<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: unsigned LDAP in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/unsigned-ldap/m-p/309910#M80272</link>
    <description>&lt;P&gt;if you were to choose to enable ldap you'd need to enable ssl (tls) and use port 636&lt;/P&gt;&lt;P&gt;since you're using kerberos, nothing changes&lt;/P&gt;</description>
    <pubDate>Thu, 06 Feb 2020 21:52:45 GMT</pubDate>
    <dc:creator>reaper</dc:creator>
    <dc:date>2020-02-06T21:52:45Z</dc:date>
    <item>
      <title>unsigned LDAP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unsigned-ldap/m-p/309572#M80214</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;As we know&amp;nbsp;Microsoft is going to disable use of unsigned LDAP port 389 in March 2020.&lt;/P&gt;&lt;P&gt;Fortunately I don't have LDAP profile on my PA firewall but I have Kerberos. Will there be any impact ?&amp;nbsp;and do I have to change it ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;Konrad&lt;/P&gt;</description>
      <pubDate>Wed, 05 Feb 2020 14:40:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unsigned-ldap/m-p/309572#M80214</guid>
      <dc:creator>KonradPolakowski_OCD</dc:creator>
      <dc:date>2020-02-05T14:40:34Z</dc:date>
    </item>
    <item>
      <title>Re: unsigned LDAP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unsigned-ldap/m-p/309910#M80272</link>
      <description>&lt;P&gt;if you were to choose to enable ldap you'd need to enable ssl (tls) and use port 636&lt;/P&gt;&lt;P&gt;since you're using kerberos, nothing changes&lt;/P&gt;</description>
      <pubDate>Thu, 06 Feb 2020 21:52:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unsigned-ldap/m-p/309910#M80272</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2020-02-06T21:52:45Z</dc:date>
    </item>
    <item>
      <title>Re: unsigned LDAP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unsigned-ldap/m-p/310812#M80485</link>
      <description>&lt;P&gt;Hey Konrad,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;For this one, you'll want to go to your Windows Servers, go to Start &amp;gt; type Event Viewer, and find the Event ID 2886 + 2889 events. To see the 2889 events, you'll need to turn on a certain logging level for Event ID 2889, and then find the Event ID 2889 events in Event Viewer.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Any Event ID 2889 events in Event Viewer on Windows Server you see indicate that some device in your organization/network is performing LDAP bindings to the LDAP Server via a SASL bind without requesting signing or is performing simple binding over clear text.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Here's how to turn on logging for and find the 2889 events:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://docs.microsoft.com/en-us/archive/blogs/russellt/identifying-clear-text-ldap-binds-to-your-dcs" target="_blank" rel="noopener"&gt;https://docs.microsoft.com/en-us/archive/blogs/russellt/identifying-clear-text-ldap-binds-to-your-dcs&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Example of that Event ID 2889 at 2:40 in below video:&lt;BR /&gt;&lt;A href="https://www.youtube.com/watch?v=rijhmYIzwwg" target="_blank" rel="noopener"&gt;https://www.youtube.com/watch?v=rijhmYIzwwg&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;So, if you see a 2889 Event ID which shows your Firewall is trying to connect to the Windows Server using an unsigned/simple bind, then you will want to implement LDAPS on your Firewall and Windows Server:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClFVCA0" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClFVCA0&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Event ID 2886 will also help you identify how many things total in your environment are binding to your LDAP using unsecured/simple/unsigned bindings.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In case you need them for further investigation/guidance, here is the general info put out by Microsoft for the upcoming March 2020 change from LDAP to LDAPS or secure LDAP:&lt;/P&gt;&lt;P&gt;&lt;A href="https://support.microsoft.com/en-us/help/4520412/2020-ldap-channel-binding-and-ldap-signing-requirement-for-windows" target="_blank"&gt;https://support.microsoft.com/en-us/help/4520412/2020-ldap-channel-binding-and-ldap-signing-requirement-for-windows&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/ADV190023" target="_blank"&gt;https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/ADV190023&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Feb 2020 15:12:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unsigned-ldap/m-p/310812#M80485</guid>
      <dc:creator>chadley</dc:creator>
      <dc:date>2020-02-12T15:12:20Z</dc:date>
    </item>
  </channel>
</rss>

