Alex Ivanov via FreeIPA-users wrote:
Greetings,
I'm struggling to find a comprehensive guide on how to block LDAP and 389 port on
FreeIPA and force usage of LDAPS and 636 port for all clients and connections. I would
really appreciate a link or a hint.
IPA requires port 389 and uses startTLS/GSSAPI to encrypt its connections.
You can try setting minSSF to reject unencrypted requests (except for
the basedn).
rob