OpenLDAP
Industry-standard open source
OpenLDAP, Active Directory, 389 Directory Server, OpenDJ, Apache DS, Oracle Internet Directory, implemented, migrated, replicated, and hardened. Sub 5ms bind latency. SSO bridging to SAML and OIDC. 90+ deployments. ISO 27001 aligned.
LDAP Deployments: 90+
LDAP Deployments
Bind Latency: < 5ms
Bind Latency
Directory Uptime: 99.99%
Directory Uptime
Years Shipping: 12+
Years Shipping
DIT Tree
Entry attributes
Entries
4,238
Bind
3.2ms
Replicas
4 / 4
TLS
1.3 ✓











Three categories of work. Each service shows the command or LDIF snippet that defines what we deliver.
Custom OpenLDAP deployments with slapd configuration, schema design, ACL rules, replication, and TLS hardening. From single-server to N-way multi-master.
AD bridging, sync to OpenLDAP, AD LDS deployments, group policy integration, Kerberos cross-realm trusts, RODC topology.
Red Hat / Fedora 389 Directory Server implementation with replication, multi-master setup, sync to AD, performance tuning.
OpenDJ (formerly Sun DSEE) implementation, REST LDAP gateway, ForgeRock DS upgrade paths, cross-realm replication.
Custom objectClass and attribute definitions, OID assignment, schema migration, deprecation handling, RFC-compliant schemas.
Multi-master (syncrepl, MMR), consumer-supplier topologies, failover, geo-distributed replicas with conflict resolution.
LDAP backend behind SAML, OIDC, OAuth2 IdPs (Keycloak, Authentik, Auth0). MFA addition via TOTP, WebAuthn, push.
AD to OpenLDAP, Oracle Directory to 389 DS, legacy NIS/NIS+ to LDAP. LDIF migration with validated dry-run, zero-downtime cutover.
TLS / StartTLS, SASL (GSSAPI, DIGEST-MD5), ACI audits, password policy, performance tuning, 24/7 Sev-1 SLA.
30-minute call with a senior IAM engineer plus a written audit of your current directory: schema health, ACI rules, replication topology, TLS posture, bind latency, and a migration plan if needed. Delivered in 3 business days. No obligation.
Not a reseller. The directory in your scope is the one that fits your applications, infrastructure, and identity roadmap, not the one with the highest commission.
Industry-standard open source
Microsoft enterprise IAM
Red Hat / Fedora directory
Java-based, REST gateway
Embeddable Java LDAP
Oracle stack IAM
Lightweight AD for apps
AD-compatible on Linux
Bespoke LDAPv3 service
Eight features that drive 90% of platform decisions. Use the matrix to shortlist before the discovery call.
Still unsure? Get a free 30-min consult →
Predictable, milestone-tracked, milestone-billed. Hardened to ISO 27001 and CIS benchmarks at every phase.
Current-state audit of directories, identity sources, applications, and downstream consumers. Output: written scope, schema gap analysis, and migration plan.
Custom objectClass / attribute design, OID assignment, replication topology, partition strategy, naming context layout. Reviewed before any deploy.
slapd / AD / 389 DS install, TLS certificates, SASL, ACI rules, indexes, password policy. Hardened to ISO 27001 / CIS benchmarks.
Multi-master (syncrepl, MMR), consumer-supplier, geo-distributed replicas. Failover testing, replication lag monitoring.
LDIF export and validated import from legacy directory or AD. Schema mapping, attribute transforms, dedupe, dry-run sign-off before cutover.
LDAP behind SAML/OIDC IdP (Keycloak, Authentik, Auth0), application bind, Kerberos cross-realm, SCIM provisioning, MFA addition.
Phased cutover by application or department. 2-week hypercare with daily health checks, bind latency monitoring, ACI audit, escalation path.
98% on-time go-live against the originally signed SOW date.
Verified by 90+ production LDAP deployments. The same metrics we report in every quarterly business review.
90+
LDAP Deployments
Across 8 platforms
< 5ms
Bind Latency
On hardened deployments
99.99%
Directory Uptime
Multi-master replication
12+
Years in Production
Senior IAM engineers
ISO
27001 Aligned Process
Security-first delivery
24 / 7
Sev-1 SLA
Enterprise support tier
Education
42k accounts migrated
University system
Migrated 42,000 student and staff accounts from legacy NDS to OpenLDAP with synced AD for Windows clients. Zero password reset required, federated to Shibboleth IdP.
Financial Services
< 5ms bind latency
Regional bank
389 Directory Server cluster with 4-way multi-master replication across 2 datacentres. SAML federation to 87 internal applications. Passed SOC 2 Type II on first audit.
Government
FIPS 140-2 cert
Federal contractor
OpenLDAP hardened to FIPS 140-2 with Kerberos cross-realm trust to government AD. PIV smart card auth, encrypted at rest, full audit trail.
“They redesigned a directory schema that had grown chaotically over 15 years. The replatform took 3 months and broke nothing downstream. That is rare.”
“Bind latency went from 80ms to under 5ms after their tuning sprint. Login storms that used to take down the directory are a non-event now.”
“They added MFA in front of our LDAP without changing a single application binding. The auditors signed off the same week.”
Three engagement models. Fixed-price for clear deployments. T&M for evolving roadmaps. Fully managed for hands-off operations.
