Min Security Rights to Preform LDAP Queries in Active Directory

血红的双手。 提交于 2019-12-10 16:23:35

问题


Our company is trying to implement a few single sign-on applications using Active Directory (Windows Server 2003) and LDAP. I would like to lock down the account used to make these LDAP queries as much as possible. What is the best practice for configuring this type of account?


回答1:


You can restrict/allow what a user can or see/query within AD by easily using the Delegation Wizard. You can access the Delegation Wizard easily by right-clicking on an OU, and the selecting Delegation Control. You als may want to take a look at these articles:

Default security concerns in Active Directory delegation

Best practices for delegating Active Directory administration: How delegation works in Active Directory

Best practices for delegating Active Directory administration: Case study: a delegation scenario




回答2:


Please see How to configure Active Directory to allow anonymous queries for minimum security.

By default, the Microsoft LDAP implementation does not support Secure LDAP. To setup secure LDAP using SSL, certificates must be installed on both the LDAP Server and the LDAP Client(s). In many cases, the LDAP Server is the domain controller running Active Directory.

The certificates required to run secure LDAP using SSL can be configured in several ways. The concept is always the same:

  • The Active Directory domain controller uses a special certificate that is issued by a trusted certification authority.
  • The clent computer trusts the certification authority that issues the certificate to the Active Directory domain controller.


来源:https://stackoverflow.com/questions/823184/min-security-rights-to-preform-ldap-queries-in-active-directory

易学教程内所有资源均来自网络或用户发布的内容,如有违反法律规定的内容欢迎反馈
该文章没有解决你所遇到的问题?点击提问,说说你的问题,让更多的人一起探讨吧!