diff --git a/servers/slapd/slapd.conf b/servers/slapd/slapd.conf index 3b7553c8e1..91dab7bdb0 100644 --- a/servers/slapd/slapd.conf +++ b/servers/slapd/slapd.conf @@ -22,7 +22,15 @@ argsfile %LOCALSTATEDIR%/slapd.args # moduleload back_passwd.la # moduleload back_shell.la +# Sample security restrictions # +# Disallow clear text exchange of passwords +# disallow bind_simple_unprotected +# +# Require integrity protection (prevent hijacking) +# Require 112-bit (3DES or better) encryption +# security ssf=1 ssf=112 + # Sample access control policy: # Allow read access of root DSE # Allow self write access