Azure / Azure/AzureLocal-Supportability
LDAP not working with WS 2025 domain due to LDAP disable
- 主要语言
- PowerShell
- 星标
- 78
- 派生
- 60
- 平均合并
- 1 天 6 小时
- 30 天内合并 PR
- 5
描述
**Bug description**
With Windows Server 2025 in a 2025 Domain Function Level LDAP is disabled and LDAP SSL is the only way.
So certain things like setspn does not work as it uses LDAP and not LDAP SSL. From a 2025 Computer the commands work fine but not from HCI 23h2.
**Repro steps**
Create a new 2025 domain and try setspn from a HCI node. The WSMAN spn records are not created. And setspn lookup or creation does not work,
**Expected behavior**
I expect that setspn and other LDAP functionality to work properly.
**Environment (please complete the following information):**
Latest 23h2 deployment with September patches.
**Screenshots**

贡献指南
调研方向
通过在 2025 Domain Function Level 创建 Windows Server 2025 域,并从 HCI 23H2 节点运行 setspn 来复现该故障。比较 LDAP 和 LDAP SSL 的行为;完成的标准是 WSMAN SPN 查找和创建均正常工作,同时其他受影响的 LDAP 功能也正常工作。
由索引模型根据 Issue 内容生成。
评估
- 技术栈
- azure
- 领域
- authentication, operating-systems
- Issue 类型
- 缺陷
- 难度
- 4/5
- 预计耗时
- 3-5 天
- 活跃度
- 停滞
- 描述清晰度
- 需要澄清
- 新手友好度
- 25/100