S 4.385 Configuration of the database used by OpenLDAP

Initiation responsibility: Head of IT, IT Security Officer

Implementation responsibility: Administrator

In OpenLDAP, settings for the actually used database management system (DBMS) can be made using configuration directives. The settings can only be made for the BerkeleyDB using the "back-bdb" or "back-hdb" backends. They do not have a direct impact on the function and operation of OpenLDAP, but have major effects on the performance of the directory service. In the following, only security-relevant settings and frequent sources of error are listed. For other settings, a database specialist should be consulted if necessary. For example, advantages in terms of higher performance at the expense of optimum integrity result from the temporary storage and transaction log settings, which must be weighed up carefully on a case-by-case basis.

Review questions: