Wireshark Capture and connection to Active Directory

JRrowab

Reputable
Nov 3, 2014
1
0
4,510
I have a Wireshark capture that i am analysis and trying to figure out what application seems to be operating between the various nodes.

The capture shows a lot of LDAP packets as well as a few KRB5 packets. In between all of this is SSLv3 packets labeled as Application Data.

The LDAP and KRB5 packet make me believe that the capture is that of four nodes using Microsoft Active Directory or similar. The question i have is whether programs such Active Directory alone will account for the TCP/SSL application Data packets, or do these packets indicate that there is another software running and the LDAP is merely a part of VMWARE or other network bridge?

Hopefully my explanation of the problem is not too confusing.

Thanks for any help in advance.
 
Solution
My guess...someone stronger in microsoft network stuff will have to confirm... LDAP can use TLS which the is directly related to SSL. Wireshark may be interpreting the tls messages as SSL. It depends on what port it is running on I guess. LDAP can also directly use SSL on some other port that I forget at the moment but this is old way to do that.
My guess...someone stronger in microsoft network stuff will have to confirm... LDAP can use TLS which the is directly related to SSL. Wireshark may be interpreting the tls messages as SSL. It depends on what port it is running on I guess. LDAP can also directly use SSL on some other port that I forget at the moment but this is old way to do that.
 
Solution