Free Online Course · Self-paced

389 Directory Server Tutorial: Complete Administration Guide

Learn 389 Directory Server administration from installation and instance creation to ACIs, TLS, plugins, password policies, LMDB tuning, backup, replication, monitoring, migration, and troubleshooting.

  • 84 parts
  • ~1358 min total
  • Beginner to Advanced
  • Updated Jul 2026
389 Directory Server Tutorial: Complete Administration Guide
By Last updated

389 Directory Server is the upstream LDAP server behind Red Hat Directory Server and the directory component inside FreeIPA. Unlike distribution-specific guides that bury the product under Rocky Linux or RHEL packaging, this course teaches 389 Directory Server administration: instance lifecycle, backends, ACIs, plug-ins, replication, and client integration, using the official CLI tools that ship with the product.

Once the package is installed, the main administration interfaces belong to 389 Directory Server itself. dscreate provisions instances. dsctl commands handle local and offline instance operations such as status, backup, import, and restore. dsconf commands change a running server's configuration over LDAP. dsidm commands manage directory data: users, groups, and organizational units. Optional Cockpit integration adds a browser console, but the CLI remains the baseline this course tests against. For general Linux tooling used alongside these guides, browse our Linux commands reference.

This is a product-focused 389 Directory Server course tested on selected Linux distributions. Core administration procedures apply to equivalent 389 Directory Server versions, while installation, service management, firewall, and security-framework commands may differ by distribution. We do not claim every procedure works identically everywhere because repository versions vary significantly.

If LDAP terminology is new, read LDAP and OpenLDAP basics in the OpenLDAP tutorial. If you are choosing between LDAP servers or migrating from OpenLDAP, read OpenLDAP vs 389 Directory Server. If you already run 389 Directory Server, jump to Install 389 Directory Server and the dscreate guides. Every article is self-contained. Each guide lists its own prerequisites and suggested next steps, so you do not need to read the course in order.


Platform compatibility

389 Directory Server packages are available across multiple Linux families, although versions and packaging differ.

Platform family Installation method Core course status
RHEL family and Fedora dnf command Fully suitable
Debian and Ubuntu apt Suitable; package version may differ
SLES and supported openSUSE releases zypper Suitable where the package is available
Arch Linux pacman Suitable; generally newer upstream version
Containers Official 389 DS container image Separate deployment track
NOTE
SUSE documentation treats 389 Directory Server as its LDAP server and documents installation, instance setup, backup, TLS, and replication end to end. openSUSE Leap releases may differ. For example, openSUSE Leap 16 currently has no official 389-ds-base package listed. Check your distribution repositories before planning a lab.
IMPORTANT
This course assumes LMDB as the default backend for newly created instances on 389 Directory Server 3.x. Older installations may still run Berkeley DB. Backend migration is covered in a dedicated article. Do not assume BDB tuning guidance applies to LMDB instances without checking your version.

Administration tools at a glance

Tool Scope Typical tasks
dscreate Instance provisioning Interactive or inf-file instance creation, backend selection
dsctl Local instance Start/stop, backup, restore, LDIF import/export, offline maintenance
dsconf Online configuration Listeners, replication agreements, indexes, plug-ins, logging
dsidm Directory data Users, groups, organizational units, password resets
Cockpit (cockpit-389-ds) Optional GUI Instance overview, entry browser, basic ACI editing

Version numbers appear in each article's tested-environment box, not in canonical URLs. When a command flag or default changed between 2.x and 3.x, the article calls it out inline.

What you'll learn

  • Install 389 Directory Server on supported Linux distributions and create a production-style instance with dscreate
  • Operate instances with dsctl, dsconf, and dsidm for configuration, data, backup, and maintenance
  • Secure the directory with TLS, ACIs, SASL binds, and password policies
  • Tune LMDB backends, indexes, logging, and monitoring for day-two operations
  • Build supplier, consumer, and multi-supplier replication topologies
  • Integrate Linux clients and applications, and migrate data from OpenLDAP or local /etc/passwd sources

Prerequisites

  • One or more Linux VMs or containers for replication and client-integration labs
  • Root or sudo command access on lab hosts
  • Basic command-line skills (systemctl, firewall tools, text editing)
  • LDAP fundamentals — read LDAP and OpenLDAP basics in the OpenLDAP tutorial if DNs, suffixes, or schema are new

