Entourage 2004 & Exchange 2003 WIN2K3 AD, LDAP Signing...

K

KonaBigIsland

Hello,

To start off with, I am not a technical Apple/Mac person, but I do
support the AD at my company. We have recently added on a clustered
Exchange 2003 SP1 setup, and now have a few people requesting the use
of the GAL via the Exchange 2003 server with Entourage 2004 SP2 client.

When setup to connect to AD to view the addresses in the GAL, the
server replies that it is not able to connect to the LDAP server. I
know I probably have got given enough Mac information, but I am still
waiting to hear from the user about a specific error code.

In a virtual test environment, when we changed the GPO setting (applied
to our DCs) "Domain controller: LDAP server signing requirements", from
"Require signing" to "None" the error is no longer present. Does
Entourage 2004 support LDAP signing? Is there a way to keep the
"Require signing" setting (since it is best practice to keep this
setting) and still have Entourage pull information from the GAL?

Thanks for any insight...

KBI
"I only drink Kona."
 
W

William Smith

KonaBigIsland said:
In a virtual test environment, when we changed the GPO setting (applied
to our DCs) "Domain controller: LDAP server signing requirements", from
"Require signing" to "None" the error is no longer present. Does
Entourage 2004 support LDAP signing? Is there a way to keep the
"Require signing" setting (since it is best practice to keep this
setting) and still have Entourage pull information from the GAL?

Currently, not even Mac OS X supports digitally signing its SMB file
sharing communications. No such feature is available in Entourage
either. From a security standpoint, both of these would be good ideas.

Digital signing in this respect guards against man-in-the-middle
attacks. While I don't like the idea of having to lessen security in any
environment, in mixed platform environments you should expect to have to
compromise some security for functionality. If you feel comfortable that
a MITMA is unlikely then you might consider not requiring signed
communications.

Hope this helps! bill
 
K

KonaBigIsland

Bill,

I still find it hard to believe, that to get Entourage to work
correctly with Exchange (to MS products), that I have to lower the
security levels recommended for my DCs.

Well, thanks for your help and response.

KBI
"Kona, its good for you."
 
Top