How to Prevent Anonymous LDAP Operations in Windows 2000 dom
Windows Server Forum Index Windows Server
Server discussion on Windows platform.
 
 FAQFAQ   MemberlistMemberlist     RegisterRegister 
 ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in 
 
Google
 
Web winserverhelp.com
How to Prevent Anonymous LDAP Operations in Windows 2000 dom

 
Post new topic   Reply to topic    Windows Server Forum Index -> Active Directory
Author Message
TC
Guest





Posted: Fri Nov 11, 2005 1:50 am    Post subject: How to Prevent Anonymous LDAP Operations in Windows 2000 dom Reply with quote

Windows 2000 domain by default allows anonymous LDAP queries. How can an
administrator restrict this without affecting operations? Thanks.
Back to top
Paul Bergson
Guest





Posted: Fri Nov 11, 2005 5:50 pm    Post subject: Re: How to Prevent Anonymous LDAP Operations in Windows 2000 Reply with quote

The key point here is 2000 allows this, 2003 only allows access to the
rootdse anything else requires you to bind to it. I'm unclear if there is a
way to block anonymous ldap queries but below is a routine that explains how
to allow access in. Maybe you can work backwards from it (I wouldn't try
this in production). My suggestion would be if you need the security
upgrade to 2003.

http://support.microsoft.com/default.aspx?scid=kb;en-us;320528


--


Paul Bergson MCT, MCSE, MCSA, CNE, CNA, CCA

This posting is provided "AS IS" with no warranties, and confers no rights.


"TC" <TC@discussions.microsoft.com> wrote in message
news:440C2D0C-1292-4BF2-ABAC-EB7ACF5B320C@microsoft.com...
Quote:
Windows 2000 domain by default allows anonymous LDAP queries. How can an
administrator restrict this without affecting operations? Thanks.
Back to top
 
Post new topic   Reply to topic    Windows Server Forum Index -> Active Directory All times are GMT
Page 1 of 1

 
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum




New Topics Powered by phpBB