danekerman (Customer) asked a question.

Is SSL mandatory for Active Directory connectors in v8 P2 ? I am unable to save a connector if the use secure connection box is unchecked. It keeps telling me I must check the box. I Did not have this issue in 7.5.x.

  • Staines_ian (RSA Security)

    This is a design decision due to the fact that various provisioning commands are not supported on cleartext binds over LDAP by Microsoft.

    Selected as Best
  • Staines_ian (RSA Security)

    Yes, it is now considered mandatory.

     

    Do you have a business justification for using a non-SSL connection?

    • danekerman (Customer)

      Thats just how it was configured in 7.5.2 before I came on board.

       

  • Staines_ian (RSA Security)

    This is a design decision due to the fact that various provisioning commands are not supported on cleartext binds over LDAP by Microsoft.

    Selected as Best
    • danekerman (Customer)

      got it, I'm working with our AD team to get the port connecting. Thanks!

    • danekerman (Customer)

      Just curious, from a UI design perspective why is there even a checkbox if its mandatory? seems unnecessary.

  • Staines_ian (RSA Security)

    It is. There is a defect open to resolve this with a change to the GUI.

  • OverthinkerDave (Customer)

    Curiosity awakens here to: Is there any OTHER connectors that have a mandatory usage of SSL (without it being visible in GUI)?

     

    Having big difficulties here with other ldap-AFX-connectors in 8.0.0 P02....

  • Staines_ian (RSA Security)

    No. This is specific to the AD Connector. Microsoft is the only endpoint that requires SSL bind for specific verbs.

     

    The visibility issue with the GUI is resolved in 8.0.0 P03.