On 8/12/26 9:12 AM, Howard Chu wrote:
Realistically, no company exposes their directory infrastructure to the public Internet. There have been many DoS's via leftover asserts in the code thru the years, but none of these have ever been associated with reports of actual attacks.
I know of some universities that purposely do expose a partial DIT to the world, very deliberately, and reasonably. I would never recommend this, but some do this.
A good security team would not imagine DOS as possible from only the internet. Internal DOS, often of the friendly-fire sort, happens, and with it, often degradation of security infra. A well-built identity and PAM system will be engineered to be resilient in the face of an LDAP outage, but usually won't like one for very long.
It's trivial to overwhelm an OpenLDAP server with simple hardware and simple client script. I wish that would be less easy to do.