The security of this directory server can be significantly enhanced by configuring the server to reject SASL<p align=left><font face=Arial size=2>I am getting this warning in my event logs. When I click on the link for How to make this configuration, the page is no longer available.</font></p> <p align=left> </p> <p align=left>Does anybody know how to do the changes?</p> <p align=left> </p> <p align=left>Thanks,</p> <p align=left>Paul</p> <p align=left><font face=Arial size=2></font> </p> <p align=left><font face=Arial size=2></font> </p> <p align=left><font face=Arial size=2>Log Name:      Directory Service<br>Source:        Microsoft-Windows-ActiveDirectory_DomainService<br>Date:          12/29/2007 9:18:31 AM<br>Event ID:      2886<br>Task Category: LDAP Interface<br>Level:         Warning<br>Keywords:      Classic<br>User:          ANONYMOUS LOGON<br>Computer:      &lt;ServerName&gt;</font></p> <p align=left><font face=Arial size=2>Description:<br>The security of this directory server can be significantly enhanced by configuring the server to reject SASL (Negotiate,  Kerberos, NTLM, or Digest) LDAP binds that do not request signing (integrity verification) and LDAP simple binds that  are performed on a cleartext (non-SSL/TLS-encrypted) connection.  Even if no clients are using such binds, configuring the server to reject them will improve the security of this server. <br> <br>Some clients may currently be relying on unsigned SASL binds or LDAP simple binds over a non-SSL/TLS connection, and will stop working if this configuration change is made.  To assist in identifying these clients, if such binds occur this  directory server will log a summary event once every 24 hours indicating how many such binds  occurred.  You are encouraged to configure those clients to not use such binds.  Once no such events are observed  for an extended period, it is recommended that you configure the server to reject such binds. <br> <br>For more details and information on how to make this configuration change to the server, please see <a title="http://go.microsoft.com/fwlink/?LinkID=87923" href="http://go.microsoft.com/fwlink/?LinkID=87923">http://go.microsoft.com/fwlink/?LinkID=87923</a>. <br> <br>You can enable additional logging to log an event each time a client makes such a bind, including information on which client made the bind.  To do so, please raise the setting for the &quot;LDAP Interface Events&quot; event logging category to level 2 or higher.</font></p>© 2009 Microsoft Corporation. All rights reserved.Fri, 13 Feb 2009 17:57:52 Z39e17bb4-029d-4880-9bcc-0723fea55fd2http://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/39e17bb4-029d-4880-9bcc-0723fea55fd2#39e17bb4-029d-4880-9bcc-0723fea55fd2http://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/39e17bb4-029d-4880-9bcc-0723fea55fd2#39e17bb4-029d-4880-9bcc-0723fea55fd2Paul024http://social.technet.microsoft.com/Profile/en-US/?user=Paul024The security of this directory server can be significantly enhanced by configuring the server to reject SASL<p align=left><font face=Arial size=2>I am getting this warning in my event logs. When I click on the link for How to make this configuration, the page is no longer available.</font></p> <p align=left> </p> <p align=left>Does anybody know how to do the changes?</p> <p align=left> </p> <p align=left>Thanks,</p> <p align=left>Paul</p> <p align=left><font face=Arial size=2></font> </p> <p align=left><font face=Arial size=2></font> </p> <p align=left><font face=Arial size=2>Log Name:      Directory Service<br>Source:        Microsoft-Windows-ActiveDirectory_DomainService<br>Date:          12/29/2007 9:18:31 AM<br>Event ID:      2886<br>Task Category: LDAP Interface<br>Level:         Warning<br>Keywords:      Classic<br>User:          ANONYMOUS LOGON<br>Computer:      &lt;ServerName&gt;</font></p> <p align=left><font face=Arial size=2>Description:<br>The security of this directory server can be significantly enhanced by configuring the server to reject SASL (Negotiate,  Kerberos, NTLM, or Digest) LDAP binds that do not request signing (integrity verification) and LDAP simple binds that  are performed on a cleartext (non-SSL/TLS-encrypted) connection.  Even if no clients are using such binds, configuring the server to reject them will improve the security of this server. <br> <br>Some clients may currently be relying on unsigned SASL binds or LDAP simple binds over a non-SSL/TLS connection, and will stop working if this configuration change is made.  To assist in identifying these clients, if such binds occur this  directory server will log a summary event once every 24 hours indicating how many such binds  occurred.  You are encouraged to configure those clients to not use such binds.  