OpenLDAP & generic LDAP
Nova manages accounts, group memberships, and passwords directly in OpenLDAP and other LDAP directories, treating them as first-class target systems.
What Nova does with OpenLDAP & generic LDAP
- Creates user entries, updates attributes, and deletes accounts on offboarding; the current state is read before every change and recorded in the change journal
- Manages posixGroup memberships in OpenLDAP as well as groupOfNames groups in generic directories; the matching profile is configured per system
- Locks accounts in OpenLDAP via the ppolicy lock and in generic directories by removing the password; when re-enabling, Nova generates a fresh password from your ruleset
- Sets passwords via the RFC 3062 password modify operation, falling back to the userPassword attribute where needed
- Resolves nested groups and reconciles actual memberships in the directory against the desired entitlements in Nova
- Rolls back changes in a controlled way, including restoring deleted entries with their group memberships from the change journal
Technical integration
Nova connects over LDAP/LDAPS using declarative directory profiles for OpenLDAP and generic LDAP (such as ApacheDS); entries are referenced by entryUUID. Supporting another directory means adding a profile, not building a new connector.
In the identity lifecycle
Joiner, mover, and leaver events are provisioned straight into the directory through lifecycle routines: create the account, adjust attributes, lock the account. Approved requests become group memberships in the directory, and recertification checks the actual state rather than a cached copy.
All product names, logos and brands mentioned are property of their respective owners. They are referenced solely to describe compatibility and do not imply any partnership or endorsement.