Skip to content

Glossary

LDAP channel binding

LDAP channel binding cryptographically ties an LDAP session to its TLS channel, preventing relay attacks against LDAP authentication.

LDAP channel binding is a security mechanism that cryptographically binds an authenticated LDAP session to the underlying TLS channel it was negotiated over. It works alongside LDAP signing by ensuring that even an authentication exchange carried over TLS cannot be intercepted and relayed to a different connection, closing a gap that signing alone does not fully address when TLS is in use.

This matters because, without channel binding, an attacker capturing NTLM authentication attempts (for example via coercion techniques) can relay them to a domain controller's LDAPS endpoint to perform privileged actions, such as creating computer objects or modifying attributes, as the relayed user. Microsoft has tightened defaults over time, for example new Windows Server 2025 deployments require LDAP signing, but most existing domain controllers still do not enforce channel binding unless configured; defenders should confirm signing is set to require and channel binding to "Always" rather than "When supported" or "Never", and monitor for LDAP authentication anomalies.

See NTLM, LDAP, and SMB hardening.