Once no such events are observed  for an extended period, it is recommended that you configure the server to reject such binds. <br> <br>For more details and information on how to make this configuration change to the server, please see <a title="http://go.microsoft.com/fwlink/?LinkID=87923" href="http://go.microsoft.com/fwlink/?LinkID=87923">http://go.microsoft.com/fwlink/?LinkID=87923</a>. <br> <br>You can enable additional logging to log an event each time a client makes such a bind, including information on which client made the bind.  To do so, please raise the setting for the &quot;LDAP Interface Events&quot; event logging category to level 2 or higher.</font></p>Sat, 29 Dec 2007 16:05:08 Z2007-12-29T16:05:08Zhttp://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/39e17bb4-029d-4880-9bcc-0723fea55fd2#c41cb3df-5e1c-4b50-abaa-8599a80f128ahttp://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/39e17bb4-029d-4880-9bcc-0723fea55fd2#c41cb3df-5e1c-4b50-abaa-8599a80f128aAaron Sankey -- Avanadehttp://social.technet.microsoft.com/Profile/en-US/?user=Aaron%20Sankey%20--%20AvanadeThe security of this directory server can be significantly enhanced by configuring the server to reject SASL<p>Paul,</p> <p align=left> </p> <p align=left>I have been looking for a written reason that you are running into this and how to get rid of it, and I cannot find one. <img alt=Sad src="http://forums.microsoft.com/MSDN/emoticons/emotion-6.gif"></p> <p align=left> </p> <p align=left>The things I am confident of:</p> <p align=left>In order to digitally sign an LDAP bind, you are going to need to get a certificate that has the purpose of digital signature.</p> <p align=left>In order to perform a simple LDAP bind over SSL/TLS you are going to need a cert that allows for network traffic encryption.</p> <p align=left> </p> <p align=left>You could do this with a single cert and the PKI infrastructure required to do this would be simple.  It would also greatly increase the security of your environment -- just like the warning states.  But, it is not something that should be undertaken trivially.  The PKI infrastructure that would be required to do this, and the best infrastructure for your environment may be different, so plan this carefully to avoid redoing a lot of work in the future!</p> <p align=left><font face=Arial size=2></font> </p> <p align=left>The things I am spitballing:</p> <p align=left>Deploying the certificates would ALLOW the server to do these things, but REQUIRING the server to do them is a different matter.</p> <p align=left>I have not had an opportunity to scour the expanded group policy to find all of the keys, but I am guessing that you can set this policy much like IPsec.  The deployment of certificates is most likely going to be a seperate set of tasks than the requiring of secure authentication...</p> <p align=left> </p> <p align=left>To conclude, as a security nut, I am a fan of machine certificates for authentication and signing.  However, they do add an overhead and an associated cost - just think about how much harder it is to clean up an environment if your certs become invalid because your CRLs fall off of the planet <img alt=Sad src="http://forums.microsoft.com/MSDN/emoticons/emotion-6.gif">.  Although the warning is correct - you could increase your security with the appropirate measures to lock down this DC - I am fairly certain that the associated costs could be allocated toward security initiatives that would give you more bang for your buck.</p> <p align=left> </p> <p align=left>Let me know if you find anything on this!!  This is something that I know I will run into often.</p> <p align=left> </p> <p align=left>Keep us posted,</p>Tue, 08 Jan 2008 16:44:47 Z2008-01-08T16:44:47Zhttp://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/39e17bb4-029d-4880-9bcc-0723fea55fd2#f7c6e4ab-7af8-41b3-8871-00a625a19e86http://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/39e17bb4-029d-4880-9bcc-0723fea55fd2#f7c6e4ab-7af8-41b3-8871-00a625a19e86Steve Linehan -http://social.technet.microsoft.com/Profile/en-US/?user=Steve%20Linehan%20-The security of this directory server can be significantly enhanced by configuring the server to reject SASL<p align=left><font face=Arial size=2>In Windows Server 2008 we added some additional logging around LDAP security to help customers identify if they have clients connecting to the directory without using LDAP signing or passing credentials in the clear via Simple LDAP binds without TLS/SSL.  The link is not live yet telling you how to configure your environment to be more secure and require it with the implications to downlevel or third party clients that may not support this requirement.  I expect this content to go live once Windows Server 2008 RTMs.  