{"id":107309,"date":"2020-02-27T15:40:28","date_gmt":"2020-02-27T14:40:28","guid":{"rendered":"https:\/\/easy-software.com\/?post_type=support_news&p=107309"},"modified":"2024-12-09T09:18:36","modified_gmt":"2024-12-09T08:18:36","slug":"microsoft-ldaps-patch-easy-capture-plus","status":"publish","type":"support_news","link":"https:\/\/easy-software.com\/en\/support_news\/microsoft-ldaps-patch-easy-capture-plus\/","title":{"rendered":"Microsoft LDAPS Patch easy Capture Plus"},"content":{"rendered":"
On Active Directory domain controllers, there are a number of unsafe standard configurations for LDAP channel binding and LDAP signing. LDAP-channel binding and LDAP-signing provide ways to increase security for communication between LDAP clients and Active Directory domain controllers. In an upcoming release, Microsoft will provide a Windows update that will change LDAP-channel binding and LDAP-signing to more secure configurations by default.<\/p>\n\n\n\n
There is no update required to use LDAPS with easy Capture Plus. You just need<\/strong> to adjust one setting<\/strong> in easy Capture Configuration<\/strong>.<\/p>\n\n\n\n Therefore please start easy Capture Configuration. You find the shortcut normally placed on the desktop of you easy Capture Plus Server.<\/p>\n\n\n Now navigate to the node \/easy CAPTURE PLUS\/Software\/CAPTURE ASE\/Basics<\/p>\n\n\n\n You can open<\/strong> the configuration with a double-click on \u201aBasics<\/strong>\u2018<\/p>\n\n\n\n If checkbox \u201aActive<\/strong>\u2018 is checked you use LDAP authentifcation<\/strong> in easy Capture Plus and you need to adjust the port to use LDAP-S. Please change the port from 389<\/strong> (default LDAP port) to port 636 <\/strong>(default LDAPS port). There is no further action required.<\/p>\n\n\n\n You can test your LDAP-S configuration with button \u201aTest<\/strong>\u2018. If your configuration<\/strong> is correct<\/strong> you see a dialog box with the message \u201aSuccessful<\/strong>\u2018. Please close the configuration dialog with \u201aOk\u2018 to save the configuration. Please restart<\/strong> Windows service \u201aeasy Capture Center\u2018.<\/p>\n\n\n\n If checkbox \u201aActive<\/strong>\u2018 is unchecked<\/strong> you do not use LDAP authentification in easy Capture Plus and no change in configuration is neccessary. Please leave<\/strong> dialog with \u201aCancel<\/strong>\u2018.<\/p>\n\n\n\n Usually the required certificates are already known on the member servers. If errors occur when connecting via LDAPS, please check the certificates on the participating servers.<\/p>\n\n\n\n The certificate must be issued for the \u201cserver authentication<\/strong>\u201d and must contain the server name and the FQDN<\/strong> as \u201cDNS name<\/strong>\u201d entry.<\/p>\n\n\n\n Please also note that easy for Exchange<\/strong> uses the LDAP interface<\/strong> in easy Archive<\/strong>. To activate<\/strong> LDAPS<\/strong> in easy archive, please check the settings according to the chapter \u201cDirectory services\u201d in the easy archive documentation.<\/p>\n\n\n\ndocumentation<\/a>\n\n\n\n <\/p>\n\n\n\nrollback instruction<\/a>\n\n\n
<\/figure><\/div>\n\n\n
<\/a><\/figure>\n\n\n\n
<\/a><\/figure>\n\n\n\nCertificate of the Active Directory Controller<\/h2>\n\n\n\n
<\/figure>\n\n\n\nAdjustments in easy <\/h4>\n\n\n\n