New directory or replatform
starting · fixed scope
Ongoing optimization
per hour · 2-week sprints
Fully managed LDAP
per month · 24/7 SLA
Enterprise IT and IAM
Employee SSO + provisioning
Higher Education
Shibboleth + EduPerson
Healthcare
HIPAA + clinician auth
Government and Defense
PIV + FIPS + Kerberos
Financial Services
SOX + bind auditing
Telecom and ISP
Subscriber LDAP at scale
SaaS and Tech
B2B federation + SCIM
Manufacturing
Shop-floor + OT identity
Directory Servers
Protocols + Standards
IdP and SSO
Federation Bridges
Tools and Monitoring
Compliance + Audit
A single-server OpenLDAP or 389 DS deployment with TLS, basic schema, and migration starts at $15,000 to $40,000 for a 3 to 8 week build. Multi-master replicated deployments with HA, SSO bridging, and MFA addition run $30,000 to $120,000+ over 6 to 16 weeks. Managed directory service starts at $3,500 per month for 24/7 monitoring and patching. We share a written fixed-price scope after a free 30-minute discovery call.
OpenLDAP for high-performance, low-overhead deployments on Linux with full schema control. Active Directory when you need native Windows integration, group policy, and Microsoft identity stack. 389 Directory Server for Red Hat or Fedora environments needing strong replication and a familiar console. OpenDJ (Java-based) for environments wanting a REST LDAP gateway and rich extensibility. We benchmark these against your application portfolio, infrastructure, and identity roadmap on the discovery call.
Single-server OpenLDAP or 389 DS: 3 to 8 weeks. Multi-master replicated cluster: 6 to 14 weeks. Migration from Active Directory or legacy NDS / NIS+: 8 to 20 weeks. LDAP-behind-IdP integration (SAML or OIDC bridge): 4 to 10 weeks added. Custom schema design and 100+ application binding: 12 to 24 weeks. We commit to dates in writing in the SOW with weekly milestone tracking.
Yes. We move users, groups, organizational units, ACLs, and Kerberos principals. Schema is mapped between AD-style attributes (sAMAccountName, userPrincipalName) and inetOrgPerson / posixAccount where needed. Migration uses validated LDIF dry-runs, sync periods, and phased cutover by application. Hybrid setups (OpenLDAP + AD synced) are common during transition periods.
We put LDAP behind a modern IdP — Keycloak, Authentik, Auth0, Okta, Shibboleth, or ADFS — so legacy LDAP-bound applications keep working while new applications use SAML, OIDC, or OAuth. The IdP handles MFA, social login, and federation; LDAP remains the source of truth for identities. We also support SCIM provisioning for outbound sync to SaaS apps.
Yes. We deploy an IdP (Keycloak, Authentik, or commercial) in front of LDAP that handles MFA (TOTP, WebAuthn, push notifications, hardware tokens) while presenting an LDAP bind interface to downstream applications. Most applications see no change. Where they do, we provide migration support to native SAML or OIDC.
TLS / StartTLS on every connection, modern cipher suites only, mutual TLS for replication. SASL: GSSAPI for Kerberos cross-realm trust, DIGEST-MD5 for backward compatibility, EXTERNAL for client cert auth. ACI rules tested and audited (rolesAllowed, groupdnattr). Password policy: history, lockout, complexity. ISO 27001 / CIS benchmarks applied as baseline.
Yes. OpenLDAP syncrepl with N-way multi-master (MMR), 389 DS multi-master with up to 20 masters, OpenDJ replication with conflict resolution, AD multi-master inheritance. We design topologies for geo-distributed deployments, calculate replication bandwidth, and instrument monitoring with Prometheus + cn=monitor.
Yes. Fully managed LDAP starting at $3,500/month: 24/7 Sev-1 incident response, monthly patching, replication health monitoring, capacity planning, quarterly security audit, and on-call escalation. We host on your AWS, Azure, GCP, or OCI account so you own the infrastructure. For sovereign deployments, on-premise managed service is available.
Index tuning (eq, sub, pres, approx on hot attributes), connection pooling, persistent search optimization, slapd / 389 DS / OpenDJ tuning per platform. Typical results: bind latency under 5ms, 10,000+ binds/sec on commodity hardware, query latency under 10ms on 1M+ entries. Read replicas for scaling, multi-master for write availability.
Retainer plans from 40 hours per month (patches, schema additions, ACL changes, small integrations) up to fully managed directory service ($3,500/month with 24/7 SLA). Quarterly business reviews covering bind latency, replication lag, ACL coverage, password policy compliance, and capacity headroom.
You do. Configuration lives in your Git repo (slapd.d, dse.ldif, ansible playbooks). Servers run on your infrastructure (AWS / Azure / GCP / on-prem) on your billing. We hand over schema docs, ACI rules, replication topology diagrams, runbooks, monitoring dashboards, and admin training. No vendor lock-in to us.
A senior IAM engineer reads your brief, runs a free 30-minute discovery call, and delivers a written audit with a fixed-price deployment estimate. No deck. No obligation.
Get Started
Tell us about your directory
30 minute call. Written LDAP audit in 3 days. No pitch deck.
Encrypted in transit · NDA on request
Share your scope. A senior developer reviews it, walks you through the trade-offs, and sends a written summary after the call. NDA before any details are discussed.
30 minute call. Written summary after. No pitch deck.