[mi-announce] Require LDAP signing for NETID AD: 10/11/2022

Microsoft Infrastructure Service Announcements mi-announce at u.washington.edu
Thu Jul 21 15:15:51 PDT 2022


What:
UW-IT will require LDAP signing for the NETID Active Directory.

When:
October 11, 2022

What you need to do:
Nothing. At this time, we are unaware of any unsigned LDAP activity.

More info:
Using LDAPS instead of LDAP has been recommended for many years. UW-IT has performed several campaigns to convert applications not using LDAPS which exposed UW NetID passwords on the network. LDAP and LDAPS are in containment and not recommended for application integration, but their use persists due to vendors who haven't adopted modern protocols and technologies. There should be no impact at the time of this change, and new applications won't have the option of a configuration which is inherently insecure.

The changes UW-IT will make in specific are:

* Change the Default Domain Controllers Policy, adding:
'Domain controller: LDAP server signing requirements'=Require signing per https://docs.microsoft.com/en-us/windows/security/threat-protection/security-policy-settings/domain-controller-ldap-server-signing-requirements
* Change the Default Domain Policy, adding
'Network security: LDAP client signing requirements'=Require signing per https://docs.microsoft.com/en-us/windows/security/threat-protection/security-policy-settings/network-security-ldap-client-signing-requirements

Brian Arkills
Microsoft Infrastructure service owner
UW-IT
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://mailman11.u.washington.edu/pipermail/mi-announce/attachments/20220721/318bfb72/attachment.html>


More information about the mi-announce mailing list