Directories & identity providers

ConnectorStandard

OpenLDAP & generic LDAP

Nova manages accounts, group memberships, and passwords directly in OpenLDAP and other LDAP directories, treating them as first-class target systems.

Capabilities

What Nova does with OpenLDAP & generic LDAP

  • Entries with journal

    Creates user entries, updates attributes, and deletes accounts on offboarding; the current state is read before every change and recorded in the change journal.

  • posixGroup and groupOfNames

    Manages posixGroup memberships in OpenLDAP as well as groupOfNames groups in generic directories; the matching profile is configured per system.

  • Locking per profile

    Locks accounts in OpenLDAP via the ppolicy lock and in generic directories by removing the password; when re-enabling, Nova generates a fresh password from your ruleset.

  • Passwords per RFC 3062

    Sets passwords via the RFC 3062 password modify operation, falling back to the userPassword attribute where needed.

  • Target vs. actual

    Resolves nested groups and reconciles actual memberships in the directory against the desired entitlements in Nova.

  • Controlled rollback

    Rolls back changes in a controlled way, including restoring deleted entries with their group memberships from the change journal.

Technology and process

Integration and identity lifecycle

Technical integration

Nova connects over LDAP/LDAPS using declarative directory profiles for OpenLDAP and generic LDAP (such as ApacheDS); entries are referenced by entryUUID. Supporting another directory means adding a profile, not building a new connector.

In the identity lifecycle

Joiner, mover, and leaver events are provisioned straight into the directory through lifecycle routines: create the account, adjust attributes, lock the account. Approved requests become group memberships in the directory, and recertification checks the actual state rather than a cached copy.

More in the catalog

Related integrations

All product names, logos and brands mentioned are property of their respective owners. They are referenced solely to describe compatibility and do not imply any partnership or endorsement.

Next step

Ask your questions live on the system.

30 minutes via video call on the demo system: you name your use cases, we show the relevant functions.

Request a demo

What happens next

  1. ReplyWe usually get back to you on the same working day and agree a date with you.
  2. PreparationWe prepare the demo around the topics you name.
  3. 30 minutes via video callLive on the demo system with fictitious data: you ask, we show the relevant views.