you could set minssf:
On 11/18/2015 07:24 AM, Prashant Bapat wrote:
We have a pair of freeipa servers (4.1.4) and a bunch of Linux clients
configured to talk to them thru pam-nss-ldapd (no sssd). I want to
ensure that these clients only talk to freeipa's LDAP server either
via ldaps or ldap+starttls. Plain ldap should not be allowed.
I can always switch to ldaps only and close the tcp/389 port on the
firewall. But is there a way to achieve this using tcp/389 port.?
Any suggestions appreciated.
Manage your subscription for the Freeipa-users mailing list:
Go to http://freeipa.org for more info on the project