That being said LDAP Signing does not require a certificate, we can use other key material such as Kerberos tickets.  Until the documentation for Windows Server 2008 gets published you can find out more about enabling LDAP signing on the Server and Client sides in the following Knowledge Base Article: <a title="http://support.microsoft.com/kb/823659" href="http://support.microsoft.com/kb/823659">http://support.microsoft.com/kb/823659</a>.</font></p> <p align=left> </p> <p align=left>Thanks,</p> <p align=left> </p> <p align=left>-Steve</p>Thu, 10 Jan 2008 04:47:34 Z2008-01-10T04:47:34Zhttp://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/39e17bb4-029d-4880-9bcc-0723fea55fd2#5a48bc8f-b47c-450f-a669-684d0822d2aehttp://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/39e17bb4-029d-4880-9bcc-0723fea55fd2#5a48bc8f-b47c-450f-a669-684d0822d2aePaul024http://social.technet.microsoft.com/Profile/en-US/?user=Paul024The security of this directory server can be significantly enhanced by configuring the server to reject SASLThanks to you both. I'll check out the KB. <p align=left><font face=Arial size=2></font> </p>Thu, 10 Jan 2008 13:29:40 Z2008-01-10T13:29:40Zhttp://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/39e17bb4-029d-4880-9bcc-0723fea55fd2#368ef1c9-d9c8-4f13-a04a-1648d0d306ebhttp://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/39e17bb4-029d-4880-9bcc-0723fea55fd2#368ef1c9-d9c8-4f13-a04a-1648d0d306ebPronichkinhttp://social.technet.microsoft.com/Profile/en-US/?user=PronichkinThe security of this directory server can be significantly enhanced by configuring the server to reject SASL<p align=left><font face=Arial size=2>The KB article number for this changes should be KB935834. And it isn't still there. Even after WS2008 already RTMed.</font></p> <p> </p> <p align=left>Could you please publish at least kinda unofficial draft version in some blog?</p> <p align=left> </p> <p align=left>Thanks in advance.</p>Sat, 23 Feb 2008 14:26:39 Z2008-02-23T14:26:39Zhttp://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/39e17bb4-029d-4880-9bcc-0723fea55fd2#4e9a6b29-17db-44a5-8994-10a483b60e75http://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/39e17bb4-029d-4880-9bcc-0723fea55fd2#4e9a6b29-17db-44a5-8994-10a483b60e75boe_dhttp://social.technet.microsoft.com/Profile/en-US/?user=boe_dThe security of this directory server can be significantly enhanced by configuring the server to reject SASL Here it is JUNE and just about every link in my event viewer for Server 2008 still comes up with bubkis - any idea when some of these links might go live?   I don't like any events in my event viewer unfortunately they all link to non existent KB articles.Sat, 14 Jun 2008 13:04:51 Z2008-06-14T13:04:51Zhttp://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/39e17bb4-029d-4880-9bcc-0723fea55fd2#a1619674-1e7d-4260-9850-fa784e7b7561http://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/39e17bb4-029d-4880-9bcc-0723fea55fd2#a1619674-1e7d-4260-9850-fa784e7b7561Markus Schuhmacherhttp://social.technet.microsoft.com/Profile/en-US/?user=Markus%20SchuhmacherThe security of this directory server can be significantly enhanced by configuring the server to reject SASL Hello,<br><br>the link / KB Article still ain't working.Tue, 01 Jul 2008 07:44:31 Z2008-07-01T07:44:31Zhttp://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/39e17bb4-029d-4880-9bcc-0723fea55fd2#c47c16b7-448c-410b-b9bb-3ebbf464bafbhttp://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/39e17bb4-029d-4880-9bcc-0723fea55fd2#c47c16b7-448c-410b-b9bb-3ebbf464bafbMax Epromhttp://social.technet.microsoft.com/Profile/en-US/?user=Max%20EpromThe security of this directory server can be significantly enhanced by configuring the server to reject SASL This is coming from a rule security about non signed client. To resolve this you have to modify the strategy policy on Default Domain Controller Policy.<br>I found that but excuse my poor english.<br>So open Gpedit, found Default Domain Controller Policy Strategy.<br>In Computer Configuration<br>  ==&gt;Strategy<br>          ==&gt; Windows Parameters<br>                   ==&gt;Local Strategy<br>                           ==&gt;Security Options<br>                                   Here go to the line : Domain Controller : Conditions required for the signature of LDAP Server ( I hope this the exact traduction because i dont know the line on the Windows 2008 server) and modify the rule to accept the signature. (This is for server negociation)<br>Go also to the line : Network Security : Conditions required for the signature of LDAP Client and modify the rule to negociate the signature (This is for clients negociation)<br><br>That will modify the rule and propage this to the clients in the domain. After this only autorized servers and clients integrated before in the domain could connect in the domain, all others will not.