| |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
3.5.3.9.1 Directory Services (Page 2 of 3) Lightweight Directory Access Protocol (LDAP) The most common protocol in use today for retrieval of information from directory services is the Lightweight Directory Access Protocol (LDAP), discussed in a prior section. LDAP requires port 389 to be open on your firewall if you want to allow LDAP-based Directory Service traffic between your internal LDAP server and other hosts on the Internet. To enable your internal hosts to query an LDAP server which sits outside your firewall, open port 389 in the outbound direction. To enable clients on the Internet to query an LDAP server on your internal network, open port 389 in the inbound direction. Most common directory services, such as Microsoft Active Directory (which stores the security policy information for the network and its users, among other things), Novell eDirectory (the service formerly known as NDS), Netscape iPlanet and OpenLDAP (an open-source project) communicate via LDAP. As you probably guessed by now, the usual caveats apply about running with the most up-to-date security patches and secure configuration settings. Since configuration settings are vendor-specific, see your vendor for details. For nice overviews of Active Directory and NDS, including security tips for NDS, see Directory Services Design, Implementation, and Management380 by Nancy Cox.
__________________ 380. Cox, Nancy, Directory Services Design, Implementation and Management, Digital Press, December, 2001, http://www.nerdbooks.com/item.html?id=1555582621
Home - Table Of Contents - Contact Us CertiGuide for Security+ (http://www.CertiGuide.com/secplus/) on CertiGuide.com Version 1.0 - Version Date: November 15, 2004 Adapted with permission from a work created by Tcat Houser et al. CertiGuide.com Version © Copyright 2004 Charles M. Kozierok. All Rights Reserved. Not responsible for any loss resulting from the use of this site. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||