← Back to projectsTechnical case

389 Directory Server and enterprise LDAP

Context

A robust directory service was needed to centralize authentication and policies across Linux systems.

Approach

Designed and implemented 389 Directory Server with CA and server certificates, TLS, a secondary node, multimaster replication, password and lockout policies, SUDOers OU and SSSD client integration.

Outcome

A documented, replicated and operable identity service with clear administration and troubleshooting procedures.

Technical highlights

  • 389 Directory Server
  • LDAP
  • TLS
  • PKI
  • Multimaster replication
  • SSSD
  • Password policies