LDAPCon 2026
6.–8. Oktober | Tübingen
Veranstaltungsprogramm
Eine Übersicht aller Sessions/Sitzungen dieser Veranstaltung.
Bitte wählen Sie einen Ort oder ein Datum aus, um nur die betreffenden Sitzungen anzuzeigen. Wählen Sie eine Sitzung aus, um zur Detailanzeige zu gelangen.
|
Tagesübersicht |
| Sitzung | |
|
Tales from integrating OpenLDAP with the modern world Florian Best Univention GmbH, Deutschland Ort: Museum, Uhlandsaal | |
| Präsentation 1 | |
Tales from integrating OpenLDAP with the modern world Univention GmbH, Deutschland OpenLDAP has been at the core of Univention Corporate Server (UCS) and Univention Nubus for 25 years. During that time, it has proven to be a reliable foundation for directory services, while the requirements around it have changed significantly. A central goal of Univention has always been to make LDAP-based identity management easier to use while integrating technologies such as Samba/Active Directory, Kerberos, and Keycloak into a common directory-based platform. Univention Directory Manager provides a management layer on top of LDAP to achieve that goal. This talk shares a selection of challenges and lessons learned from building and operating UCS and Nubus on top of OpenLDAP. Rather than presenting LDAP in theory, the focus is on practical problems that appeared in real deployments and the solutions we developed along the way. Topics include integrating OpenID Connect with OpenLDAP through the crudeOAuth SASL module, performance observations from memberOf and dynamic group resolution, insights into LDAP ACLs and delegated administration in complex OU structures, implementing a recycle bin for LDAP objects, and some tricky and security-relevant issues around Distinguished Name comparison and normalization. The talk concludes with a few ideas on where current LDAP-based solutions still require additional complexity and how some of these use cases could be supported more naturally in the future. Attendees can expect practical examples, engineering trade-offs, and a few stories from 25 years of building on top of OpenLDAP. | |
