Skip to content

Added LDAP signing + Channel Binding compatibility to dnstool.py - #41

Open
flashlam wants to merge 1 commit into
dirkjanm:masterfrom
synacktiv:master
Open

Added LDAP signing + Channel Binding compatibility to dnstool.py#41
flashlam wants to merge 1 commit into
dirkjanm:masterfrom
synacktiv:master

Conversation

@flashlam

@flashlam flashlam commented Oct 3, 2024

Copy link
Copy Markdown

Hi Dirk-jan !

A tiny PR to add LDAP signing and Channel Binding compatibility using the package ldap3-bleeding-edge which includes those features.

Do not hesitate if you have any remarks

@tact1c1an

Copy link
Copy Markdown

Is it possible to get this merged with the main branch? Its a very neat PR.

@er4z0r

er4z0r commented Oct 20, 2025

Copy link
Copy Markdown

Thanks for this PR! I was having issues with an IPS (Frocepoint) (mis-) detection the addition of DNS records as an attempt to exploit CVE-2020-0664. Attempts to switch LDAPS failed on me with:

description': 'invalidCredentials', 'dn': '', 'message': '80090346: LdapErr: DSID-0C090880, comment: AcceptSecurityContext error,

because the DC was requiring channel binding. Using this PR fixed the issue for me.

@derekkddj

Copy link
Copy Markdown

this should be merged yes.

@3ldidi94

Copy link
Copy Markdown

I am using this PR each time I do a git clone of this project. It is working just fine.
@dirkjanm Could you please merge this PR please ? I have a fork of the project just to include this PR

@flashlam thanks for this PR btw.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants