Get a brief on Recovery Database and how it can be used to restore Exchange database in this section!
There can be many situations demanding the conversion of Outlook OST files to PST format and as such, there is no shortage of automated tools to perform this conversion. However, what makes Stellar OST to PST converter stand above the rest? Let us e…
To add imagery to an HTML email signature, you have two options available to you. You can either add a logo/image by embedding it directly into the signature or hosting it externally and linking to it. The vast majority of email clients display l…
how to add IIS SMTP to handle application/Scanner relays into office 365.
Suggested Courses

971 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question