FAQ Search Today's Posts Mark Forums Read
» Video Reviews

» Linux Archive

Linux-archive is a website aiming to archive linux email lists and to make them easily accessible for linux users/developers.


» Sponsor

» Partners

» Sponsor

Go Back   Linux Archive > Redhat > Fedora Directory

 
 
LinkBack Thread Tools
 
Old 12-14-2009, 01:01 PM
Kenneth Holter
 
Default Securing LDAP information on the network

Hi all.
*
*
We'd like to make sure that the LDAP data on our network is encrypted, at least the data that contains sensitive information. We've set up TLS between on these communication*links:

LDAP client <-> LDAP server (using StartTLS)
LDAP master <-> LDAP slave
Web browser <-> Admin server web console (i.e. https)
We have a pretty default installation of the directory server (which btw is Red Hat Directory Server v8.1.0). To my best knowledge, these links above should cover all relevant trafikk on the network, since the directory server, admins server and the console are all located on the same physical server. Does anyone agree or disagree?

*
Btw, if anyone knows of any nice diagrams that shows the different data links (i.e information flow) between the directory server components (such as admins server, console,*main console, directory server, and so forth) please do post a link to this.

*
Best regards,
Kenneth Holter
--
389 users mailing list
389-users@redhat.com
https://www.redhat.com/mailman/listinfo/fedora-directory-users
 
Old 12-14-2009, 05:36 PM
"John A. Sullivan III"
 
Default Securing LDAP information on the network

On Mon, 2009-12-14 at 15:01 +0100, Kenneth Holter wrote:
> Hi all.
>
>
> We'd like to make sure that the LDAP data on our network is encrypted,
> at least the data that contains sensitive information. We've set up
> TLS between on these communication links:
> * LDAP client <-> LDAP server (using StartTLS)
> * LDAP master <-> LDAP slave
> * Web browser <-> Admin server web console (i.e. https)
> We have a pretty default installation of the directory server (which
> btw is Red Hat Directory Server v8.1.0). To my best knowledge, these
> links above should cover all relevant trafikk on the network, since
> the directory server, admins server and the console are all located on
> the same physical server. Does anyone agree or disagree?
>
> Btw, if anyone knows of any nice diagrams that shows the different
> data links (i.e information flow) between the directory server
> components (such as admins server, console, main console, directory
> server, and so forth) please do post a link to this.
<snip>
That's what we've done although we also use LDAPS in some cases. We
have not yet played with disabling unencrypted traffic. If someone does
not request StartTLS or LDAPS, we do respond with unencrypted traffic.
We've also ensured that backups of the database are both sent and stored
encrypted - John
--
John A. Sullivan III
Open Source Development Corporation
+1 207-985-7880
jsullivan@opensourcedevel.com

http://www.spiritualoutreach.com
Making Christianity intelligible to secular society

--
389 users mailing list
389-users@redhat.com
https://www.redhat.com/mailman/listinfo/fedora-directory-users
 

Thread Tools




All times are GMT. The time now is 06:04 AM.

VBulletin, Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO ©2007, Crawlability, Inc.
Copyright ©2007 - 2008, www.linux-archive.org