• English
  • Deutsch
  • Log In
    Password Login
    Research Outputs
    Fundings & Projects
    Researchers
    Institutes
    Statistics
Repository logo
Fraunhofer-Gesellschaft
  1. Home
  2. Fraunhofer-Gesellschaft
  3. Scopus
  4. Characterizing Hosting and Security Practices for Public-Facing LDAP Servers
 
  • Details
  • Full
Options
2025
Conference Paper
Title

Characterizing Hosting and Security Practices for Public-Facing LDAP Servers

Abstract
The Lightweight Directory Access Protocol (LDAP) is widely used to make structured data available for standardized lookup, which may sometimes include personal information or authentication credentials. Previous work, including ours, found security issues such as public LDAP servers leaking sensitive information without prior authentication and server configurations with poor communication security. However, prior work did not investigate whether, or to what extent, the identified problems are linked to hosting and management setups. In this paper, we address this gap and explore the organizations hosting publicfacing LDAP servers. We identify the network segments more likely to host LDAP instances, the products and operating systems used, and examine the management practices related to Public Key Infrastructure (PKI) setups for LDAP. In contrast to studies on Web and email, which have revealed strong centralization tendencies in deployment, we show that the LDAP ecosystem is diverse, with a wide range of different hosting networks. In this study, we identify 69.1 k LDAP instances- 6.5 × more than prior work-and map these to the respective LDAP products. We find that 5.8% of the servers use a product that is end-of-life or runs on a deprecated OS. We identify servers using problematic X. 509 certificates, e.g., those associated with publicly known private keys. From our observations, we give recommendations for network operators to improve their security posture.
Author(s)
Cesar, Gustavo Luvizotto
Universiteit Twente
Öndarö, Gurur
Fachhochschule Münster
Kaspereit, Jonas
Fachhochschule Münster
Ising, Fabian
Fraunhofer-Institut für Sichere Informationstechnologie SIT  
Schinzel, Sebastian
Fraunhofer-Institut für Sichere Informationstechnologie SIT  
Jonker, Mattijs
Universiteit Twente
Holz, Ralph G.
Universiteit Twente
Mainwork
21th International Conference on Network and Service Management CNSM 2025. Proceedings  
Funder
Bundesministerium für Forschung, Technologie und Raumfahrt  
Conference
International Conference on Network and Service Management 2025  
DOI
10.23919/CNSM67658.2025.11297453
Language
English
Fraunhofer-Institut für Sichere Informationstechnologie SIT  
Keyword(s)
  • hosting, and management practices

  • LDAP

  • network security

  • Cookie settings
  • Imprint
  • Privacy policy
  • Api
  • Contact
© 2024