Synology NAS and secure domain authentication (SASL)

You’ve also experienced this: your domain controller is telling you every day that a sum of clients have tried to authenticate without encryption?


SSH into the synology box, using the admin credentials.
Edit the file: /usr/syno/etc/smb.conf using your favorite editor.

Under the [global] section add these two lines.

   ldap ssl=start tls
   ldap ssl ads=yes

Restart samba

/usr/syno/etc/rc.sysv/ restart

Log in with kerberous, using the command

kinit -V a_domain_admin_username

Replace “a_domain_admin_username” with a username on the domain, that have admin level access. It should ask you for the password.

Make sure it worked

wbinfo -u

Please Synology add a GUI option for the “ldap ssl ads=yes”. The lack of SSL is a security risk and gives big warnings on Windows Server 2012.