Configuring LDAP Services for Novell eDirectory
365
n
ov
do
cx (e
n)
22
Ju
n
e 20
09
In Novell iManager, you can browse to the Key Material object (KMO) certificates. Using the drop-
down list, you can change to a different certificate. Either the DNS or the IP certificate will work.
As part of the validation, the server should validate the name (the hard IP address or the DN) that is
in the certificate.
To establish a TLS connection, ensure the following:
The LDAP server must know the server's KMO
You connect to the secure port or start TLS after connecting to the clear port
After you reconfigure the LDAP server, refresh the server. See
Section 15.5, “Refreshing the LDAP
Server,” on page 361
. ConsoleOne and Novell iManager automatically refresh the server.
15.6.4 Configuring the Client for TLS
An LDAP client is an application (for example, Netscape Communicator, Internet Explorer, or ICE).
The client must understand the certificate authority that LDAP server uses.
When a server is added into an eDirectory tree, by default the installation creates
A certificate authority for the tree (the tree CA).
A KMO from the tree CA.
The LDAP server uses this certificate provider.
The client needs to import a certificate that the client will trust so that the client can validate the tree
CA that the LDAP server claims to be using. The client must import a certificate from the server so
that whenever the server sends its certificate, the client can validate it and verify that the server is
who it claims to be.
So that the client can get a secure connection, the client must be configured before the connection.
The way that the client imports the certificate differs, based on the kind of application being used.
Each application must have a method to import a certificate. Netscape browser has one way, IE has
another way, and ICE has a third way. These are three different LDAP clients. Each client has its
method for locating the certificates that it trusts.
15.6.5 Exporting the Trusted Root
You can automatically export the trusted root while accepting the certificate server.
Summary of Contents for EDIRECTORY 8.8 SP5
Page 4: ...4 Novell eDirectory 8 8 Administration Guide novdocx en 22 June 2009...
Page 72: ...72 Novell eDirectory 8 8 Administration Guide novdocx en 22 June 2009...
Page 118: ...118 Novell eDirectory 8 8 Administration Guide novdocx en 22 June 2009...
Page 130: ...130 Novell eDirectory 8 8 Administration Guide novdocx en 22 June 2009...
Page 188: ...188 Novell eDirectory 8 8 Administration Guide novdocx en 22 June 2009...
Page 222: ...222 Novell eDirectory 8 8 Administration Guide novdocx en 22 June 2009...
Page 240: ...240 Novell eDirectory 8 8 Administration Guide novdocx en 22 June 2009...
Page 264: ...264 Novell eDirectory 8 8 Administration Guide novdocx en 22 June 2009...
Page 290: ...290 Novell eDirectory 8 8 Administration Guide novdocx en 22 June 2009...
Page 322: ...322 Novell eDirectory 8 8 Administration Guide novdocx en 22 June 2009...
Page 540: ...540 Novell eDirectory 8 8 Administration Guide novdocx en 22 June 2009...
Page 548: ...548 Novell eDirectory 8 8 Administration Guide novdocx en 22 June 2009...
Page 616: ...616 Novell eDirectory 8 8 Administration Guide novdocx en 22 June 2009...