Userdir Ldap
Channel | Revision | Published | Runs on |
---|---|---|---|
latest/stable | 152 | 08 Sep 2025 | |
latest/stable | 151 | 08 Sep 2025 | |
latest/stable | 150 | 08 Sep 2025 | |
latest/stable | 149 | 08 Sep 2025 | |
latest/stable | 148 | 08 Sep 2025 | |
latest/stable | 147 | 08 Sep 2025 | |
latest/stable | 146 | 08 Sep 2025 | |
latest/stable | 145 | 08 Sep 2025 | |
latest/stable | 144 | 08 Sep 2025 | |
latest/stable | 143 | 08 Sep 2025 | |
latest/stable | 142 | 08 Sep 2025 | |
latest/stable | 141 | 08 Sep 2025 | |
latest/stable | 12 | 14 Feb 2023 | |
latest/stable | 6 | 09 Feb 2022 | |
latest/stable | 2 | 01 Feb 2021 | |
latest/candidate | 152 | 08 Sep 2025 | |
latest/candidate | 151 | 08 Sep 2025 | |
latest/candidate | 150 | 26 Aug 2025 | |
latest/candidate | 149 | 26 Aug 2025 | |
latest/candidate | 148 | 26 Aug 2025 | |
latest/candidate | 147 | 26 Aug 2025 | |
latest/candidate | 146 | 26 Aug 2025 | |
latest/candidate | 145 | 26 Aug 2025 | |
latest/candidate | 144 | 26 Aug 2025 | |
latest/candidate | 143 | 26 Aug 2025 | |
latest/candidate | 142 | 26 Aug 2025 | |
latest/candidate | 141 | 26 Aug 2025 | |
latest/candidate | 12 | 11 Jan 2023 | |
latest/candidate | 7 | 09 Feb 2022 | |
latest/candidate | 4 | 21 Jul 2021 | |
latest/edge | 164 | 08 Sep 2025 | |
latest/edge | 163 | 08 Sep 2025 | |
latest/edge | 162 | 08 Sep 2025 | |
latest/edge | 161 | 08 Sep 2025 | |
latest/edge | 160 | 08 Sep 2025 | |
latest/edge | 159 | 08 Sep 2025 | |
latest/edge | 158 | 08 Sep 2025 | |
latest/edge | 157 | 08 Sep 2025 | |
latest/edge | 156 | 08 Sep 2025 | |
latest/edge | 155 | 08 Sep 2025 | |
latest/edge | 154 | 08 Sep 2025 | |
latest/edge | 153 | 08 Sep 2025 | |
latest/edge | 12 | 27 Nov 2024 |
juju deploy userdir-ldap
Deploy universal operators easily with Juju, the Universal Operator Lifecycle Manager.
Platform:
Security Hardening Guidance
SSH configuration
Here’s a comprehensive list of improvements and considerations for hardening the charm:
-
Stick with curve25519-sha256 as the default
kex-algorithms
charm option and never use weaker algorithms such as diffie-hellman-group14-sha1 or any SHA-1 based KEX algorithms. -
Consider removing or avoiding
aes128-gcm
from the ciphers charm configuration, since AES-256 is more secure and doesn’t come with a significant performance penalty on modern hardware. Run the following command for increasing the security:
juju config userdir-ldap ciphers="chacha20-poly1305@openssh.com,aes256-gcm@openssh.com"
Consider removing or not using non-ETM versions like hmac-sha2-256
in the macs
configuration. You can also consider dropping umac-128-etm
as it provides only 128-bit integrity, which might be considered insufficient for some environments.Run the following command for increasing the security:
juju config userdir-ldap macs="hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com"