Skip to content

implement LDAP starttls - #341

Open
vikerup wants to merge 1 commit into
ly4k:mainfrom
vikerup:implement-starttls
Open

vikerup wants to merge 1 commit into
ly4k:mainfrom
vikerup:implement-starttls

Conversation

@vikerup

@vikerup vikerup commented Dec 17, 2025

Copy link
Copy Markdown

Implementation of LDAP STARTTLS. Useful if LDAPS in unavailable while DC still requires signing/TLS

Plain LDAP not allowed:

certipy find -u administrator@test.local -p <pw> -dc-ip 100.64.5.200 -vulnerable -enabled -text -stdout -ldap-scheme ldap -no-ldap-signing
Certipy v5.0.4 - by Oliver Lyak (ly4k)

[-] LDAP NTLM authentication failed: {'result': 8, 'description': 'strongerAuthRequired', 'dn': '', 'message': '00002028: LdapErr: DSID-0C090346, comment: The server requires binds to turn on integrity checking if SSL\\TLS are not already active on the connection, data 0, v4563\x00', 'referrals': None, 'saslCreds': None, 'type': 'bindResponse'}
[-] Got error: LDAP authentication refused because LDAP signing is required. Try one of these options:
- Remove '-no-ldap-signing' to enable LDAP signing
- Use '-ldap-scheme ldaps' to use TLS encryption
- Use '-ldap-simple-auth' for SIMPLE bind authentication
[-] Use -debug to print a stacktrace

Using starttls:

certipy find -u administrator@test.local -p <pw> -dc-ip 100.64.5.200 -vulnerable -enabled -text -ldap-scheme ldap+starttls
Certipy v5.0.4 - by Oliver Lyak (ly4k)

[*] Finding certificate templates
[*] Found 37 certificate templates
[*] Finding certificate authorities
....

I'm not 100% sure how you built the LDAP authentication as ldap3 natively does not seem to support username+password when LDAP signing is required. But your code works 👍

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant