Skip to content

Support for stopTLS: Downgrade LDAP Connection from TLS to Plaintext after Successful Bind #188

Description

@divakarm1984

We are using the UnboundID LDAP SDK in a high-throughput environment where LDAP is used for authentication and directory operations. As part of our security requirements, all initial communication with the LDAP server must be encrypted using TLS (via the StartTLS extended operation). This ensures that the bind request, including user credentials, is transmitted securely over the network.

Once the StartTLS handshake is complete and the bind operation has successfully authenticated the user, the sensitive part of the communication is over. The subsequent LDAP operations (searches, compares, lookups, etc.) in our use case do not carry confidential data and do not require transport-level encryption. Therefore, we would like to downgrade the already established TLS connection back to plaintext on the same socket, instead of tearing down and re-establishing a new connection.

On high-throughput machines, the cost of encrypting and decrypting every LDAP message adds significant CPU overhead and latency. By performing a stopTLS operation after authentication, we can eliminate this per-message cryptographic overhead while still ensuring that authentication itself was performed securely. This approach gives us the best of both worlds: secure credential exchange during bind and efficient, low-overhead communication afterwards.

We kindly request the UnboundID team to consider adding support for the stopTLS operation in the SDK, ideally as a method (e.g., stopTLS()) on the LDAPConnection object, symmetric to the existing StartTLS support. This would allow applications to programmatically downgrade an authenticated TLS connection back to plaintext on the same socket, in line with the TLS layering semantics described in RFC 4511 (Section 4.14) and supported by several LDAP server implementations.

With stopTLS support, applications using the UnboundID SDK will be able to optimize resource usage on high-volume LDAP clients and servers, reduce CPU consumption associated with TLS encryption/decryption, and increase overall throughput, while still maintaining strong security for the authentication phase. This will be particularly valuable for performance-sensitive systems such as telecom, large-scale web platforms, and any service performing a high rate of LDAP operations per second.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions