Skip to content

Disable Simple LDAP

Final step is to disable simple LDAP on domain controller and require LDAP server signing. The steps are described in the following Microsoft article.

You would need to use Group Policy to enable LDAP signing, navigate to Default Domain Controller Policy > Computer Configuration > Policies > Windows Settings > Security Settings > Local Policies, then select Security Options.

Default Domain Controllers Policy

Right-click Domain controller: LDAP server signing requirements, select Properties and configure the LDAP server signing requirements as shown on the following screenshot.

Enable LDAP Signing

Click OK and reboot your domain controller to take effect.

From now on any attempt to bind to LDAP server using simple LDAP will fail with the following error ( Strong(er) authentication required ).

LDAPS Test Connection Failure 2

ERROR: Connection to 1st LDAP server failed: cannot bind to LDAP host with user 
name 'squid@example.lan', error 8, error_str Strong(er) authentication required