Possible to Handle Active Directory "Channel Binding" & "LDAP Signing" in LDAP Module

Created on 31 October 2022, over 1 year ago
Updated 4 January 2024, 6 months ago

Problem/Motivation

We have a Drupal 7 site (using Linux & Nginx) that users from another organisation login into with their Active Directory credentials. We use Service Account Bind.

It's a pretty straightforward setup, we are a purely a consumer of their AD service, we don't write back and it's over LDAPS.

I recently got an email from the other organisation stating that they attempted to enable "Channel Binding" & "LDAP Signing" as per this description.
https://support.microsoft.com/en-us/topic/2020-ldap-channel-binding-and-...

However, it killed the login on the Drupal server so they rolled back.

They want too know if there is anything I can do at my end. I been asking my mate (Google) but can't find anything. Frankly, I'm stumped.

Is this "doable" with the LDAP module. Hell, are "Channel Binding" & "LDAP Signing" something that exists outside AD?

Thanks, Brett

πŸ’¬ Support request
Status

Closed: outdated

Version

2.6

Component

Task

Created by

πŸ‡¦πŸ‡ΊAustralia BrettSh

Live updates comments and jobs are added and updated live.
Sign in to follow issues

Comments & Activities

Not all content is available!

It's likely this issue predates Contrib.social: some issue and comment data are missing.

Production build 0.69.0 2024