Skip to main content
AD Academy
Advanced Protocols and Infrastructure
Advanced12 minLast updated: Topic 2 of 4

SPN and LDAPS

How services are identified in Kerberos and how LDAP is encrypted.

Not read

What you will learn here

  • What an SPN is and why Kerberos needs it
  • How to find duplicate SPNs
  • How to enable LDAPS

Worth reading first:NTLM — the old protocol that's still alive

(Service Principal Name) is the unique name of a service in , for example MSSQLSvc/sql01.lab.local:1433. uses it to know which service to issue a ticket for.

# Display SPN of an account
setspn -L LAB\svc_sql

# Search for user accounts with SPN (Kerberoasting targets)
Get-ADUser -Filter {ServicePrincipalName -like "*"} -Properties ServicePrincipalName

# Check if LDAPS is active (port 636)
Test-NetConnection dc01.lab.local -Port 636
powershell
Architecture and Theory — Under the Hood

links a service name (HTTP/web01.corp.com) to the account running it. Without SPN — no , falls back to . LDAPS = over TLS on port 636.

Practical Configuration (PowerShell / GUI)
# SPN Registration
setspn -S HTTP/portal.corp.com CORP\svc_web

# Duplicate check (Duplicate SPN = Broken Kerberos)
setspn -X

# LDAPS — Requires a certificate in the computer's Personal store with Server Authentication EKU
# Check
ldp.exe → Connection → Connect → Port 636 → SSL
powershell
Real-World Scenarios in an Organization
  • Web application running under a service account — must have an for each hostname (short + FQDN).
  • LDAPS is mandatory before enabling Channel Binding (protects against relay).
Troubleshooting
  • klist purge and retry after fix.
  • Event 4771 with code 0x25 = Clock skew, 0x18 = incorrect password.
  • certutil -store MY — checking DC certificates for LDAPS.
Glossary and Quick Command Line
  • — Service Principal Name.
  • LDAPS — over TLS (636).
  • setspn -L user — list SPNs for an account.

Check yourself

What does an SPN represent?

Was this page helpful?