Syllabus

11 chapters · 84 lessons · ~1358 min of reading

  1. 1 Installation & instance basics 5 lessons
    1. Part 1 Architecture — instances, backends, plug-ins 13 min read
    2. Part 2 Install 389 Directory Server 20 min read
    3. Part 3 dscreate inf file reference 11 min read
    4. Part 4 Run multiple instances on one host 15 min read
    5. Part 5 Non-root instance (development) 11 min read
  2. 2 Administration CLI 3 lessons
    1. Part 6 dsctl — local and offline operations 14 min read
    2. Part 7 dsconf — online configuration 13 min read
    3. Part 8 dsidm — users, groups, directory data 12 min read
  3. 3 Backup, upgrade & maintenance 3 lessons
    1. Part 9 Back up and restore 15 min read
    2. Part 10 Update and upgrade safely 25 min read
    3. Part 11 Migrate Berkeley DB to LMDB 21 min read
  4. 4 Migration & replication 17 lessons
    1. Part 12 Replication architecture and topology 14 min read
    2. Part 13 Single-supplier replication setup 15 min read
    3. Part 14 Cascading replication setup 20 min read
    4. Part 15 Multi-supplier replication setup 20 min read
    5. Part 16 Manage replication agreements 21 min read
    6. Part 17 Configure fractional replication 15 min read
    7. Part 18 Manage replication changelog 14 min read
    8. Part 19 Monitor replication and lag 19 min read
    9. Part 20 Troubleshoot replication failures 16 min read
    10. Part 21 Initialize and reinitialize replicas 13 min read
    11. Part 22 Promote or demote a replica 18 min read
    12. Part 23 Remove a replica from the topology 16 min read
    13. Part 24 CleanAllRUV stale replica IDs 11 min read
    14. Part 25 Certificate-based replication authentication 27 min read
    15. Part 26 Migrate to a new server 37 min read
    16. Part 27 Migrate from OpenLDAP 31 min read
    17. Part 28 Restore a replicated server 21 min read
  5. 5 Directory data & schema 15 lessons
    1. Part 29 Suffixes and backends 18 min read
    2. Part 30 Export and import LDIF 17 min read
    3. Part 31 Manage users and groups 13 min read
    4. Part 32 Configure the memberOf plug-in 17 min read
    5. Part 33 Configure Referential Integrity 18 min read
    6. Part 34 Configure Auto Membership 15 min read
    7. Part 35 Configure Managed Entries and Linked Attributes 18 min read
    8. Part 36 Enforce unique LDAP attributes 15 min read
    9. Part 37 Assign UID and GID with DNA 19 min read
    10. Part 38 Roles vs groups 13 min read
    11. Part 39 Class of Service (CoS) 16 min read
    12. Part 40 Rename and move LDAP entries 14 min read
    13. Part 41 Generate test data with ldifgen 15 min read
    14. Part 42 Create custom schema 14 min read
    15. Part 43 Read-only databases and instances 7 min read
  6. 6 Advanced directory features 3 lessons
    1. Part 44 LDAP referrals 14 min read
    2. Part 45 Database chaining 14 min read
    3. Part 46 Directory views 11 min read
  7. 7 TLS, certificates & authentication 9 lessons
    1. Part 47 TLS, STARTTLS, and LDAPS 16 min read
    2. Part 48 TLS versions and cipher suites 17 min read
    3. Part 49 Require secure LDAP connections 16 min read
    4. Part 50 Client certificate authentication 16 min read
    5. Part 51 SASL GSSAPI and Kerberos 18 min read
    6. Part 52 Certificate management 25 min read
    7. Part 53 FIPS mode 20 min read
    8. Part 54 Attribute encryption 11 min read
    9. Part 55 Restrict anonymous access 14 min read
  8. 8 Password policy & access control 10 lessons
    1. Part 56 Password storage schemes 16 min read
    2. Part 57 Global, subtree, and user password policy 21 min read
    3. Part 58 Account lockout 14 min read
    4. Part 59 Disable and inactivate user accounts 17 min read
    5. Part 60 ACI examples 18 min read
    6. Part 61 Advanced ACI targets and bind rules 14 min read
    7. Part 62 Self-service password and profile ACIs 12 min read
    8. Part 63 Delegated administration 24 min read
    9. Part 64 Macro ACIs 17 min read
    10. Part 65 Get Effective Rights — test ACI permissions 19 min read
  9. 9 Client and application integrations 3 lessons
    1. Part 66 SSSD LDAP authentication 14 min read
    2. Part 67 SSH public keys with SSSD 13 min read
    3. Part 68 Apache LDAP authentication 16 min read
  10. 10 Troubleshooting library 8 lessons
    1. Part 69 Fix LDAP error 49 — invalid credentials 11 min read
    2. Part 70 Fix LDAP error 50 — insufficient access 11 min read
    3. Part 71 Fix LDAP error 53 — unwilling to perform 14 min read
    4. Part 72 Fix LDAP error 65 — object class violation 12 min read
    5. Part 73 Fix LDAP works but LDAPS fails 13 min read
    6. Part 74 Fix missing or stale memberOf 13 min read
    7. Part 75 Fix slow LDAP searches 13 min read
    8. Part 76 Reset Directory Manager password 8 min read
  11. 11 Performance and production operations 8 lessons
    1. Part 77 Configure LDAP indexes 13 min read
    2. Part 78 Configure LDAP search limits 12 min read
    3. Part 79 Configure threads and connections 9 min read
    4. Part 80 Virtual List View indexes 15 min read
    5. Part 81 Tune LMDB and caches 16 min read
    6. Part 82 Configure low disk space protection 18 min read
    7. Part 83 Benchmark performance with ldclt 28 min read
    8. Part 84 Tune large groups and memberOf 18 min read
Deepak Prasad

R&D Engineer

Founder of GoLinuxCloud with more than 15 years of expertise in Linux, Python, Go, Laravel, DevOps, Kubernetes, Git, Shell scripting, OpenShift, AWS, Networking, and Security. With extensive experience, he excels across development, DevOps, networking, and security, delivering robust and efficient solutions for diverse projects.

  • Go (programming language)
  • Python (programming language)
  • DevOps
  • Computer Security
  • Cloud Computing
  • Kubernetes
  • Linux
  • Ansible (software)