LDAP and Directory Services

Directory services that hold up. Identity that scales.

OpenLDAP, Active Directory, 389 Directory Server, OpenDJ, Apache DS, Oracle Internet Directory, implemented, migrated, replicated, and hardened. Sub 5ms bind latency. SSO bridging to SAML and OIDC. 90+ deployments. ISO 27001 aligned.

  • OpenLDAP certified
  • Microsoft Identity
  • Oracle IDM partner
  • Apache committers
  • ISO 27001 aligned
  • LDAP Deployments: 90+

    LDAP Deployments

  • Bind Latency: < 5ms

    Bind Latency

  • Directory Uptime: 99.99%

    Directory Uptime

  • Years Shipping: 12+

    Years Shipping

Trusted by 150+ teams across 35+ countries

  • UnitedHealthcare logo, client of Decipher Zone
  • Indeed logo, client of Decipher Zone
  • Boston Beer logo, client of Decipher Zone
  • Comviva logo, client of Decipher Zone
  • Arkadium logo, client of Decipher Zone
  • Letshego logo, client of Decipher Zone
  • Cerebrum logo, client of Decipher Zone
  • Farm Fetch logo, client of Decipher Zone
  • IDDO logo, client of Decipher Zone
  • MyComplianceOffice logo, client of Decipher Zone
  • VIDA logo, client of Decipher Zone
  • Marra Forni logo, client of Decipher Zone
What We Offer

Nine LDAP services, grouped by intent.

Three categories of work. Each service shows the command or LDIF snippet that defines what we deliver.

Build and Configure

4 services
  • OpenLDAP Development

    /01

    Custom OpenLDAP deployments with slapd configuration, schema design, ACL rules, replication, and TLS hardening. From single-server to N-way multi-master.

  • Active Directory Integration

    /02

    AD bridging, sync to OpenLDAP, AD LDS deployments, group policy integration, Kerberos cross-realm trusts, RODC topology.

  • 389 Directory Server

    /03

    Red Hat / Fedora 389 Directory Server implementation with replication, multi-master setup, sync to AD, performance tuning.

  • OpenDJ / ForgeRock DS

    /04

    OpenDJ (formerly Sun DSEE) implementation, REST LDAP gateway, ForgeRock DS upgrade paths, cross-realm replication.

Integrate and Bridge

3 services
  • LDAP Schema Design

    /05

    Custom objectClass and attribute definitions, OID assignment, schema migration, deprecation handling, RFC-compliant schemas.

  • Replication and HA

    /06

    Multi-master (syncrepl, MMR), consumer-supplier topologies, failover, geo-distributed replicas with conflict resolution.

  • LDAP to SSO Bridging

    /07

    LDAP backend behind SAML, OIDC, OAuth2 IdPs (Keycloak, Authentik, Auth0). MFA addition via TOTP, WebAuthn, push.

Operate and Secure

2 services
  • LDAP Migration

    /08

    AD to OpenLDAP, Oracle Directory to 389 DS, legacy NIS/NIS+ to LDAP. LDIF migration with validated dry-run, zero-downtime cutover.

  • Support and Hardening

    /09

    TLS / StartTLS, SASL (GSSAPI, DIGEST-MD5), ACI audits, password policy, performance tuning, 24/7 Sev-1 SLA.

Limited 3 audits this month

Free LDAP and IAM audit worth $2,000

30-minute call with a senior IAM engineer plus a written audit of your current directory: schema health, ACI rules, replication topology, TLS posture, bind latency, and a migration plan if needed. Delivered in 3 business days. No obligation.

Directory Platforms We Master

Nine directory platforms. One honest recommendation.

Not a reseller. The directory in your scope is the one that fits your applications, infrastructure, and identity roadmap, not the one with the highest commission.

  • OpenLDAP

    Industry-standard open source

  • Active Directory

    Microsoft enterprise IAM

  • 389 Directory Server

    Red Hat / Fedora directory

  • OpenDJ / ForgeRock DS

    Java-based, REST gateway

  • Apache Directory Server

    Embeddable Java LDAP

  • Oracle Internet Directory

    Oracle stack IAM

  • AD LDS

    Lightweight AD for apps

  • Samba 4

    AD-compatible on Linux

  • Custom BuildWe pick

    Bespoke LDAPv3 service

Compare Directories Side by Side

OpenLDAP vs AD vs 389 DS vs OpenDJ. Honest comparison.

Eight features that drive 90% of platform decisions. Use the matrix to shortlist before the discovery call.

