LDAP · Active Directory · Identity infrastructure since 2001
I'm Chris Paul. For 25 years I've run the directories behind trading floors, hospitals, airlines and telecoms: OpenLDAP, Active Directory, 389/RHDS, ODSEE, FreeIPA, and the PKI that holds them together. Rex Consulting is the small practice I run for the part that can't fail, staffed with senior engineers I've worked with for years.
What I do
Identity infrastructure is the specialty. Monitoring and email security are the two things we've run alongside it for long enough to offer them properly.
Replication topology, schema, ACLs and PKI designed so the directory is boring. Migrations off ODSEE and Sun DS onto OpenLDAP, 389/RHDS or FreeIPA with no login outage.
Replication that quietly stopped, a directory nobody remembers how to change, an upgrade that went sideways at 2 a.m. We've done the 2 a.m. part before.
Mutual TLS, credential elimination, least-privilege ACLs, bind identities that can only do what they were meant to. Findings you can act on, not a report.
For the team that inherited a directory they didn't build. Hands-on, against their own environment, so it sticks.
Nagios, run by a Nagios Certified Administrator. Custom service checks tuned to your stack, alerts by email and SMS, and event handlers that fix the common failures before anyone is paged.
Proofpoint threat protection as a managed service, and Zimbra mailbox hosting with secure IMAP, calendaring and retention. Filtered before it reaches your network, with a person on the phone when you call.
Over 25 years and several firms. Some of these were direct engagements, some through prior employers.
How I work
I set the architecture and stay accountable for it. The engineering is done by senior people I've worked with for years, not a rotating bench. You'll know who is on your directory, and it won't change mid-engagement.
Authentication is the one system that takes everything else down with it. We plan every change so nobody notices it happened.
Flat, reviewable configuration. Monitoring that notices before people do. Recovery measured in minutes. The goal is a directory you can forget about.
What clients say
I have worked with Chris on two projects. He's always the first person I would call when LDAP challenges arise. Chris is self-directed, and highly-motivated. He's the type of consultant that you can give a task, and expect quick, quality results. He's become somewhat of a trusted advisor to top-management at my current client, and he only worked with us for a few short weeks.
Chris was in charge of designing and developing an LDAP solution for an Identity Management project. He did an excellent job of coming in and analyzing the situation and developing the correct solution. He designed and implemented the LDAP solution including interfaces with existing applications. He was focused, detailed oriented and committed to ensure that the job was done.
Chris has a very good understanding of the LDAP technology. With his help, we were able to deploy a complex LDAP deployment. I would recomend Chris for any LDAP consulting.
I have to tell you that I'm always impressed that I get a live person (and not a recording) on the line when I call with problems, and that you're always ready to investigate. That level of customer service is a rare thing these days. We really think a lot of Sentinare and the service you provide, and I appreciate your taking care of us.
Before switching to Sentinare two years ago, the Wayne Farms email servers received over 10,000 spam email messages per day. We had in house spam filtering software that only caught about 90% of incoming SPAM after it already arrived consuming a good percentage our internet bandwidth. We even fell victim to directory harvesting and denial of service attacks on a few occasions. For the past two years Sentinare has provided near 100% spam free email delivery to our company and our users have become accustomed to spam free messaging. We no longer worry about internet bandwidth being consumed by unwanted email. Sentinare email filtering has been one of the best investments we have made.
So far the managed service is awesome. Easy to deploy and easy user interface. So far our 65 users have had zero spam and zero viruses come through via Sentinare. Nice!
I have to meet the stringent requirements of the NASD (FINRA) in regards to email retention and I was lucky enough to find Sentinare to solve this problem. They create and send me a backup CD-ROM each month which we store off-site and also their system keeps all these historical emails online as well for recovery. Having the email scanned for virus issues before even reaching my network is also fantastic and has kept my employees from opening virus carrying emails.
Spam and junk is now at a absolute minimum. We have friends that use Yahoo.com so we could not block out the whole domain. Things are Much Much Better Now plus I feel that the company (and our home computer) are a lot safer.
I just signed up and I have had no SPAM in my inbox for several days. I have not had that experience in years. I am not exaggerating. That is the literal truth. Furthermore, my partner thinks I was a genius to find you guys. He loves having NO SPAM. I can't believe we put up with it for so long. Thanks!
You guys are great, it is nice not to have to worry about spam and viruses as much as before.
Sentinare was the name of Rex Consulting's managed email-security service.
About

I'm Chris Paul, and Rex Consulting is my practice. I've run identity and authentication infrastructure since 2001, in environments from quantitative trading to healthcare to federal energy, at scales up to the 500-million-entry directory I managed at AT&T. Before that I was a UNIX systems administrator, which is still how I think about a directory: it's a system, it has to be operable, and it has to survive the person who built it leaving.
I care about systems that are boring on purpose: certificate-based trust, no root credentials, recovery measured in minutes, and monitoring that notices problems before people do. I write about that work at ldapguys.com, and the older Nagios and security notes live here under Tech Tips.
Engagements are delivered by senior engineers I've worked alongside for years, on some of the largest directories in the country. They know LDAP and Nagios the way I do. I stay on the architecture and the accountability.
LinkedIn · ldapguys.com · Oakland, California
Contact
One conversation with someone who has run this at scale. Tell me what's keeping you up, and I'll tell you honestly whether we're the right people for it.