Link to home
Start Free TrialLog in
Avatar of Hani_SA
Hani_SA

asked on

Configure LDAP over SSL Windows Server 2008 R2

Hey,

I have an Active Directory role running on windows server 2008 R2 accepting client connections over port 389.
I wish to enable SSL for this AD role by generating a certificate signed by CA and then passed to clients wishing to initiate authentication requests with my LDAP over port 636, other clients may still connect over non-SSL port.

Can you share detailed steps to accomplish this setup. (generate the certificate request, get it signed by CA then test ldp over port 636 ...)

Thanks in advance
ASKER CERTIFIED SOLUTION
Avatar of XcelogiX
XcelogiX

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
SOLUTION
Avatar of Aard Vark
Aard Vark
Flag of Australia image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of Hani_SA
Hani_SA

ASKER

Dear XcelogiX,

I already have a CA installed on another server different than the server where ADDS role installed, so how can I get the generate the certificate request and submit it to our CA for signing ???

Once LDAPS is configured will AD Server still be able to process authentication request from clients configured over non-ssl port:389 ??
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Hani_SA, how is your LDAPS setup going? Made any progress?
What do you mean there is not enough information to confirm an answer?
I believe I have answered the question comprehensively. I have provided in reply http://#a41728630:

- A full guide on how to setup LDAPS on a DC from the Microsoft Wiki.
- A secondary method via the Microsoft KB
- An article for information purposes from one of Microsoft's PKI experts.

I don't see how the answer could be any more comprehensive without going as far as to copy and paste the articles into the reply. So I believe my reply has answered the question.