SSF enforces key length or something else? I didn't quite understand what it is all about.
Alex Ivanov via FreeIPA-users wrote:
> Greetings,
>
> I'm struggling to find a comprehensive guide on how to block LDAP and 389 port on FreeIPA and force usage of LDAPS and 636 port for all clients and connections. I would really appreciate a link or a hint.
IPA requires port 389 and uses startTLS/GSSAPI to encrypt its connections.
You can try setting minSSF to reject unencrypted requests (except for
the basedn).
rob