Configuring LDAP Services for Novell eDirectory
353
no
vd
ocx
(e
n)
6 Ap
ril 20
07
To require that the client also establish legitimacy, you set a value on the server. This attribute is
ldapTLSVerifyClientCertificate.
Before the server can support TLS, you must provide the server with an X.509 certificate that the
server can use to establish its legitimacy.
This certificate is automatically provided during the eDirectory installation. During installation, Key
Material objects are created as part of Public Key Infrastructure (PKI) and Novell Modular
Authentication Services (NMAS
TM
). The following figure illustrates these objects in iManager:
The installation automatically associates one of those certificates with the LDAP server. In Novell
iManager, the Connections tab for the LDAP Server object displays a DN. This DN represents the
X.509 certificate. The Server Certificate field in the following figure illustrates this DN.
In Novell iManager, you can browse to the Key Material object (KMO) certificates. Using the drop-
down list, you can change to a different certificate. Either the DNS or the IP certificate will work.
As part of the validation, the server should validate the name (the hard IP address or the DN) that is
in the certificate.
To establish a TLS connection, ensure the following:
The LDAP server must know the server's KMO
Value
Description
0
Off. During a handshake, the server provides a certificate to the client. The server
never requires the client to send a certificate. The client can use or ignore the
certificate. A secure session is established.
1
During the handshake, the server provides a certificate to the client and requests a
certificate from the client. The client can choose to send its certificate back. The
client's certificate is validated. If the server cannot validate the client's certificate, the
connection is terminated.
If the client doesn't send a certificate, the server maintains the connection.
2
During the handshake, the server requests and requires a certificate from the client. If
the client does not provide a certificate, or if the certificate can't be validated, the
connection is terminated.
Summary of Contents for EDIRECTORY 8.8 SP2
Page 4: ...novdocx en 6 April 2007...
Page 116: ...116 Novell eDirectory 8 8 Administration Guide novdocx en 6 April 2007...
Page 128: ...128 Novell eDirectory 8 8 Administration Guide novdocx en 6 April 2007...
Page 255: ...256 Novell eDirectory 8 8 Administration Guide novdocx en 6 April 2007...
Page 406: ...408 Novell eDirectory 8 8 Administration Guide novdocx en 6 April 2007...
Page 563: ...566 Novell eDirectory 8 8 Administration Guide novdocx en 6 April 2007...
Page 573: ...576 Novell eDirectory 8 8 Administration Guide novdocx en 6 April 2007...
Page 601: ...604 Novell eDirectory 8 8 Administration Guide novdocx en 6 April 2007...