FreeIPA
FreeIPA is an open-source, community-maintained identity management platform for Linux/Unix environments that integrates 389 Directory Server, MIT Kerberos, Dogtag PKI, SSSD, and DNS into a centralized SSO, authentication, and policy system serving enterprise IT teams and web application developers.
- Company typePrivate
- Founded-
- HeadquartersLondon, United Kingdom
- Headcount51–100
- GTM typeB2B
- OfferingSoftware
What FreeIPA does
FreeIPA is an open-source, community-maintained identity, policy, and audit (IdM) platform for Linux and Unix environments. It integrates multiple established open-source components into a unified system: Fedora Linux as the base, 389 Directory Server for LDAP-based identity storage, MIT Kerberos for authentication and authorization, NTP, BIND with the bind-dyndb-ldap driver for DNS, the Dogtag certificate system for PKI, and SSSD for OS-level identity delivery. The platform supports full multi-master replication for redundancy and scalability, and exposes its management surface through a CLI, Web UI, XML-RPC and JSON-RPC APIs, and a Python SDK. It enables centralized management of Linux users and client hosts, Single Sign-On via Kerberos, Host-Based Access Control (HBAC) policies, DNS, SUDO, SELinux, and autofs, and establishes mutual trust relationships with Microsoft Active Directory for cross-realm authentication.
The product is distributed as free open-source software through official downloads on freeipa.org, Fedora/RHEL package repositories via yum/dnf, and source builds on Codeberg. It serves enterprise IT infrastructure teams managing Linux estates, web application developers integrating SSO via Apache modules (mod_auth_gssapi, mod_authnz_pam, mod_lookup_identity, mod_auth_mellon), organizations operating multiple identity providers, and storage infrastructure teams integrating NFS, CIFS, Samba, and storage arrays (Dell EMC, NetApp, NexentaStor). FreeIPA has no direct revenue model; it is a community project under the "FreeIPA Team" and is distributed at no cost. Commercial support is available indirectly through Red Hat's Enterprise Linux Identity Management product, which is built on FreeIPA technology. The project is governed by community mailing lists, IRC channels, and a public demo instance, with active development evident in releases through 2024.
FreeIPA firmographics
Firmographics- Name
- FreeIPA
- Legal name
- FreeIPA Team
- Website
- https://freeipa.org
- Company type
- Private
- Operating status
- Operating
- Headcount range
- 51–100 employees
- Short description
- FreeIPA is an open-source, community-maintained identity management platform for Linux/Unix environments that integrates 389 Directory Server, MIT Kerberos, Dogtag PKI, SSSD, and DNS into a centralized SSO, authentication, and policy system serving enterprise IT teams and web application developers.
- Ownership category
- akta.pro rank
FreeIPA industry classification
Industry- Product category
- Identity Management Software
- NAICS
- Computer Systems Design and Related Services (54151)
- SIC
- Services-Prepackaged Software (7372)
- akta.pro primary industry
- Directory Services & Identity Stores (LDAP/AD, Cloud Directory) (HDAEAJAA)
- akta.pro secondary industries
- Single Sign-On (SSO) & Federation (SAML/OIDC, Identity Providers) (HDAEAJAB), Directory Services & Identity Data Platforms (BPAMAEAG)
Keywords
Where FreeIPA is headquartered
LocationHeadquarters
- HQ city
- London
- HQ country
- United Kingdom
- HQ region
- Europe
Markets served
FreeIPA business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Technology or R&D, Personnel, Operations, Others
Revenue model
- Open Source Software: FreeIPA is a free, open-source identity, policy, and audit solution. The project is community-driven with no direct revenue generation. Organizations may receive commercial support through Red Hat's Identity Management product which is based on FreeIPA.
Go-to-market motion1 record
Distribution channels4 records
Marketing channels8 records
FreeIPA product offering
Product offeringCore offering
FreeIPA is an open-source integrated identity, policy, and audit management solution for Linux and Unix environments. It combines 389 Directory Server, MIT Kerberos, NTP, DNS (BIND-dyndb-ldap), the Dogtag certificate system, and SSSD into a single platform that delivers centralized user and host management, Kerberos-based Single Sign-On authentication, and policy-based access control for DNS, SUDO, SELinux, and autofs. The platform exposes extensible management interfaces including a CLI, a Web UI, JSON-RPC and XML-RPC APIs, and a Python SDK, and supports mutual trust relationships with Microsoft Active Directory, full multi-master replication, certificate lifecycle management, and web application authentication through Apache modules.
