The 389 Directory Server (previously Fedora-DS) is an LDAP (Lightweight Directory Access Protocol) server developed by Red Hat, as part of Red Hat's community-supported Fedora Project. 389 Directory Server is identical to the Red Hat Directory Server, just rebranded. The name 389 is derived from the port number for LDAP.
Questions tagged [389-ds]
58 questions
0
votes
3 answers
Is it possible for 389 Directory Server to do read-only AD sync?
Goal: Have 389DirectoryServer (AKA Redhat/Centos/Fedora DS) pull account info from AD, allowing both AD accounts and 389-native accounts be authenticated through 389DS, but have the sync be one way, AD->389. We don't want accidental/malicious…

Orangutech
- 290
- 4
- 14
0
votes
1 answer
How can I start Fedora Directory Service with SELinux enabled?
I just did a fresh base install of fedora 12, and did a yum install 389-ds. I went through the included setup script (setup-ds-admin.pl) and everything started fine and was working normally. I could access the directory server and login using the…

TrueDuality
- 1,874
- 5
- 27
- 37
0
votes
0 answers
Load Balancer for LDAP(S)
I have created a load balancer in the cloud with backend servers running FreeIPA.
When I try to run:
$ ldapsearch -x -H ldap: -b "dc=example,dc=com
ldap_sasl_bind(SIMPLE): Can't contact LDAP server (-1)
However, it's possible to contact…

N. J
- 131
- 5
0
votes
1 answer
LDAP replication to server with Let's Encrypt certificate fails, "unable to get issuer certificate"
I am currently trying to set up LDAP replication between to instances of 389 Directory Server (both running on Fedora 37), which I'll call $SUPPLIER and $CONSUMER in the following (serving at the domains supplier.mydomain.example and…

TuringTux
- 51
- 7
0
votes
0 answers
ldap password policy for other attributes
Say, you have a user with a normal password attribute, userPassword, and an apllication-password attribute, appPassword, that are not the same and also have a different hash-scheme.
In OpenLDAP, you can define password policies with ObjectClass…
0
votes
0 answers
Understanding default permissions in 389-DS
Importing an LDIF from an OpenLDAP server and examining the ACIs found, I don't really understand how default permissions are established:
I only found these two ACIs (LDIF unfolded):
dn:…

U. Windl
- 366
- 3
- 17
0
votes
1 answer
OpenLDAP to 389-DS: Can I have "named password policies"?
I'm trying to understand how "password policy" works in 389-DS, compared to OpenLDAP 2.4:
In OpenLDAP 2.4 I could define multiple "named" password policy entries, and assign those to user entries.
For example I had a policy "interactive users"…

U. Windl
- 366
- 3
- 17
0
votes
1 answer
Where can I find documentation for 389-DS on SLES15?
The version of 389-DS shipped with SLES15 SP3 is 1.4.4.19, and I wonder where the corresponding documentation can be found:
389 Directory Server refers to Product Documentation for Red Hat Directory Server 12 and I wonder whether the SLES version…

U. Windl
- 366
- 3
- 17
0
votes
1 answer
Why does my 389-ds configuration work over LDAP but not LDAPS?
Sorry if this has been asked before, but when I searched for similar issues, I got results like these (that make no sense to me).
I've been trying to set up 389-ds using Red Hat's Directory Server 11 documentation on two fully-updated Rocky Linux…

Russ
- 1
- 2
0
votes
0 answers
OpenLDAP/ds-389 Secure Hardening Guide
I am in the process of setting up an Open Ldap Server (ds-389) however, I cannot find many good resources which define a security or hardening guide which can be applied to the configuration or schema of the directory.
Does anyone have any good…

sfalzon
- 1
0
votes
1 answer
389DS multi master replication with TLS
I would like to replace our existing Directory Server with 389DS multi master replication. Also TLS need to enable for sssd client configuration.
I have searched on internet and did single 389DS but I am not able to configure TLS properly. Could…

MOBIN TM
- 3
- 1
-1
votes
1 answer
How to configure 389ds LDAP for idle user timeout
For my application till now i was using Java code for timing out the inactive user session from application. But for the purpose of upgrading it, want to use 389ds LDAP (my application is already integrated with 389ds LDAP).
I don't find any…

pramod_pams
- 1
- 1
-4
votes
2 answers
Is Active Directory backup as flexible as OpenLDAPs or 389-ds's?
With 389-ds I can export my entire directory using db2ldif and import it into a new directory server using ldif2db without any issues; even in catastrophic failure situations.
Now, the question is with Active Directory; can I do the same thing…
user101130