What is the most elegant and efficient way to provide AAA to web services using WS Gateway and LDAP?

I am looking for the best way to provide authorization, authentication, and auditing to web services. I will use the web service gateway device deployed in the DMZ, and there will be an LDAP instance as the repository of users behind the firewall. How to build it?

Greetings

K.A.

Update As indicated in the answer below, LDAP is not ideal for auditing. Now we look at the call of our CRM system for this function, since we can check the client’s use.

+3
source share
1 answer

. (, "uid" ). , , DN .

" ", , , " ", , "groupOfNames" " DN " member ".

, . LDAP, , . , , syslog.

+4

Source: https://habr.com/ru/post/1699303/


All Articles