Search the docs

Best Practices

Name service resolution order. The resolution order affects both performance and which entry is used when a name exists in more than one domain. Put the domain that holds most of the commonly used names first, rather than simply the closest server. If you have duplicate names across domains, configure the order so that the entry you want is found first, or have users and applications use qualified names.

If several servers hold most of the same names, identify the fastest connection and order the name services accordingly. If you experience identity-lookup delays, contact Hammerspace Support for troubleshooting assistance.

Use LDAPS or StartTLS, and configure the server by the name on its certificate. Plain LDAP sends lookups, and the bind secret if you use one, in clear text. With LDAPS or StartTLS, configure the server address exactly as it appears in the certificate’s Subject Alternative Name (SAN) extension — usually the server’s DNS name. See Securing LDAP Connections with LDAPS or StartTLS.

Set the transport mode explicitly in production. If you leave the transport mode unset, the connection test chooses the first mode that works, trying StartTLS, then LDAPS, then plain LDAP. If the secure modes are blocked or misconfigured — including when the server certificate does not name the address you configured — the test falls back to plain LDAP if the server accepts it, and the name service is saved unencrypted. Setting the transport mode makes the add or update fail instead.

Use a read-only bind account. If your directory requires a Bind DN, use a dedicated account that can only read the user and group entries.

Verify before you rely on the configuration. After adding or changing a name service, look up a known user and group with User/Group Lookup or --resolve-user before users mount shares. The lookup exercises the same SSSD path that NFS uses; the connection test does not.