[389-users] Securing LDAP information on the network

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Mon, 2009-12-14 at 15:01 +0100, Kenneth Holter wrote:
> Hi all.
>  
>  
> We'd like to make sure that the LDAP data on our network is encrypted,
> at least the data that contains sensitive information. We've set up
> TLS between on these communication links:
>       * LDAP client <-> LDAP server (using StartTLS)
>       * LDAP master <-> LDAP slave
>       * Web browser <-> Admin server web console (i.e. https)
> We have a pretty default installation of the directory server (which
> btw is Red Hat Directory Server v8.1.0). To my best knowledge, these
> links above should cover all relevant trafikk on the network, since
> the directory server, admins server and the console are all located on
> the same physical server. Does anyone agree or disagree? 
>  
> Btw, if anyone knows of any nice diagrams that shows the different
> data links (i.e information flow) between the directory server
> components (such as admins server, console, main console, directory
> server, and so forth) please do post a link to this. 
<snip>
That's what we've done although we also use LDAPS in some cases.  We
have not yet played with disabling unencrypted traffic.  If someone does
not request StartTLS or LDAPS, we do respond with unencrypted traffic.
We've also ensured that backups of the database are both sent and stored
encrypted - John
-- 
John A. Sullivan III
Open Source Development Corporation
+1 207-985-7880
jsullivan at opensourcedevel.com

http://www.spiritualoutreach.com
Making Christianity intelligible to secular society




[Index of Archives]     [Fedora User Discussion]     [Older Fedora Users]     [Fedora Announce]     [Fedora Package Announce]     [EPEL Announce]     [Fedora News]     [Fedora Cloud]     [Fedora Advisory Board]     [Fedora Education]     [Fedora Security]     [Fedora Scitech]     [Fedora Robotics]     [Fedora Maintainers]     [Fedora Infrastructure]     [Fedora Websites]     [Anaconda Devel]     [Fedora Devel Java]     [Fedora Legacy]     [Fedora Desktop]     [Fedora Fonts]     [ATA RAID]     [Fedora Marketing]     [Fedora Management Tools]     [Fedora Mentors]     [Fedora Package Review]     [Fedora R Devel]     [Fedora PHP Devel]     [Kickstart]     [Fedora Music]     [Fedora Packaging]     [Centos]     [Fedora SELinux]     [Fedora Legal]     [Fedora Kernel]     [Fedora QA]     [Fedora Triage]     [Fedora OCaml]     [Coolkey]     [Virtualization Tools]     [ET Management Tools]     [Yum Users]     [Tux]     [Yosemite News]     [Yosemite Photos]     [Linux Apps]     [Maemo Users]     [Gnome Users]     [KDE Users]     [Fedora Tools]     [Fedora Art]     [Fedora Docs]     [Maemo Users]     [Asterisk PBX]     [Fedora Sparc]     [Fedora Universal Network Connector]     [Fedora ARM]

  Powered by Linux