Audit LDAP transport and certificate validation #6

Open
opened 2026-08-23 17:07:47 +00:00 by stanta · 0 comments
Owner

Outcome

Ensure each LDAP client uses validated LDAPS or StartTLS where supported.

Current state

LDAP transport and certificate validation have not been audited across all FreeIPA clients.

Work

  • Audit Authelia.
  • Audit Grafana and other direct LDAP clients.
  • Audit Warpgate.
  • Audit scripts that query FreeIPA.
  • Replace plaintext LDAP where supported.
  • Record justified exceptions.

Validation

  • Login and group lookup pass for every changed client.
  • Certificate validation failures are not suppressed.
  • Remaining plaintext clients have a recorded reason.

References

  • iac/guides/roadmap-phase-2.md
  • iac/ansible/roles/authelia/
  • iac/ansible/roles/warpgate/
## Outcome Ensure each LDAP client uses validated LDAPS or StartTLS where supported. ## Current state LDAP transport and certificate validation have not been audited across all FreeIPA clients. ## Work - [ ] Audit Authelia. - [ ] Audit Grafana and other direct LDAP clients. - [ ] Audit Warpgate. - [ ] Audit scripts that query FreeIPA. - [ ] Replace plaintext LDAP where supported. - [ ] Record justified exceptions. ## Validation - [ ] Login and group lookup pass for every changed client. - [ ] Certificate validation failures are not suppressed. - [ ] Remaining plaintext clients have a recorded reason. ## References - `iac/guides/roadmap-phase-2.md` - `iac/ansible/roles/authelia/` - `iac/ansible/roles/warpgate/`
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
stanta/homelab#6
No description provided.