Pinned LDAPS
Require port 636 and constant-time SHA-256 server-certificate pin validation.
2AYE now registers certificate-pinned LDAPS connectors, confines changes to a configured base DN, prepares privacy-preserving exact-change fingerprints, consumes a single-use runtime authorization before LDAP execution, and records success or failure receipts.
Require port 636 and constant-time SHA-256 server-certificate pin validation.
Refuse target or member distinguished names outside the configured base DN.
Bind add member, remove member, or disable account to the agent, environment, connector, and hashed exact target.
Redeem once before LDAP and record an execution receipt; replay and parameter substitution never reach the adapter.
Each consequential action moves through the same six control points. See where 2AYE evaluates authority, requests human review, and preserves the outcome.
Identify tenant, identities, resources, and policy inputs.
Create the required records and immutable policy versions.
Reject missing, stale, cross-tenant, or insufficient authority.
Inspect audit evidence and improve the control.