SSL encrypted connections to AD controller

Questions about using Windows AD service.

SSL encrypted connections to AD controller

Postby napqguy » Fri Jun 15, 2012 5:59 am

Hi !

Our company is currently moving towards using SSL-LDAP/LDAP signing to encrypt all AD traffic.
Since we have integrated our NAS into our AD by joining the AD Domain, we need to setup the NAS to use SSL-LDAP/LDAP signing, too.

Unfortunately, I could not find any hint on how to enable SSL-LDAP/LDAP signing while usind the AD membership option in 'Access Right Managment' -> 'Domain Security' ->'Active Directory authentication (domain member)'.

Althoug there is an SSL option in the 'LDAP authentication' dialog, this does not seem to be the solution for my problem.

Additional Information on LDAP signing can be found at http://search.abb.com/library/Download. ... ion=Launch

Is this a missing feature in the GUI ? Perhaps I can set the required option by modifying the AD/LDAP config files.

Has anybody any hints on this ?

Thanks for you help !

BR,
Michael
napqguy
New here
 
Posts: 3
Joined: Fri Jun 15, 2012 4:48 am
NAS Model: SS-839 Pro

Re: SSL encrypted connections to AD controller

Postby sbresin » Fri Jul 06, 2012 4:02 am

Hi Michael,

Well it seems you did not get any valuable answers yet sorry for you...

Just for information, what is the point to 'encrypt all AD traffic'? What could be the risk?

thanks
stanislas
sbresin
Easy as a breeze
 
Posts: 459
Joined: Sun Jan 08, 2012 10:50 pm
NAS Model: TS-119P+

Re: SSL encrypted connections to AD controller

Postby napqguy » Sun Jul 15, 2012 10:18 pm

Hi Stanislas,

we are participating in a corporate AD structure. The descision to encrypt all AD-traffic was made by corporate IT.
If we can not modify the QNAP to perform LDAP signing & encryption, we will loose AD connectivity which implies that will will have to drop the QNAP and find an alternative solution.

BR,
Michael
napqguy
New here
 
Posts: 3
Joined: Fri Jun 15, 2012 4:48 am
NAS Model: SS-839 Pro

Re: SSL encrypted connections to AD controller

Postby sbresin » Mon Jul 16, 2012 1:41 am

Hi Michael,

Thanks for the explanations. After a few months of experiencing QNAP, their NAS seem to be not good at all for specific configuration... Was wondering what could be the alternatives, windows server maybe...

regards
Stanislas
sbresin
Easy as a breeze
 
Posts: 459
Joined: Sun Jan 08, 2012 10:50 pm
NAS Model: TS-119P+

Re: SSL encrypted connections to AD controller

Postby napqguy » Mon Jul 16, 2012 5:29 am

Hi Stanislas,

fortunately, I made another try to search the forum with new keywords and found a hint stating the following:

Connect to the NAS by SSH, edit the file /etc/smb.conf, and add the line after the [global] :

client ldap sasl wrapping = sign

We are going to try this and see what happens. Maybe this could be the solution. I'll post the results but this may take until end of July, since I am on holiday, right now.

BR,
Michael
napqguy
New here
 
Posts: 3
Joined: Fri Jun 15, 2012 4:48 am
NAS Model: SS-839 Pro


Return to Windows Domain & Active Directory

Who is online

Users browsing this forum: No registered users and 2 guests