Is it possible to block LDAP port 389 on IdM server to secure LDAP connections?
Issue
Unencrypted LDAP service was active on the TCP and UDP ports 389 on host. While this is expected in a default RedHat IdM configuration according to the documentation, lack of encryption during communication with the service could pose a risk in certain scenarios. For example, a malicious actor could MitM traffic and intercept the user or server LDAP authentication.
Can we block port 389 of the IdM server to secure the connections between IDM LDAP clients and IdM servers?
Environment
- Red Hat Enterprise Linux 7+
- Red Hat IdM
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.