Forum Discussion

tbgsaunders's avatar
tbgsaunders
Copper Contributor
Nov 02, 2020
Solved

LDAP SSL with Third-Party Certificate schannel event Id 36887 fatal alert 46

We use Mimecast anti-spam service and it has an AD Directory Connector using LDAP which has been functioning find for years using standard LDAP (not secure).  The are going to require secure so tryin...
  • tbgsaunders's avatar
    tbgsaunders
    Nov 02, 2020

    Ok folks,

    There was a setting on Mimecast called Encryption Mode allowing Relaxed OR Strict.

    Their notes state:

    If the "Encrypt Connection" option is checked, specify one of the following encryption modes:
    Encryption Mode Description
    Strict - Trust Enforced This mode requires a certificate issued by a Mimecast trusted public root certification authority, and a key length greater than 1024 bits to be installed on your domain controller.
    Relaxed This mode must be used if your certificate is self-signed, has a key length of less than 1024 bits, or has an incomplete trust chain.

     

    Not sure why it was required as Strict should have worked, but we are up and going now.

    Greg

Resources