Anonymous Bind Requirements with NSL7SP2

  • 7009792
  • 23-Nov-2011
  • 26-Apr-2012

Environment

Novell SecureLogin
NSL7.0.2
NSL7 SP2
AD Environment
Attaching to Active Directory Server

Situation

Is anonymous bind required for NSL7.0SP2 installed in AD Mode?
Will SecureLogin 7 sp2 work without enabling anonymous bind on the Active Directory server?

Resolution

Beginning with NSL7.0.2, configuring anonymous bind on the AD server is no longer a hard-fast requirement.   As stated in the NSL7SP2 Readme:

Secured LDAP Browsing Option
With the release of Novell SecureLogin 7.0 SP2, the LDAP Contextless Search feature has been enhanced to enable the LDAPAuth component to perform a search even when anonymous bind is disabled. 

Beginning with NSL7.0.2, administrators have the choice of either enabling anonymous bind or configuring contextless login as described in section 10.4 of the NSL7 SP2 Installation Guide.

Additional Information

Note:  To determine whether or not to use anonymous bind NSL uses the registry setting
HKLM/SOFTWARE/Protocom/SecureLogin           SZ        LDAPContextlessSearchBindcreds

If LDAPContextlessSearchBindcreds is present, SecureLogin assumes that  anonymous bind is disabled and tries to use the encrypted credentials written in the registry. If it is not present SecureLogin will attempt an anonymous bind.