lists.arthurdejong.org
RSS feed

Re: DNS feature doesn't work with LDAPS

[Date Prev][Date Next] [Thread Prev][Thread Next]

Re: DNS feature doesn't work with LDAPS



On 11/4/21 20:43, Albert Akchurin wrote:
DNS is a great feature that allows effortless reinstall/modification of LDAP servers.

DNS SRV lookup is not specified to be used with LDAPS. Especially there is no well-defined equivalent to the TLS hostname check defined for this use-case.

So when using DNS SRV lookups there's no cryptographic binding between your the URI ldaps:///dc=example,dc=com in your LDAP client config and the public-key in the TLS server cert.

So for security reasons you should not rely on that. Or let *all* your LDAP clients verify DNS lookups with DNSSEC which would require to use a local validating resolver on 127.0.0.1 or integrate DNSSEC validation in your LDAP clients.

(And of course I very well understand why you'd love to use it. So no need to argue.)

Ciao, Michael.