I've got 389 Directory Server running on RHEL 5 with groups, users, posix etc. RHEL clients are authenticating users with LDAP - no problems, everything works perfect, but passwords are sent in plaintext and are visible with network sniffer. So, decided to run with SSL: Created CA - got both private and public CA certificates Default LDAP ports are 389 (ldap://) and 636 (ldaps://). TLS ¶ Whether you want to use TLS , that is typically start with an connection on default port 389 and then set up an encrypted connection.