Ben's notes

Linux, Unix, network, radio...

User Tools

Site Tools


openldap_centos7_tls

Link to this comparison view

Both sides previous revisionPrevious revision
Next revision
Previous revision
Next revisionBoth sides next revision
openldap_centos7_tls [2015/09/10 18:43] – [CentOS 7 - OpenLDAP 2.4 provider (master)] adminopenldap_centos7_tls [2015/09/10 21:44] – [Install and configure OpenLDAP] admin
Line 12: Line 12:
   * Minimum SSF 256 (recommended by manual).   * Minimum SSF 256 (recommended by manual).
   * No anonymous binds.   * No anonymous binds.
-  * Users can change own password, nothing else (cannot alter UID/GID etc). +  * Users can only change own password, nothing else (cannot alter UID/GID etc). 
-  * Users can only see their own password hash, not from others.+  * Users cannot see password hashes.
   * Use the default repo packages (note: uses MozNSS instead of OpenSSL).   * Use the default repo packages (note: uses MozNSS instead of OpenSSL).
   * SELinux enabled.   * SELinux enabled.
Line 156: Line 156:
 replace: olcTLSProtocolMin replace: olcTLSProtocolMin
 olcTLSProtocolMin: 3.1 olcTLSProtocolMin: 3.1
-- 
-replace: olcSaslSecProps 
-olcSaslSecProps: noanonymous,noplain,forwardsec,minssf=256 
 - -
 replace: olcDisallows replace: olcDisallows
openldap_centos7_tls.txt · Last modified: 2021/10/09 15:14 by 127.0.0.1