Product overview
FreeIPA is an integrated open-source identity management system that combines Linux (Fedora), 389 Directory Server, MIT Kerberos, NTP, DNS, Dogtag certificate system, and SSSD into a unified platform. It provides centralized management of Linux users and client hosts through multiple interfaces: CLI, Web UI, XML-RPC API, JSON-RPC API, and Python SDK. The product offers Single Sign-On authentication via Kerberos, host-based access control (HBAC) policies, trust relationships with Microsoft Active Directory, certificate management, and DNS services. FreeIPA supports full multi-master replication for redundancy and scalability, with extensible management interfaces designed for ease of automation and configuration.
Differentiator
Problem solved
Functional benefit
Products and services
- FreeIPA (Identity, Policy, Audit) An integrated open-source identity, policy, and audit management platform combining Linux (Fedora), 389 Directory Server, MIT Kerberos, NTP, DNS (bind-dyndb-ldap), Dogtag certificate system, and SSSD. Provides centralized management of Linux users and client hosts, Single Sign-On authentication, Kerberos-based authorization policies for DNS, SUDO, SELinux, and autofs, mutual trust with Microsoft Active Directory, full multi-master replication for redundancy and scalability, and certificate lifecycle management. Designed for IT administrators managing Linux enterprise environments requiring centralized identity, authentication, and authorization.
- FreeIPA Client Client software that enrolls Linux and Unix machines into FreeIPA domains, enabling Single Sign-On authentication and centralized identity management for enrolled hosts. Supports various Unix platforms including FreeBSD, IBM AIX, Solaris, and HP-UX as client configurations. Targeted at system administrators enrolling servers and workstations into a centralized FreeIPA realm.
Companies that use FreeIPA
Customer profileSegments4 records
Ideal customer profiles3 records
FreeIPA technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration37 records
Feature9 records
FreeIPA partnerships and signals
Strategic signalPartnerships
Eight partnerships are on record, tiered core.
- 389 Directory ServercoreFreeIPA is built on 389 Directory Server as its core directory backend, providing LDAP-based identity storage and replication capabilities. This is a fundamental component dependency essential to FreeIPA's operation.
- MIT KerberoscoreFreeIPA uses MIT Kerberos for authentication and authorization, implementing Kerberos ticket management, S4U2Proxy delegation, and integration with the KDC.
- Dogtag Certificate SystemcoreFreeIPA incorporates Dogtag PKI for certificate management, CA operations, CRL management, and certificate enrollment services.
- SSSD (System Security Services Daemon)coreSSSD provides access to identity and authentication services at the operating system level, enabling FreeIPA client enrollment and caching for web application authentication.
- BIND/DNS (bind-dyndb-ldap)coreFreeIPA integrates BIND with dyndb-ldap driver for DNS zone management, dynamic updates with GSS-TSIG, and DNSSEC support.
- Microsoft Active DirectorycoreFreeIPA creates mutual trust relationships with Active Directory, enabling cross-realm authentication, AD user access to IPA resources, and enterprise identity federation scenarios.
- Fedora ProjectcoreFreeIPA is developed and primarily tested on Fedora Linux, serving as the upstream distribution for Red Hat Enterprise Linux.
- Apache HTTP Server Modules (mod_auth_gssapi, mod_authnz_pam, mod_lookup_identity, mod_intercept_form_submit, mod_auth_mellon)coreFreeIPA web application authentication relies on Apache modules for Kerberos SSO, PAM-based access control, identity lookup, form submission interception, and SAML federation.
Scale indicators1 record
Recent moves4 records
Expansion highlights4 records
FreeIPA competitors and assessment
Company assessmentBroad incumbents
- ForgeRock: Enterprise identity platform offering workforce and customer identity with strong directory, federation, and access management capabilities. Comparable as a full-stack identity vendor targeting large enterprise deployments similar to FreeIPA's primary use cases.
- Microsoft Active Directory: Dominant enterprise identity platform that FreeIPA explicitly interoperates with via mutual trust relationships. Active Directory is the incumbent FreeIPA most often complements or partially displaces in Linux-centric environments.
