Security Compliance
SEM LDAPS Setup/Configuration
How to configure SEM to use LDAPS/Secure LDAP/LDAP over SSL
First published date
Last published date
Overview
In some environments, LDAP will only be possible over SSL. This normally changes the port that is used and requires a certificate to be accepted on the SEM side. This guide explains the steps to check for this, or enable it if needed.
Product section
Resolution
Configuring LDAPS
When adjusting the SEM to use LDAPS instead of LDAP it is important to enable SSL in two primary locations. One is when configuring LDAP authentication to the SEM. This can be done by going into the settings on the HTML5 web console and adjusting the "LDAP Configuration" to use SSL.
Another important place to check is in your Manager Connectors. There is a Directory Services Query connector that is sometimes set up to allow the use of Active Directory groups when applying rule logic. This also has settings to enable SSL, which will allow its traffic to traverse using LDAPS.
One place to check after adjusting these settings, to verify that the connection is still working, is the SEM Internal Events filter under the Events tab. Keep an eye out for events mentioning the LDAP connection status was successful.