SSF enforces key length or something else? I didn't quite understand what it is all about.

вт, 31 янв. 2023 г., 17:09 Rob Crittenden <rcritten@redhat.com>:
Alex Ivanov via FreeIPA-users wrote:
> Greetings,
>
> I'm struggling to find a comprehensive guide on how to block LDAP and 389 port on FreeIPA and force usage of LDAPS and 636 port for all clients and connections. I would really appreciate a link or a hint.

IPA requires port 389 and uses startTLS/GSSAPI to encrypt its connections.

You can try setting minSSF to reject unencrypted requests (except for
the basedn).

rob