ldaps vs. Require LDAP Signing on domain

Iron Contributor

Hello

 

I'm trying to understand the preferred method?  Currently i have a number of client\applications that are making ldap binds to DC's over non secure port. From reading on how to remediate this it sounds like i have two options . #1 configure GPO on all DC's for "Require LDAP Signing on domain" or #2 install a cert on every DC, then configure client\apps to connect over port 636

 

Trying to understand the best option ?

Thank you 

1 Reply