Event ID: 2887
log name: directory service
source: microsoft-windows-activedirectory_domainservice
date: 2/15/2012 8:00:35 am
event id: 2887
task category: ldap interface
level: warning
keywords: classic
user: anonymous logon
computer: newserver.microsoft.com
description:
during previous 24 hour period, clients attempted perform ldap binds either:
(1) sasl (negotiate, kerberos, ntlm, or digest) ldap bind did not request signing (integrity validation), or
(2) ldap simple bind performed on cleartext (non-ssl/tls-encrypted) connection
directory server not configured reject such binds. the security of directory server can enhanced configuring server reject such binds. for more details , information on how make configuration change server, please see http://go.microsoft.com/fwlink/?linkid=87923.
summary information on number of these binds received within past 24 hours below.
can enable additional logging log event each time client makes such bind, including information on client made bind. to so, please raise setting "ldap interface events" event logging category level 2 or higher.
number of simple binds performed without ssl/tls: 345
number of negotiate/kerberos/ntlm/digest binds performed without signing: 0
event xml:
<event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<system>
<provider name="microsoft-windows-activedirectory_domainservice" guid="{0e8478c5-3605-4e8c-8497-1e730c959516}" eventsourcename="ntds ldap" />
<eventid qualifiers="32768">2887</eventid>
<version>0</version>
<level>3</level>
<task>16</task>
<opcode>0</opcode>
<keywords>0x8080000000000000</keywords>
<timecreated systemtime="2012-02-15t02:30:35.028275000z" />
<eventrecordid>2491</eventrecordid>
<correlation />
<execution processid="720" threadid="876" />
<channel>directory service</channel>
<computer>server.gpma.local</computer>
<security userid="s-1-5-7" />
</system>
<eventdata>
<data>345</data>
<data>0</data>
</eventdata>
</event>
source: microsoft-windows-activedirectory_domainservice
date: 2/15/2012 8:00:35 am
event id: 2887
task category: ldap interface
level: warning
keywords: classic
user: anonymous logon
computer: newserver.microsoft.com
description:
during previous 24 hour period, clients attempted perform ldap binds either:
(1) sasl (negotiate, kerberos, ntlm, or digest) ldap bind did not request signing (integrity validation), or
(2) ldap simple bind performed on cleartext (non-ssl/tls-encrypted) connection
directory server not configured reject such binds. the security of directory server can enhanced configuring server reject such binds. for more details , information on how make configuration change server, please see http://go.microsoft.com/fwlink/?linkid=87923.
summary information on number of these binds received within past 24 hours below.
can enable additional logging log event each time client makes such bind, including information on client made bind. to so, please raise setting "ldap interface events" event logging category level 2 or higher.
number of simple binds performed without ssl/tls: 345
number of negotiate/kerberos/ntlm/digest binds performed without signing: 0
event xml:
<event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<system>
<provider name="microsoft-windows-activedirectory_domainservice" guid="{0e8478c5-3605-4e8c-8497-1e730c959516}" eventsourcename="ntds ldap" />
<eventid qualifiers="32768">2887</eventid>
<version>0</version>
<level>3</level>
<task>16</task>
<opcode>0</opcode>
<keywords>0x8080000000000000</keywords>
<timecreated systemtime="2012-02-15t02:30:35.028275000z" />
<eventrecordid>2491</eventrecordid>
<correlation />
<execution processid="720" threadid="876" />
<channel>directory service</channel>
<computer>server.gpma.local</computer>
<security userid="s-1-5-7" />
</system>
<eventdata>
<data>345</data>
<data>0</data>
</eventdata>
</event>
hth
marcin
Windows Server > Directory Services
Comments
Post a Comment