Questions tagged [389-ds]

The 389 Directory Server (previously Fedora-DS) is an LDAP (Lightweight Directory Access Protocol) server developed by Red Hat, as part of Red Hat's community-supported Fedora Project. 389 Directory Server is identical to the Red Hat Directory Server, just rebranded. The name 389 is derived from the port number for LDAP.

58 questions
0
votes
3 answers

Is it possible for 389 Directory Server to do read-only AD sync?

Goal: Have 389DirectoryServer (AKA Redhat/Centos/Fedora DS) pull account info from AD, allowing both AD accounts and 389-native accounts be authenticated through 389DS, but have the sync be one way, AD->389. We don't want accidental/malicious…
Orangutech
  • 290
  • 4
  • 14
0
votes
1 answer

How can I start Fedora Directory Service with SELinux enabled?

I just did a fresh base install of fedora 12, and did a yum install 389-ds. I went through the included setup script (setup-ds-admin.pl) and everything started fine and was working normally. I could access the directory server and login using the…
TrueDuality
  • 1,874
  • 5
  • 27
  • 37
0
votes
0 answers

Load Balancer for LDAP(S)

I have created a load balancer in the cloud with backend servers running FreeIPA. When I try to run: $ ldapsearch -x -H ldap: -b "dc=example,dc=com ldap_sasl_bind(SIMPLE): Can't contact LDAP server (-1) However, it's possible to contact…
N. J
  • 131
  • 5
0
votes
1 answer

LDAP replication to server with Let's Encrypt certificate fails, "unable to get issuer certificate"

I am currently trying to set up LDAP replication between to instances of 389 Directory Server (both running on Fedora 37), which I'll call $SUPPLIER and $CONSUMER in the following (serving at the domains supplier.mydomain.example and…
TuringTux
  • 51
  • 7
0
votes
0 answers

ldap password policy for other attributes

Say, you have a user with a normal password attribute, userPassword, and an apllication-password attribute, appPassword, that are not the same and also have a different hash-scheme. In OpenLDAP, you can define password policies with ObjectClass…
0
votes
0 answers

Understanding default permissions in 389-DS

Importing an LDIF from an OpenLDAP server and examining the ACIs found, I don't really understand how default permissions are established: I only found these two ACIs (LDIF unfolded): dn:…
U. Windl
  • 366
  • 3
  • 17
0
votes
1 answer

OpenLDAP to 389-DS: Can I have "named password policies"?

I'm trying to understand how "password policy" works in 389-DS, compared to OpenLDAP 2.4: In OpenLDAP 2.4 I could define multiple "named" password policy entries, and assign those to user entries. For example I had a policy "interactive users"…
U. Windl
  • 366
  • 3
  • 17
0
votes
1 answer

Where can I find documentation for 389-DS on SLES15?

The version of 389-DS shipped with SLES15 SP3 is 1.4.4.19, and I wonder where the corresponding documentation can be found: 389 Directory Server refers to Product Documentation for Red Hat Directory Server 12 and I wonder whether the SLES version…
U. Windl
  • 366
  • 3
  • 17
0
votes
1 answer

Why does my 389-ds configuration work over LDAP but not LDAPS?

Sorry if this has been asked before, but when I searched for similar issues, I got results like these (that make no sense to me). I've been trying to set up 389-ds using Red Hat's Directory Server 11 documentation on two fully-updated Rocky Linux…
Russ
  • 1
  • 2
0
votes
0 answers

OpenLDAP/ds-389 Secure Hardening Guide

I am in the process of setting up an Open Ldap Server (ds-389) however, I cannot find many good resources which define a security or hardening guide which can be applied to the configuration or schema of the directory. Does anyone have any good…
0
votes
1 answer

389DS multi master replication with TLS

I would like to replace our existing Directory Server with 389DS multi master replication. Also TLS need to enable for sssd client configuration. I have searched on internet and did single 389DS but I am not able to configure TLS properly. Could…
MOBIN TM
  • 3
  • 1
-1
votes
1 answer

How to configure 389ds LDAP for idle user timeout

For my application till now i was using Java code for timing out the inactive user session from application. But for the purpose of upgrading it, want to use 389ds LDAP (my application is already integrated with 389ds LDAP). I don't find any…
-4
votes
2 answers

Is Active Directory backup as flexible as OpenLDAPs or 389-ds's?

With 389-ds I can export my entire directory using db2ldif and import it into a new directory server using ldif2db without any issues; even in catastrophic failure situations. Now, the question is with Active Directory; can I do the same thing…
user101130
1 2 3
4