How to enable LDAPS on AWS Managed Microsoft AD for FortiGate authentication
A technical guide details how to migrate FortiGate LDAP authentication from plaintext port 389 to encrypted LDAPS on port 636 using AWS Managed Microsoft AD. Because AWS does not grant direct access to managed domain controllers, certificates cannot be installed manually — instead, Active Directory autoenrollment is required, meaning a Microsoft Enterprise CA joined to the domain must be deployed on a management EC2 instance. The Domain Controllers automatically begin listening on port 636 once they receive a valid certificate through autoenrollment, with no configuration needed in the AWS Directory Service console. Only the CA's public certificate needs to be exported and imported into FortiGate so it can validate the DC's TLS certificate during the LDAPS handshake. The VPN tunnel and LDAPS operate as independent layers: the VPN delivers traffic to the VPC while LDAPS encrypts the LDAP session within it.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in