Post #2938703
2026-05-15 07:20 UTC
Replies (4)
-
@hyc@mastodon.social 2026-05-15 07:35
The only reason FreeIPA uses 389DS instead of OpenLDAP is because RedHat paid $25M to acquire Netscape's assets and they needed to protect their investment from being cannibalized by OpenLDAP. That's also why they explicitly rejected the OpenLDAP Project's contribution of patches to support OpenLDAP in FreeIPA. Not because OpenLDAP lacked the necessary features or performance. Because they knew nobody would use their decrepit old server if given a choice. https://mastodon.social/@hyc/115834028708458926
-
@hyc@mastodon.social 2026-05-15 09:32
Of course, systemd-journald can't keep up at that rate. It crashes or hangs, so we had to write our own logger that doesn't use syslog any more. https://git.openldap.org/openldap/openldap/-/blob/master/servers/slapd/logging.c?ref_type=heads
-
@synlogic4242@social.vivaldi.net 2026-05-15 08:33
@hyc@mastodon.social I once thought about getting a T-shirt that read, "I don't even get out of bed unless I can shave off nanoseconds."
-
@mbpaz@mas.to 2026-05-15 10:15
@hyc@mastodon.social I had deployed OpenLDAP in our university lab in the late 90's. Then in 1999 at a new job I had to evaluate whether to deploy OpenLDAP or the "robust, tested, well supported" IBM Directory Server. The documentation for IBM Directory Server: "This product is based on OpenLDAP."