Re: start_tls versus ldaps

At 09:30 AM 8/13/2004, Imobach González Sosa wrote:
>First, thanks ViSolve and Axel for your replies.
>El Jueves, 12 de Agosto de 2004 13:12, ViSolve OpenLDAP Support escribió:
>> StartTLS standard was defined with LDAPv3.Here we can have LDAP requests
>> after a connection is established.With this approach,a single listener can
>> be used for both cleartext and TLS-encrypted sessions.This is more
>> flexible, since we don't need to maintain a separate listener for encrypted
>> sessions.
>Ok, I see. But if I wanna "force" encrypted sessions, can I do it using TLS? 

Note that TLS (either by StartTLS or ldaps://) is not the only way
to provide data security for LDAP.  SASL also supports data security
layers.  Anyways, see slapd.conf(5) for various ways of requiring
data security.  IIRC, this is also discussed in the Admin Guide
security considerations.

>I've "googled" and I've seen some references, but nothing clear at all.

