[Freeipa-users] By default on port 389 , any encryption between client and server

Rob Crittenden rcritten at redhat.com
Wed Feb 12 13:42:23 UTC 2014


barrykfl at gmail.com wrote:
> Hi all:
> Some doc said it already build in TLS on 389 ... is it nsslapd-minssf on
> the dse.ldif?

Yes.

> Should i need to set 636 ldaps ? or set higher nsslapd-minssf enough?

Higher minssf should be enough. It will require GSSAPI or startTLS on a 
connection.

> What document tell the default secure connection of free ipa?

I don't believe we have everything in one place. The LDAP security 
settings are available at 
https://access.redhat.com/site/documentation/en-US/Red_Hat_Directory_Server/9.0/html/Administration_Guide/SecureConnections.html

rob




More information about the Freeipa-users mailing list