Azure / Azure/AzureLocal-Supportability

LDAP not working with WS 2025 domain due to LDAP disable

未关闭
#11 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
主要语言
PowerShell
星标
78
派生
60
平均合并
1 天 6 小时
30 天内合并 PR
5

描述

**Bug description**
With Windows Server 2025 in a 2025 Domain Function Level LDAP is disabled and LDAP SSL is the only way.

So certain things like setspn does not work as it uses LDAP and not LDAP SSL. From a 2025 Computer the commands work fine but not from HCI 23h2.

**Repro steps**
Create a new 2025 domain and try setspn from a HCI node. The WSMAN spn records are not created. And setspn lookup or creation does not work,

**Expected behavior**
I expect that setspn and other LDAP functionality to work properly.

**Environment (please complete the following information):**
Latest 23h2 deployment with September patches.

**Screenshots**
![image](https://github.com/user-attachments/assets/8108c0dd-ac25-441c-becc-a511630adbc9)

贡献指南

打开贡献指南

调研方向

通过在 2025 Domain Function Level 创建 Windows Server 2025 域,并从 HCI 23H2 节点运行 setspn 来复现该故障。比较 LDAP 和 LDAP SSL 的行为;完成的标准是 WSMAN SPN 查找和创建均正常工作,同时其他受影响的 LDAP 功能也正常工作。

由索引模型根据 Issue 内容生成。

评估

技术栈
azure
领域
authentication, operating-systems
Issue 类型
缺陷
难度
4/5
预计耗时
3-5 天
活跃度
停滞
描述清晰度
需要澄清
新手友好度
25/100

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。