A Unified CM LDAP directory or authentication configuration that uses plain LDAP on port 389 without Use TLS is likely to have its simple binds rejected by a domain controller that enforces LDAP signing, and because Unified CM does not support StartTLS, LDAPS on 636 or 3269 is the supported way to encrypt those binds.

inferred · Checked 2026-09-25

Vendor
Cisco
Product
Cisco Unified Communications Manager
Subsystem
LDAP transport security
Deployment
on-premises
Region
not restricted
Release range
Release 15 and SUs with Active Directory
Status
inferred
Checked
2026-09-25

Sources

Cite this note

APA

WarmTransfer. (2026, September 25). Unified CM LDAP directory sync and authentication: source note cucm-ldap-integration-plain-389-signing-risk. WarmTransfer. https://warmtransfer.net/knowledge/claims/cucm-ldap-integration-plain-389-signing-risk

BibTeX

@misc{warmtransfer-claim-cucm-ldap-integration-plain-389-signing-risk,
  title  = {Unified CM LDAP directory sync and authentication: source note cucm-ldap-integration-plain-389-signing-risk},
  author = {{WarmTransfer}},
  year   = {2026},
  url    = {https://warmtransfer.net/knowledge/claims/cucm-ldap-integration-plain-389-signing-risk},
  note   = {Source note cucm-ldap-integration-plain-389-signing-risk, checked 2026-09-25}
}

Read in context