OpenLDAP

Open source
Yes
OS native
Linux
Replication
N-way MMR
REST gateway
Add-on
Kerberos cross-realm
Yes
License cost
Free
Schema flexibility
Full
Best for
Linux IAM

Active Directory

Open source
No
OS native
Windows
Replication
Multi-master
REST gateway
No
Kerberos cross-realm
Native
License cost
Per CAL
Schema flexibility
Limited
Best for
Windows shop

389 DS

Open source
Yes
OS native
Linux
Replication
MMR
REST gateway
Add-on
Kerberos cross-realm
Yes
License cost
Free
Schema flexibility
Full
Best for
Red Hat

OpenDJ

Open source
Yes
OS native
Cross
Replication
Multi-master
REST gateway
Built-in
Kerberos cross-realm
Yes
License cost
Free
Schema flexibility
Full
Best for
Java apps

Custom

Open source
Yes
OS native
Cross
Replication
Custom
REST gateway
Built-in
Kerberos cross-realm
Custom
License cost
Free
Schema flexibility
Full
Best for
Unique needs

Still unsure? Get a free 30-min consult →

Our Process

Seven phases. Secured by default.

Predictable, milestone-tracked, milestone-billed. Hardened to ISO 27001 and CIS benchmarks at every phase.

  1. Phase 1 / 7

    Discovery and Directory Audit

    Current-state audit of directories, identity sources, applications, and downstream consumers. Output: written scope, schema gap analysis, and migration plan.

  2. Phase 2 / 7

    Schema and Topology Design

    Custom objectClass / attribute design, OID assignment, replication topology, partition strategy, naming context layout. Reviewed before any deploy.

  3. Phase 3 / 7

    Deploy and Configure

    slapd / AD / 389 DS install, TLS certificates, SASL, ACI rules, indexes, password policy. Hardened to ISO 27001 / CIS benchmarks.

  4. Phase 4 / 7

    Replication and HA Setup

    Multi-master (syncrepl, MMR), consumer-supplier, geo-distributed replicas. Failover testing, replication lag monitoring.

  1. Phase 5 / 7

    Data Migration

    LDIF export and validated import from legacy directory or AD. Schema mapping, attribute transforms, dedupe, dry-run sign-off before cutover.

  2. Phase 6 / 7

    Integration Wiring

    LDAP behind SAML/OIDC IdP (Keycloak, Authentik, Auth0), application bind, Kerberos cross-realm, SCIM provisioning, MFA addition.

  3. Phase 7 / 7

    Cutover and Hypercare

    Phased cutover by application or department. 2-week hypercare with daily health checks, bind latency monitoring, ACI audit, escalation path.

98% on-time go-live against the originally signed SOW date.

Why Decipher Zone

Numbers, not adjectives.

Verified by 90+ production LDAP deployments. The same metrics we report in every quarterly business review.

  • Metric 01LIVE

    90+

    LDAP Deployments

    Across 8 platforms

  • Metric 02LIVE

    < 5ms

    Bind Latency

    On hardened deployments

  • Metric 03LIVE

    99.99%

    Directory Uptime

    Multi-master replication

  • Metric 04LIVE

    12+

    Years in Production

    Senior IAM engineers

  • Metric 05LIVE

    ISO

    27001 Aligned Process

    Security-first delivery

  • Metric 06LIVE

    24 / 7

    Sev-1 SLA

    Enterprise support tier

Replication syncedTLS 1.3 enforcedACI audited
Results We Have Shipped

Three production wins. Dozens more on the shelf.

  • Education

    42k accounts migrated

    University system

    Migrated 42,000 student and staff accounts from legacy NDS to OpenLDAP with synced AD for Windows clients. Zero password reset required, federated to Shibboleth IdP.

    • OpenLDAP
    • AD Sync
    • Shibboleth
  • Financial Services

    < 5ms bind latency

    Regional bank

    389 Directory Server cluster with 4-way multi-master replication across 2 datacentres. SAML federation to 87 internal applications. Passed SOC 2 Type II on first audit.

    • 389 DS
    • SAML
    • SOC 2
  • Government

    FIPS 140-2 cert

    Federal contractor

    OpenLDAP hardened to FIPS 140-2 with Kerberos cross-realm trust to government AD. PIV smart card auth, encrypted at rest, full audit trail.

    • OpenLDAP
    • Kerberos
    • FIPS
What Clients Say

4.9 / 5 across 2,495 reviews.

