Whats using LDAPS, Check in event viewer.

Biswajeet Kumar 46 Reputation points
2021-01-13T07:49:18.263+00:00

Hi,

How do I know what is using LDAPS in event viewer, what clients are using LDAPS in my domain controller. Basically want to know the event id for LDAPS events in event viewer.

By normally looking the event viewer I am not finding any events related to LDAPS.

Thanks

Windows Server 2012
Windows Server 2012
A Microsoft server operating system that supports enterprise-level management, data storage, applications, and communications.
1,595 questions
Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
6,578 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Hannah Xiong 6,276 Reputation points
    2021-01-13T09:04:37.523+00:00

    Hello,

    Thank you so much for your posting.

    According to my research, there is only one Event ID that is directly related to LDAP over SSL, which is Event 1220. For more information, we could refer to:

    https://social.technet.microsoft.com/wiki/contents/articles/2979.event-id-1220-ldap-over-ssl-ldaps.aspx

    There seems to be no event ID for LDAPS events in event viewer showing that what is using LDAPS based on my research. There are some events which are related to LDAP signing, such as Event 2887, 2888 and 2889.

    56134-13.png

    Reference:
    2020 LDAP channel binding and LDAP signing requirements for Windows
    https://support.microsoft.com/en-us/help/4520412/2020-ldap-channel-binding-and-ldap-signing-requirements-for-windows

    Have we enable LDAPS?

    LDAP over SSL/TLS (LDAPS) is automatically enabled when you install an Enterprise Root CA on a domain controller (although installing a CA on a domain controller is not a recommended practice).

    We could follow these steps to verify that LDAPS is enabled:

    1. On the client, start Ldp.exe
      For example:
      56172-12.png
    2. On the Connection menu, click Connect.
    3. Type the name of the LDAP server (e.g. domain controller or AD LDS/ADAM server) to which you want to connect.
    4. Type 636 as the port number.
    5. Click OK.

    Besides, there is no way to make clients prefer LDAPS because the type of connection depends on the application that is running on the client computer.

    Thanks so much.

    Best regards,
    Hannah Xiong

    ============================================

    If the Answer is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.