Windows Server 2025 LDAP hardening: validate signing and channel binding before enforcement
Short answer: requiring LDAP signing rejects simple binds without TLS and SASL binds without signing or sealing outside TLS. Simple bind over TLS satisfies the server signing requirement and is unaffected by LdapEnforceChannelBinding. SASL authentication over TLS is the relevant channel-binding…