Re: DNS feature doesn't work with LDAPS
[
Date Prev][
Date Next]
[
Thread Prev][
Thread Next]
Re: DNS feature doesn't work with LDAPS
- From: Michael Ströder <michael [at] stroeder.com>
- To: nss-pam-ldapd-users [at] lists.arthurdejong.org
- Subject: Re: DNS feature doesn't work with LDAPS
- Date: Fri, 5 Nov 2021 12:57:00 +0100
On 11/4/21 20:43, Albert Akchurin wrote:
DNS is a great feature that allows effortless reinstall/modification of
LDAP servers.
DNS SRV lookup is not specified to be used with LDAPS. Especially there
is no well-defined equivalent to the TLS hostname check defined for this
use-case.
So when using DNS SRV lookups there's no cryptographic binding between
your the URI ldaps:///dc=example,dc=com in your LDAP client config and
the public-key in the TLS server cert.
So for security reasons you should not rely on that. Or let *all* your
LDAP clients verify DNS lookups with DNSSEC which would require to use a
local validating resolver on 127.0.0.1 or integrate DNSSEC validation in
your LDAP clients.
(And of course I very well understand why you'd love to use it. So no
need to argue.)
Ciao, Michael.