<br><br>Hope this will be helpfull.<br><br>Explanations can be found in : <a href="http://support.microsoft.com/kb/823659">http://support.microsoft.com/kb/823659</a> but still have to search like always in KB.Wed, 23 Jul 2008 14:43:13 Z2008-07-23T14:43:13Zhttp://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/39e17bb4-029d-4880-9bcc-0723fea55fd2#1ca45ae8-e728-4108-9339-f0397d8b0c83http://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/39e17bb4-029d-4880-9bcc-0723fea55fd2#1ca45ae8-e728-4108-9339-f0397d8b0c83I installed vista on my binhttp://social.technet.microsoft.com/Profile/en-US/?user=I%20installed%20vista%20on%20my%20binThe security of this directory server can be significantly enhanced by configuring the server to reject SASL I cant find anything about Strategy, are you using some kind of strategy here?<br><br>Oh right got it!Tue, 05 Aug 2008 15:36:37 Z2008-08-05T15:54:55Zhttp://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/39e17bb4-029d-4880-9bcc-0723fea55fd2#36c2d46a-0cc8-4acb-9035-53ce5df11b4fhttp://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/39e17bb4-029d-4880-9bcc-0723fea55fd2#36c2d46a-0cc8-4acb-9035-53ce5df11b4fdsloyerhttp://social.technet.microsoft.com/Profile/en-US/?user=dsloyerThe security of this directory server can be significantly enhanced by configuring the server to reject SASL The two gpo's to configure to remove this warning are:<br><br>Computer Configuration&gt;Policies&gt;Windows Settings&gt;Security Settings&gt;Local Policies&gt;Security Options&gt; -- Network Security: LDAP client signing requirements = negotiate signing<br><br>Computer Configuration&gt;Policies&gt;Windows Settings&gt;Security Settings&gt;Local Policies&gt;Security Options&gt; -- Domain controller: LDAP server signing requirements = require signing<br><br>Hope this helps - You must have a thorough understanding of LDAP certificate management prior to this change as stated previously.<hr size="1" align="left" width="25%">dsloyerSun, 07 Sep 2008 06:06:08 Z2008-09-07T06:06:08Zhttp://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/39e17bb4-029d-4880-9bcc-0723fea55fd2#7ac605dd-86e8-435c-ad3a-57a5c1be76afhttp://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/39e17bb4-029d-4880-9bcc-0723fea55fd2#7ac605dd-86e8-435c-ad3a-57a5c1be76afDelmirahttp://social.technet.microsoft.com/Profile/en-US/?user=DelmiraThe security of this directory server can be significantly enhanced by configuring the server to reject SASL Hello<br><br>In my case those two rules are = NONE<br><br>And the second one I can not change it? Do you know why?<br><br><br>Delmira<br><br>Sun, 26 Oct 2008 03:03:13 Z2008-10-26T03:03:13Zhttp://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/39e17bb4-029d-4880-9bcc-0723fea55fd2#01dc6a9a-08e8-4348-810c-b8482deaafe3http://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/39e17bb4-029d-4880-9bcc-0723fea55fd2#01dc6a9a-08e8-4348-810c-b8482deaafe3GBMarylandhttp://social.technet.microsoft.com/Profile/en-US/?user=GBMarylandThe security of this directory server can be significantly enhanced by configuring the server to reject SASL I noticed these posts while working on an issue with some legacy systems.<br><br>Basically, I've got some Linux boxes that use Basic LDAP binds to our Windows 2003 servers.  I'm trying to raise the functional level to Windows 2008, and I'm noticing that when I point these Linux systems to the new Windows 2008 boxes... the simple LDAP binds no longer work.<br><br>Of course, I'm ALSO seeing the Event ID 2886 errors, which is fine for now.<br><br>Question:  Does anyone know what I need to change to allow SIMPLE LDAP BINDS to work against a Windows 2008 AD DC?<br><br>(This would be temporary until we get LDAPS up and running, or something like it... We're using IPSEC anyway... so the risk is minimal...)<br><br>GB <hr class=sig> GerhardTue, 09 Dec 2008 16:11:28 Z2008-12-09T16:11:54Zhttp://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/39e17bb4-029d-4880-9bcc-0723fea55fd2#bbeb4c52-05d9-4365-8fd8-b6d7a4e14644http://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/39e17bb4-029d-4880-9bcc-0723fea55fd2#bbeb4c52-05d9-4365-8fd8-b6d7a4e14644Henry Jerezhttp://social.technet.microsoft.com/Profile/en-US/?user=Henry%20JerezThe security of this directory server can be significantly enhanced by configuring the server to reject SASL The KB has been created and should now be available. You can access it directly at: <br><a href="http://support.microsoft.com/kb/935834">http://support.microsoft.com/kb/935834</a><br>Thank you and sorry for the delayFri, 13 Feb 2009 17:57:03 Z2009-02-13T17:57:03Z