  • They redesigned a directory schema that had grown chaotically over 15 years. The replatform took 3 months and broke nothing downstream. That is rare.
    IAM LeadHealthcare network
  • Bind latency went from 80ms to under 5ms after their tuning sprint. Login storms that used to take down the directory are a non-event now.
    Infrastructure DirectorUniversity system
  • They added MFA in front of our LDAP without changing a single application binding. The auditors signed off the same week.
    CISORegional bank
Pricing and Engagement

Transparent pricing. No hidden change orders.

Three engagement models. Fixed-price for clear deployments. T&M for evolving roadmaps. Fully managed for hands-off operations.

New directory or replatform

Implementation Sprint

$30,000

starting · fixed scope

  • Discovery + schema design
  • Deploy + replication + TLS
  • Migration + UAT
  • 30-day hypercare
  • Runbooks + admin training
Get a fixed quote
Most popular

Ongoing optimization

Time and Material

$60

per hour · 2-week sprints

  • 2-week sprint cadence
  • Live priority queue
  • Live demo every Friday
  • Monthly burn reports
  • Pause or cancel anytime
Start a sprint

Fully managed LDAP

Managed Directory Service

$3,500

per month · 24/7 SLA

  • 24/7 Sev-1 incident response
  • Monthly patching + updates
  • Replication health monitoring
  • Quarterly security audit
  • Capacity planning
Outsource your directory
Industries Served

Vertical-aware IAM engineering.

  • Enterprise IT and IAM

    Employee SSO + provisioning

  • Higher Education

    Shibboleth + EduPerson

  • Healthcare

    HIPAA + clinician auth

  • Government and Defense

    PIV + FIPS + Kerberos

  • Financial Services

    SOX + bind auditing

  • Telecom and ISP

    Subscriber LDAP at scale

  • SaaS and Tech

    B2B federation + SCIM

  • Manufacturing

    Shop-floor + OT identity

Our Tech Stack

LDAP-grade, production-tested.

Directory Servers

  • OpenLDAP
  • Active Directory
  • 389 DS
  • OpenDJ
  • Apache DS
  • Oracle ID
  • AD LDS
  • Samba 4

Protocols + Standards

  • LDAPv3
  • SASL
  • Kerberos
  • GSSAPI
  • StartTLS
  • mTLS
  • RFC 4511
  • RFC 4519

IdP and SSO

  • Keycloak
  • Authentik
  • Auth0
  • Okta
  • Shibboleth
  • ADFS
  • PingFederate

Federation Bridges

  • SAML 2.0
  • OpenID Connect
  • OAuth 2.0
  • SCIM 2.0
  • CAS
  • WS-Federation

Tools and Monitoring

  • Apache Directory Studio
  • JXplorer
  • LdapAdmin
  • OpenLDAP cn=monitor
  • Prometheus
  • Grafana

Compliance + Audit

  • ISO 27001
  • SOC 2
  • HIPAA
  • GDPR
  • FIPS 140-2
  • CIS Benchmarks
Common Questions

Twelve questions we hear on every call.

How much does LDAP implementation cost in 2026?

A single-server OpenLDAP or 389 DS deployment with TLS, basic schema, and migration starts at $15,000 to $40,000 for a 3 to 8 week build. Multi-master replicated deployments with HA, SSO bridging, and MFA addition run $30,000 to $120,000+ over 6 to 16 weeks. Managed directory service starts at $3,500 per month for 24/7 monitoring and patching. We share a written fixed-price scope after a free 30-minute discovery call.

OpenLDAP vs Active Directory vs 389 DS vs OpenDJ, which one should I pick?

OpenLDAP for high-performance, low-overhead deployments on Linux with full schema control. Active Directory when you need native Windows integration, group policy, and Microsoft identity stack. 389 Directory Server for Red Hat or Fedora environments needing strong replication and a familiar console. OpenDJ (Java-based) for environments wanting a REST LDAP gateway and rich extensibility. We benchmark these against your application portfolio, infrastructure, and identity roadmap on the discovery call.

How long does an LDAP implementation take?

Single-server OpenLDAP or 389 DS: 3 to 8 weeks. Multi-master replicated cluster: 6 to 14 weeks. Migration from Active Directory or legacy NDS / NIS+: 8 to 20 weeks. LDAP-behind-IdP integration (SAML or OIDC bridge): 4 to 10 weeks added. Custom schema design and 100+ application binding: 12 to 24 weeks. We commit to dates in writing in the SOW with weekly milestone tracking.

Can you migrate from Active Directory to OpenLDAP (or any directory to any other)?