- Red Hat Identity Management: Red Hat's commercial Identity Management product is built directly on FreeIPA, offering enterprise support, certified RHEL integration, and professional services around the upstream codebase. Most directly comparable as the commercial wrapper of FreeIPA's open-source technology.
- Microsoft Entra ID (Azure Active Directory): Cloud-based identity service that is increasingly the default identity layer for hybrid and cloud-first enterprises. Primary competitive threat to on-premises Linux identity stacks like FreeIPA, especially as Microsoft extends Entra capabilities into Linux management.
- Okta: Cloud-native identity and access management leader offering workforce and customer identity. FreeIPA already documents integration with Okta SSO, positioning Okta as the cloud-side complement or competitor depending on deployment scenario.
Direct peers
- 389 Directory Server: The LDAP directory server that FreeIPA is built on; serves as FreeIPA's identity store. Closely related as both a dependency and a peer open-source directory technology targeting enterprise identity needs.
- OpenLDAP: Open-source LDAP directory server that overlaps with FreeIPA's 389 Directory Server component. Comparable as a foundational open-source directory technology, though FreeIPA layers Kerberos, PKI, and policy management on top.
Emerging players
- Shibboleth Consortium: Open-source federated identity solution focused on SAML-based SSO for web applications and research/academic federations. Overlaps with FreeIPA on SSO and SAML federation capabilities, particularly for web app authentication scenarios.
- Apache Syncope: Open-source identity management project under the Apache Software Foundation providing user provisioning, workflow, and administration. Comparable as an open-source IAM alternative targeting similar enterprise use cases.
- Keycloak: Open-source identity and access management focused on modern applications and cloud-native deployments, offering OAuth2/OIDC/SAML. Comparable as an open-source IAM alternative with stronger cloud and web application orientation than FreeIPA.
Market position
Strengths4 records
Weaknesses4 records
Competitive moat4 records
Key risks6 records
Key highlights6 records
Customer concentration
FreeIPA social profiles
Digital presenceFreeIPA financial estimates
Financial estimateRevenue estimate
Valuation estimate
FreeIPA leadership team
Management profileNumber of profiles
FreeIPA funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
FreeIPA M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about FreeIPA
What does FreeIPA do?
FreeIPA is an open-source integrated identity, policy, and audit management solution for Linux and Unix environments. It combines 389 Directory Server, MIT Kerberos, NTP, DNS (BIND-dyndb-ldap), the Dogtag certificate system, and SSSD into a single platform that delivers centralized user and host management, Kerberos-based Single Sign-On authentication, and policy-based access control for DNS, SUDO, SELinux, and autofs. The platform exposes extensible management interfaces including a CLI, a Web UI, JSON-RPC and XML-RPC APIs, and a Python SDK, and supports mutual trust relationships with Microsoft Active Directory, full multi-master replication, certificate lifecycle management, and web application authentication through Apache modules.
Is FreeIPA a public or private company?
FreeIPA is a private company. It is classified as unknown and is currently operating.
When was FreeIPA founded?
FreeIPA was founded in -1. It employs 51 to 100 people.
Where is FreeIPA based?
FreeIPA is headquartered in London, United Kingdom, in the Europe region.
How does FreeIPA make money?
One revenue line is on record: open Source Software.
Who are FreeIPA's main competitors?
Broad incumbents on record are ForgeRock, Microsoft Active Directory, Red Hat Identity Management, Microsoft Entra ID (Azure Active Directory) and Okta. Direct peers are 389 Directory Server and OpenLDAP. Emerging players are Shibboleth Consortium, Apache Syncope and Keycloak.
Does FreeIPA have an API?
Yes. FreeIPA provides extensible management interfaces including CLI, Web UI, XMLRPC and JSONRPC API, and Python SDK for managing Linux users and client hosts, Kerberos authentication, authorization policies, and trust relationships with other Identity Management systems. Developer documentation is at www.freeipa.org.
What industry is FreeIPA in?
FreeIPA's product category is Identity Management Software. Its primary akta.pro industry code is HDAEAJAA, Directory Services & Identity Stores (LDAP/AD, Cloud Directory), with a secondary code of HDAEAJAB, Single Sign-On (SSO) & Federation (SAML/OIDC, Identity Providers). Its NAICS code is 54151 and its SIC code is 7372.