Elektrine lite

← Feed

@hyc@mastodon.social

Post #2938704

2026-05-15 07:35 UTC

The only reason FreeIPA uses 389DS instead of OpenLDAP is because RedHat paid $25M to acquire Netscape's assets and they needed to protect their investment from being cannibalized by OpenLDAP. That's also why they explicitly rejected the OpenLDAP Project's contribution of patches to support OpenLDAP in FreeIPA. Not because OpenLDAP lacked the necessary features or performance. Because they knew nobody would use their decrepit old server if given a choice. https://mastodon.social/@hyc/115834028708458926

Replies (1)

  • @hyc@mastodon.social 2026-05-15 08:31

    Fyi, the email thread where using OpenLDAP for FreeIPA was discussed appears to have been scrubbed from Red Hat's email archives. A reference to it is here in 2009 https://lists.openldap.org/hyperkitty/list/openldap-technical@openldap.org/message/PJ3AEDS42JWGM2CJRNSQB4VUCN2WDKWS/ but RedHat's own archives only go back to 2017 now. One reason we still prefer email lists in the OpenLDAP Project is knowledge is shared and preserved indefinitely. The whole point of open source is sharing knowledge. I guess Red Hat doesn't care about that, either.

    Open ##2938705