Yes. We move users, groups, organizational units, ACLs, and Kerberos principals. Schema is mapped between AD-style attributes (sAMAccountName, userPrincipalName) and inetOrgPerson / posixAccount where needed. Migration uses validated LDIF dry-runs, sync periods, and phased cutover by application. Hybrid setups (OpenLDAP + AD synced) are common during transition periods.

How do you bridge LDAP to modern SSO (SAML, OIDC, OAuth)?

We put LDAP behind a modern IdP — Keycloak, Authentik, Auth0, Okta, Shibboleth, or ADFS — so legacy LDAP-bound applications keep working while new applications use SAML, OIDC, or OAuth. The IdP handles MFA, social login, and federation; LDAP remains the source of truth for identities. We also support SCIM provisioning for outbound sync to SaaS apps.

Can you add MFA in front of an existing LDAP without changing applications?

Yes. We deploy an IdP (Keycloak, Authentik, or commercial) in front of LDAP that handles MFA (TOTP, WebAuthn, push notifications, hardware tokens) while presenting an LDAP bind interface to downstream applications. Most applications see no change. Where they do, we provide migration support to native SAML or OIDC.

How do you handle directory security, ACI, TLS, SASL, and Kerberos?

TLS / StartTLS on every connection, modern cipher suites only, mutual TLS for replication. SASL: GSSAPI for Kerberos cross-realm trust, DIGEST-MD5 for backward compatibility, EXTERNAL for client cert auth. ACI rules tested and audited (rolesAllowed, groupdnattr). Password policy: history, lockout, complexity. ISO 27001 / CIS benchmarks applied as baseline.

Do you support LDAP replication (multi-master, syncrepl, MMR)?

Yes. OpenLDAP syncrepl with N-way multi-master (MMR), 389 DS multi-master with up to 20 masters, OpenDJ replication with conflict resolution, AD multi-master inheritance. We design topologies for geo-distributed deployments, calculate replication bandwidth, and instrument monitoring with Prometheus + cn=monitor.

Do you offer managed LDAP / directory-as-a-service?

Yes. Fully managed LDAP starting at $3,500/month: 24/7 Sev-1 incident response, monthly patching, replication health monitoring, capacity planning, quarterly security audit, and on-call escalation. We host on your AWS, Azure, GCP, or OCI account so you own the infrastructure. For sovereign deployments, on-premise managed service is available.

How do you handle LDAP performance and scale?

Index tuning (eq, sub, pres, approx on hot attributes), connection pooling, persistent search optimization, slapd / 389 DS / OpenDJ tuning per platform. Typical results: bind latency under 5ms, 10,000+ binds/sec on commodity hardware, query latency under 10ms on 1M+ entries. Read replicas for scaling, multi-master for write availability.

What ongoing support do you offer after LDAP go-live?

Retainer plans from 40 hours per month (patches, schema additions, ACL changes, small integrations) up to fully managed directory service ($3,500/month with 24/7 SLA). Quarterly business reviews covering bind latency, replication lag, ACL coverage, password policy compliance, and capacity headroom.

Who owns the LDAP infrastructure, configuration, and data after launch?

You do. Configuration lives in your Git repo (slapd.d, dse.ldif, ansible playbooks). Servers run on your infrastructure (AWS / Azure / GCP / on-prem) on your billing. We hand over schema docs, ACI rules, replication topology diagrams, runbooks, monitoring dashboards, and admin training. No vendor lock-in to us.

Start your LDAP project

Send a brief. Get an LDAP audit in 3 days.

A senior IAM engineer reads your brief, runs a free 30-minute discovery call, and delivers a written audit with a fixed-price deployment estimate. No deck. No obligation.

  • Reply within 1 business day
  • Senior engineer on every call (not a sales rep)
  • NDA signed on request before any detail is shared
  • Configuration, data, and infrastructure are yours from day one

Get Started

Tell us about your directory

Engineers available this week

30 minute call. Written LDAP audit in 3 days. No pitch deck.

Encrypted in transit · NDA on request

Free 30-minute consultation

Talk to senior engineers, not salespeople.

Share your scope. A senior developer reviews it, walks you through the trade-offs, and sends a written summary after the call. NDA before any details are discussed.

  • Written estimate within 5 business days
  • Senior engineer on the first call
  • Code stays in your repository
  • ISO 9001 certified shop
4.9 / 5from 2,495 reviews
350+ builds shipped

Talk to Senior Engineers

Available

30 minute call. Written summary after. No pitch deck.

NDA signed before any project details are shared