SSF enforces key length or something else? I didn't quite understand what
it is all about.
вт, 31 янв. 2023 г., 17:09 Rob Crittenden <rcritten(a)redhat.com>:
Alex Ivanov via FreeIPA-users wrote:
> Greetings,
>
> I'm struggling to find a comprehensive guide on how to block LDAP and
389 port on FreeIPA and force usage of LDAPS and 636 port for all clients
and connections. I would really appreciate a link or a hint.
IPA requires port 389 and uses startTLS/GSSAPI to encrypt its connections.
You can try setting minSSF to reject unencrypted requests (except for
the basedn).
rob