Port 636: LDAP over TLS/SSL
Port 636 carries LDAP inside a TLS session that starts as soon as the client connects. Active Directory domain controllers listen on 636 for LDAP SSL, alongside plain LDAP on 389 and the Global Catalog on 3268 and 3269. Applications use it for directory lookups and simple binds that must not travel in cleartext.
Port Details
Security Exposure
LDAPS exposes the directory, which holds account and group data, to anyone who can reach it. Microsoft notes that unsigned or unprotected LDAP traffic is open to replay and man-in-the-middle attacks, and that channel binding tokens make LDAP over TLS more resistant to them.
Hardening
- +Restrict 636 to internal networks and approved application servers; do not publish domain controllers to the internet.
- +Enable LDAP channel binding on domain controllers so LDAPS binds are tied to the TLS session.
- +Require LDAP signing and reject simple binds over non-TLS connections on 389.
- +Deploy valid server certificates on domain controllers and monitor their expiry.
Monitoring
Collect Directory Service events 3039 to 3041 for channel binding failures and events 2887 and 2889 for binds that do not use signing or TLS. Investigate clients that keep appearing in these events.
Tools for Auditing and Monitoring LDAPS
BloodHound CE
Free / CommercialAttack path analysis platform that maps identity and privilege relationships across Active Directory, Entra ID, and other platforms through OpenGraph.
Nmap
Free / CommercialNetwork discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.
Wazuh
Free / CommercialOpen-source SIEM and XDR platform providing endpoint monitoring, log analysis, file integrity checks, and threat detection.
Related Tool Categories
Secrets managers, identity engines, and access control platforms for managing credentials and privilege.
Zero trust access, secure web gateways, firewalls, and perimeter enforcement platforms.
SIEM platforms, EDR agents, SOAR automation, and detection rule engines for security operations.
Frequently Asked Questions
What is the difference between port 389 and 636?→
Microsoft explains that LDAP uses port 389, while LDAPS uses port 636 and establishes SSL/TLS upon connecting.
Is port 636 TCP or UDP?→
LDAPS runs over TCP. IANA lists ldaps on both TCP and UDP, and Microsoft's port reference lists LDAP SSL on TCP 636.
Sources
- IANA Service Name and Port Number Registry: port 636
- Microsoft Support: LDAP channel binding and LDAP signing requirements for Windows (KB4520412)
- Microsoft Learn: How to enable LDAP signing in Windows Server
- Microsoft Learn: Service overview and network port requirements for Windows
- RFC 4513: LDAP: Authentication Methods and Security Mechanisms
Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 636 is not guaranteed to be LDAPS. Exploited-in-the-wild data from the CISA KEV catalog (CC0).