bump tls version, enforce strong ciphers
This commit is contained in:
@@ -5,6 +5,8 @@
|
|||||||
attributes:
|
attributes:
|
||||||
olcTLSCertificateFile: "{{ ldap_cert_path }}"
|
olcTLSCertificateFile: "{{ ldap_cert_path }}"
|
||||||
olcTLSCertificateKeyFile: "{{ ldap_key_path }}"
|
olcTLSCertificateKeyFile: "{{ ldap_key_path }}"
|
||||||
|
olcTLSProtocolMin: "3.3" # TLS 1.2+
|
||||||
|
olcTLSCipherSuite: HIGH:!aNULL:!MD5
|
||||||
args:
|
args:
|
||||||
server_uri: ldapi:///
|
server_uri: ldapi:///
|
||||||
sasl_mech: EXTERNAL
|
sasl_mech: EXTERNAL
|
||||||
|
|||||||
Reference in New Issue
Block a user